Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Ransomware crews exploiting Palo Alto GlobalProtect VPN login bypass: check your remote access today

What small and medium-sized businesses should look out for today.

High Tuesday 21 July 2026, 15:20 UK time
Today’s look-out: Remote access / VPN compromise leading to ransomware and business disruption

What to look out for today

Reports say the Qilin ransomware group is actively exploiting a Palo Alto PAN-OS GlobalProtect authentication bypass to gain initial access to organisations.

  • If your business (or your IT provider) runs Palo Alto firewalls/VPN with GlobalProtect, treat this as an urgent remote-access risk.
  • Even if you’re not sure you use Palo Alto, many SMEs inherit VPN setups via MSPs and previous IT projects—worth confirming.

Why this matters to smaller businesses

VPNs and remote access sit on the front door of the business. If attackers can bypass authentication, they may be able to enter without needing stolen passwords, then move quickly to disruption (including ransomware), data theft, and email/account compromise.

Warning signs

  • Unusual VPN sign-ins (new locations/countries, odd times, logins that don’t match staff travel or working patterns).
  • Sudden account lockouts or MFA prompts reported by staff who weren’t logging in.
  • New admin accounts, unexpected changes to firewall/VPN configuration, or new “support” accounts.
  • Unexpected remote tooling appearing (legitimate-looking remote admin tools you didn’t approve).
  • Unplanned outages, disabled security tools, or file servers becoming slow/unavailable.

How attackers may exploit the situation

  • Scan for internet-exposed GlobalProtect portals/gateways and use the authentication bypass to get into a network.
  • Establish persistence (create accounts/keys, change settings) so they can return.
  • Move to high-value systems (file servers, backups, finance systems) and then deploy ransomware.

What to do today

  • Confirm ownership: Ask your IT provider today whether you use Palo Alto PAN-OS/GlobalProtect anywhere (including at branch sites).
  • Confirm exposure: If you do, confirm whether GlobalProtect is internet-facing and whether mitigations/updates have been applied.
  • Review access logs: Check recent VPN sign-in activity for unusual patterns and investigate anything suspicious promptly.
  • Reduce blast radius: Ensure VPN users are not routinely local admins, and that sensitive systems (backups, finance, HR) have tighter access controls.
  • Ransomware readiness quick-check: Verify you can restore key data (at least one recent, tested restore) and that backup access is separate from everyday accounts.

Ask your IT provider

  • Do we run Palo Alto PAN-OS and is GlobalProtect enabled on any site?
  • Is our GlobalProtect portal/gateway internet-exposed, and what’s the current risk position?
  • Have we applied the vendor fix/mitigation for the reported authentication bypass, and when was it done?
  • Have you reviewed our VPN logs for the last 30 days for suspicious access linked to this issue?
  • If compromise is suspected, what’s the containment plan (disable external access, isolate systems, preserve logs, restore approach)?

Patch watch - only one short paragraph, and only if relevant

This matters because attackers commonly weaponise known issues quickly after fixes are available. If you use Palo Alto PAN-OS/GlobalProtect, treat confirmation of applied updates/mitigations and a quick log review as time-sensitive operational hygiene—especially for any internet-facing VPN.

One action today

Message your IT provider today to confirm whether you use Palo Alto GlobalProtect and, if yes, that mitigations/updates are applied and VPN logs have been reviewed for unusual access.

Related Actions On Cyber resource

Actions On Cyber checklist: “Ransomware readiness in 30 minutes (backups, access, restore test)”

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.