PGH Networks

Qilin Ransomware Is Exploiting a Palo Alto GlobalProtect VPN Flaw

July 21, 2026· PGH Networks Team· 4 min readCybersecurity
Qilin Ransomware Is Exploiting a Palo Alto GlobalProtect VPN Flaw

What happened

Security researchers say the Qilin ransomware crew is now actively exploiting a critical authentication-bypass vulnerability in Palo Alto Networks' PAN-OS GlobalProtect VPN portal to break into corporate networks. According to reporting from BleepingComputer, incident responders at Arctic Wolf have tied recent Qilin intrusions back to the flaw, which lets an unauthenticated attacker slip past the login on internet-facing GlobalProtect gateways.

Once inside, Qilin's playbook is the usual double-extortion routine: harvest credentials, move laterally, exfiltrate data, then detonate ransomware. Because the entry point is the VPN itself, traditional endpoint alerts often fire too late. If you run Palo Alto GlobalProtect, verify the exact CVE, affected PAN-OS versions, and patched builds directly against Palo Alto's official security advisory before you plan your remediation window, then confirm your firewalls are on a fixed release.

man standing beside another sitting man using computer

Why this matters for Pittsburgh SMBs

Palo Alto is not just a Fortune 500 brand. Plenty of Pittsburgh-area CPA firms, law offices, specialty manufacturers, and healthcare practices in the 25–200 employee range sit behind a Palo Alto firewall with GlobalProtect published to the internet for remote and hybrid workers. That is exactly the profile Qilin has been hunting: mid-market organizations with valuable data, real revenue, and lean internal IT.

A few reasons this one deserves your attention today, not next quarter:

  • Ransomware crews love VPN bugs. VPN portals are, by design, exposed to the open internet. One unpatched appliance can undo an otherwise mature security program.
  • Compliance exposure is real. If you handle PHI, CUI for a DoD prime, client trust data, or cardholder information, a Qilin intrusion is not just an outage — it is a reportable event under HIPAA, DFARS 7012, the FTC Safeguards Rule, and most cyber-insurance policies. Notification clocks are short (HIPAA's 60-day breach notification, DFARS 7012's 72-hour DoD reporting).
  • Local defense-industrial-base firms are prime targets. If you are working toward CMMC Level 2, an unpatched perimeter device is precisely the kind of finding that will sink an assessment.
  • "Small" does not mean "under the radar." Qilin affiliates run automated scans across the entire IPv4 space. Being a 40-person firm in Robinson Township offers zero protection.

What to do about it this week

Here is a practical checklist you (or your IT provider) can start on immediately. None of this is exotic — it is basic hygiene applied with urgency.

  1. Inventory your Palo Alto footprint. Confirm every PAN-OS device you own, its version, and whether GlobalProtect is enabled and internet-facing. If you cannot answer this in under an hour, that itself is a finding.
  2. Patch to a fixed PAN-OS release, or apply Palo Alto's documented mitigations. Verify the fixed-version numbers on Palo Alto's security advisory rather than trusting screenshots or forum posts. Schedule a maintenance window this week, not next month.
  3. Hunt before you assume you're clean. Review GlobalProtect and firewall logs for unusual authentication events, unexpected admin sessions, and new local accounts going back at least 60 days. If logs don't go back that far, note that gap for your SOC 2 or CMMC evidence file.
  4. Enforce MFA on the VPN and on every admin interface. If GlobalProtect can be reached with a password alone from anywhere in the world, fix that today. Consider certificate-based or conditional-access-gated authentication.
  5. Validate your EDR/MDR coverage on servers, not just laptops. Qilin dwell time is measured in days. A modern EDR platform with 24/7 monitoring is what turns a breach attempt into a contained incident.
  6. Confirm immutable, offline-tested backups. Pull last week's restore report. If you don't have one, run a live restore of a representative file share and a domain controller this week.
  7. Refresh your incident response contacts. Cyber insurance carrier, breach counsel, MSP after-hours line, and — for DoD contractors — your DIBNet reporting credentials. Print them. Ransomware negotiations are not the time to be resetting a password on your insurance portal.

Bonus for regulated shops: document each of the above with dates, tickets, and screenshots. That paper trail is what turns an incident from an existential threat into a defensible response under HIPAA or CMMC.

people working at desks in open office

How PGH Networks helps

This is the exact scenario our managed IT and cybersecurity teams handle every day for Pittsburgh SMBs: emergency patch cycles on perimeter gear, log review, MFA enforcement on VPN and Microsoft 365, and the compliance documentation that keeps auditors and insurers satisfied afterward. If you're not sure whether your firewall is exposed, whether your backups would actually survive Qilin, or whether your remote-access design would pass a CMMC assessment, our vCIO team can walk your environment and give you a straight answer.

Talk to us

Call 724.888.7007 or reach out through the contact form and we'll get a Palo Alto exposure check on your calendar this week.

Share

Related reading

Cybersecurity Services in Greentree, PA

Cybersecurity services in Greentree, PA for small and mid-market businesses: local response, EDR/MDR, HIPAA and CMMC support from a Pittsburgh MSP.