Cyber Security

Ransomware groups exploit your vulnerable VPNs

Cybercriminals are exploiting newly discovered vulnerabilities in Palo Alto Networks firewall and VPN appliances to release the Qilin ransomware.

A critical bypass authentication flaw (CVE-2026-0257) in the Palo Alto GlobalProtect portal and gateway was a common link in the June intrusion chain, Arctic Wolf Labs warns. Exploitation of the vulnerability has come days of disclosure.

“The post-exploit trade has varied across interventions, from quick encryption-only operations to double-spoofing, which may suggest multiple entities operating under the Qilin ransomware-as-a-service (RaaS) umbrella,” Arctic Wolf researchers wrote in a post about the threat.

The campaign against Palo Alto’s VPN client is part of a growing trend that sees ransomware groups increasingly targeting vulnerabilities in network edge tools and devices.

Ransomware takes the target to the edge

Beyond GlobalProtect, Qilin – the most active threat group in Q2 2026, responsible for 14% of attacks, according to the latest NCC Group’s Quarterly Cyber ​​​​Threat Intelligence Report – also targeted errors in Fortinet’s FortiGate, Citrix NetScaler, and Check Point Remote Access VPN.

Check Point warned in June about ransomware attacks against VPNs that still use the deprecated Internet Key Exchange protocol version 1 (IKEv1). Citrix released patches in early July for a bug similar to CitrixBleed on its NetScalar devices that were affected.

Meanwhile, Fortibleed, a major compromise campaign, exposed 75,000 FortiGate firewalls in June.

Qilin is not alone in increasing its effectiveness against VPNs and other network security tools.

Gentlemen, No. 2 on the NCC Group list with 238 victims in Q2 2026, it is notable for breaking into organizations using firewalls, VPNs, and other Internet-exposed systems – especially FortiGate and Cisco products.

Akira, number 4 on the NCC Group list (127 victims), is also known for exploiting VPN vulnerabilities and abusing legitimate information, primarily when compared to products from Ivanti, Cisco, and Fortinet.

In the line of fire

Security devices at the network edge are becoming security liabilities for enterprise security professionals, with an alarming rise in zero-day attacks from what experts describe as basic and easily preventable vulnerabilities.

Various attackers ranging from opportunistic hackers to ransomware-as-a-service operators and nationally sponsored APT (advanced persistent threat) groups are exploiting software vulnerabilities in advanced devices to gain access to corporate networks.

“Although there has not been an increase in the volume of ransomware in the last quarter, the number of attacks continues to increase, and VPNs remain an attractive target,” said Matt Hull, VP and head of cyber intelligence and responses at NCC Group.

Unpatched vulnerabilities in edge devices are far from the software bugs that fuel ransomware attacks. For example, last year the Cop ransomware gang hacked hundreds of companies by exploiting a zero-day vulnerability in Oracle’s E-Business Suite software.

The edge of darkness

VPNs and other Internet-facing devices remain prime targets for ransomware operators because they provide a direct route to an organization’s network.

“Attackers may exploit unpublished vulnerabilities, use stolen information, or target weak authentication controls,” said Alexander Leslie, senior consultant at record-breaking cyber intelligence firm Record Future. “Sometimes, exploits begin before organizations have had enough time to implement vendor guidance, leaving security teams with a very small window to respond.”

Exploiting a VPN is accompanied by other primary access methods, such as phishing, compromised data, or software supply chain attacks. An attacker’s preferred entry method varies by campaign and sector but securing security on host devices has certain advantages from the attacker’s point of view.

“Vulnerabilities in perimeter devices are critical to attackers because those systems are constantly exposed to the Internet and can provide privileged access while bypassing other endpoint controls,” Leslie said.

Dray Agha, senior manager of security operations at private detection and response firm Huntress, backed this assessment by saying that exploiting Internet-facing VPNs and edge devices remains a “dominant, volume-driven strategy” for ransomware operators because these tools provide a “direct, publicly accessible gateway straight into the heart of corporate networks.”

Rather than exploiting vulnerabilities in edge devices, attackers often use gateways to the Internet as a way to misuse stolen credentials to break into corporate networks, according to Huntress.

“What we see at Huntress is that a VPN is the first port of call 70% of the time, for advanced threat actors,” Agha said. “However, at the extreme, they are not exploiting access, rather they are using stolen documents to authenticate non-MFA’d. [multi-factor authentication] user accounts.”

A solid perimeter

CSOs should treat their network perimeter as a hostile environment by enforcing aggressive patch management, applying critical device updates within 24 to 48 hours, and enforcing strict MFA on all access.

Using zero-trust network isolation to deter attackers and prevent coordinated movement when the first gateway is compromised also helps make corporate networks more resilient to attacks, advises Huntress’ Agha.

Verification of multiple anti-phishing devices, removal of unsupported systems, and close monitoring of unusual authentication or control activity also form key components in mitigating the impact of an attack.

Internet-facing assets that are known to be in use should be prioritized as a priority for patching.

“Threat intelligence and evidence of active exploitation should help determine which vulnerabilities require immediate action,” said Record Future’s Leslie.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button