View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Qilin ransomware exploits critical Palo Alto GlobalProtect VPN auth

🚨 ACTIVE EXPLOITATION

  • Qilin ransomware exploits critical Palo Alto GlobalProtect VPN auth bypass β€” bleepingcomputer.com
    Qilin ransomware gang exploits a critical Palo Alto GlobalProtect VPN authentication bypass flaw.
    • Applies to Palo Alto Networks GlobalProtect VPN users, including over 70,000 customers worldwide
    • Vulnerability CVE-2026-0257 allows attackers to bypass authentication and establish unauthorized VPN connections
    • Exploitation leads to network breaches and domain-wide Qilin ransomware encryption
    • Attackers use varied post-exploitation tactics, including rapid encryption and double-extortion
    • Observed ongoing exploitation since May 2026 with multiple Qilin affiliates involved

πŸ’₯ BREACHES & INCIDENTS

  • Clover Health Investments Discloses Data Breach via Social Engineering Attack β€” SecurityWeek
    Hackers used social engineering to compromise employee accounts at Clover Health Investments.
    • Applies to Clover Health Investments, a healthcare technology company offering Medicare Advantage plans
    • Three non-managerial employee accounts with access to personal and protected health information were compromised
    • Attack vector was social engineering targeting employees with member scheduling and broker-facing sales roles
    • No access to corporate financial or claims systems was gained by attackers
    • Incident discovered July 4, 2026; company engaged third-party experts to contain and investigate

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Meta paid $78,000 bounty for broken access control flaw exposing support data β€” SecurityWeek
    A broken access control vulnerability exposed Meta customer support data.

    • Applies to Meta’s backend support infrastructure and Meta Horizon Managed Solutions
    • Vulnerability involved missing authorization, broken access control, and IDOR issues
    • Allowed enumeration of support cases and access to emails, chats, personal info, and files
    • Attackers could create and modify support requests and add unauthorized subscribers
    • Discovered by researcher Rony K Roy, patched by Meta in April 2026, no exploitation found
  • Sandworm uses fake CAPTCHAs to trick users into running malware via PowerShell β€” bitdefender.com
    Sandworm hackers use fake CAPTCHAs to trick users into executing malicious PowerShell commands.

    • Targets users visiting compromised websites, primarily in Ukraine
    • Fake CAPTCHAs prompt users to run PowerShell commands disguised as verification steps
    • Commands execute malware, reconnaissance tools, or remote access software
    • Attack attributed to Kremlin-backed Sandworm group, UAC-0145 branch
    • At least 10 websites compromised since June 2026

πŸ”“ CVEs & KEV

  • CVE-2026-15370 β€” Libssh stack buffer overflow in sftp server longname construction
  • CVE-2026-64609 β€” Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy
  • CVE-2026-64608 β€” Apache Fory: Heap type confusion and out-of-bounds read/write in C++ compatibility
  • CVE-2026-62415 β€” Joomla Extension joomdonation.com insecure default configuration Membersh...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check