Monday , July 27 2026
Palo Alto

CVE-2026-0257
Palo Alto Warns of GlobalProtect VPN Vuln Actively Exploited

Palo Alto Networks Unit 42 has given an urgent alert about the active use of CVE-2026-0257. This is a serious security hole that allows bypassing authentication in the GlobalProtect portal and gateway parts of PAN-OS software.

The flaw lets unauthenticated remote attackers bypass security measures and start unauthorized VPN connections without needing any login details.

“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

PentesterFlow is a new open-source AI tool for command lines. It is made for penetration testers and bug bounty hunters....
Read More
“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

A famous AI red team expert claimed developing a universal jailbreak that can work against top large language models, like...
Read More
Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

Researchers found security flaws in every script generated by ChatGPT, Copilot, and Gemini

A new study from Beacom College shows that all automation scripts produced by top AI models like ChatGPT, Microsoft Copilot,...
Read More
Researchers found security flaws in every script generated by ChatGPT, Copilot, and Gemini

Australian Energy Giant Origin confirms unauthorized access and disclosure of customer data

Origin Energy Limited, a major energy provider in Australia, has said there was a cybersecurity issue with unauthorized access to...
Read More
Australian Energy Giant Origin confirms unauthorized access and disclosure of customer data

Anthropic Unveils Claude Security Plugin for Code Flaw Scanning

Anthropic launched the Claude Security plugin in beta. This tool uses AI to find serious security flaws in Claude Code....
Read More
Anthropic Unveils Claude Security Plugin for Code Flaw Scanning

Apple, ASUS Router, Meta, Windmill & Ubuntu Patch Critical Security Flaws

ASUS has put out important security updates for a serious router flaw. This issue could let remote hackers run any...
Read More
Apple, ASUS Router, Meta, Windmill & Ubuntu Patch Critical Security Flaws

SolarWinds Patches 15 Critical Serv-U Flaws

SolarWinds has shared important security updates for its Serv-U file transfer software. These updates fix 15 problems that could let...
Read More
SolarWinds Patches 15 Critical Serv-U Flaws

Oracle fixes 1,400+ vulnerabilities; critical flaws threaten enterprise servers

Oracle has fixed over 1,400 security holes in its July 2026 Critical Patch Update (CPU). Most of these flaws were...
Read More
Oracle fixes 1,400+ vulnerabilities; critical flaws threaten enterprise servers

Zimbra Patches 4 XSS and Critical SNMP Command Injection Flaws

Zimbra has launched updates to fix serious security flaws, including a command injection bug in the SNMP monitoring part. As...
Read More
Zimbra Patches 4 XSS and Critical SNMP Command Injection Flaws

Qilin ransomware gang exploiting critical Palo Alto VPN Flaw

The Qilin ransomware group is exploiting a flaw in PAN-OS GlobalProtect to break into victims' networks, says the cybersecurity firm...
Read More
Qilin ransomware gang exploiting critical Palo Alto VPN Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) included CVE-2026-0257 in its list of known problems on May 29, 2026, showing how serious it is and that it has been used in real attacks.

Unit 42 researchers found an unknown threat actor testing GlobalProtect-enabled devices. The attacker checked many targets, but only a few made real VPN connections, leading to gateway-related events. There is no proof of further actions, movement, or data theft right now, but it is still possible.

Organizations should quickly look for signs of problems (IOCs) in their GlobalProtect logs and start their response plans for any successful events connected to the listed signs.
Organizations must check the Palo Alto Networks security notice right away, use any available fixes, or upgrade to a fixed PAN-OS version. Rapid7 has also shared a technical report on the exploitation activity they have seen.

Threat hunters need to look at GlobalProtect logs for successful logins from these IP addresses, especially for any actions before the public PoC release on May 29, 2026:

IP Address Indicators

IP Address Context Phase
23.128.228[.]6 Malicious source IP Pre-PoC (before May 29, 2026)
104.207.144[.]154 Malicious source IP Pre-PoC (before May 29, 2026)
146.19.216[.]119 Malicious source IP Pre-PoC (before May 29, 2026)
146.19.216[.]120 Malicious source IP Pre-PoC (before May 29, 2026)
146.19.216[.]125 Malicious source IP Pre-PoC (before May 29, 2026)
179.43.172[.]213 Malicious source IP Pre-PoC (before May 29, 2026)
185.195.232[.]139 Malicious source IP Pre-PoC (before May 29, 2026)
198.12.106[.]60 Malicious source IP Pre-PoC (before May 29, 2026)
202.144.192[.]47 Malicious source IP Pre-PoC (before May 29, 2026)

Host-Based Indicators

Indicator Type Context
aa:bb:cc:dd:ee:ff MAC Address Suspicious device identifier in GlobalProtect logs
00:11:22:33:44:55 MAC Address Suspicious device identifier in GlobalProtect logs
WINDOWS-LAPTOP-001 Hostname Suspicious host ID in GlobalProtect logs
DESKTOP-GP01 Hostname Suspicious host ID in GlobalProtect logs
GP-CLIENT Hostname Suspicious host ID in GlobalProtect logs

Post-PoC Hard-Coded Client Configuration Indicators

Field Value Context
endpoint_os_version Microsoft Windows 10 Pro 64-bit Hard-coded in PoC exploit code
source_user_info.domain (empty) Hard-coded in PoC exploit code

Check Also

Qilin

Qilin ransomware gang exploiting critical Palo Alto VPN Flaw

The Qilin ransomware group is exploiting a flaw in PAN-OS GlobalProtect to break into victims’ …