What to look out for today
Reports say the Qilin ransomware group is actively exploiting a Palo Alto PAN-OS GlobalProtect authentication bypass to gain initial access to organisations.
- If your business (or your IT provider) runs Palo Alto firewalls/VPN with GlobalProtect, treat this as an urgent remote-access risk.
- Even if you’re not sure you use Palo Alto, many SMEs inherit VPN setups via MSPs and previous IT projects—worth confirming.
Why this matters to smaller businesses
VPNs and remote access sit on the front door of the business. If attackers can bypass authentication, they may be able to enter without needing stolen passwords, then move quickly to disruption (including ransomware), data theft, and email/account compromise.
Warning signs
- Unusual VPN sign-ins (new locations/countries, odd times, logins that don’t match staff travel or working patterns).
- Sudden account lockouts or MFA prompts reported by staff who weren’t logging in.
- New admin accounts, unexpected changes to firewall/VPN configuration, or new “support” accounts.
- Unexpected remote tooling appearing (legitimate-looking remote admin tools you didn’t approve).
- Unplanned outages, disabled security tools, or file servers becoming slow/unavailable.
How attackers may exploit the situation
- Scan for internet-exposed GlobalProtect portals/gateways and use the authentication bypass to get into a network.
- Establish persistence (create accounts/keys, change settings) so they can return.
- Move to high-value systems (file servers, backups, finance systems) and then deploy ransomware.
What to do today
- Confirm ownership: Ask your IT provider today whether you use Palo Alto PAN-OS/GlobalProtect anywhere (including at branch sites).
- Confirm exposure: If you do, confirm whether GlobalProtect is internet-facing and whether mitigations/updates have been applied.
- Review access logs: Check recent VPN sign-in activity for unusual patterns and investigate anything suspicious promptly.
- Reduce blast radius: Ensure VPN users are not routinely local admins, and that sensitive systems (backups, finance, HR) have tighter access controls.
- Ransomware readiness quick-check: Verify you can restore key data (at least one recent, tested restore) and that backup access is separate from everyday accounts.
Ask your IT provider
- Do we run Palo Alto PAN-OS and is GlobalProtect enabled on any site?
- Is our GlobalProtect portal/gateway internet-exposed, and what’s the current risk position?
- Have we applied the vendor fix/mitigation for the reported authentication bypass, and when was it done?
- Have you reviewed our VPN logs for the last 30 days for suspicious access linked to this issue?
- If compromise is suspected, what’s the containment plan (disable external access, isolate systems, preserve logs, restore approach)?
Patch watch - only one short paragraph, and only if relevant
This matters because attackers commonly weaponise known issues quickly after fixes are available. If you use Palo Alto PAN-OS/GlobalProtect, treat confirmation of applied updates/mitigations and a quick log review as time-sensitive operational hygiene—especially for any internet-facing VPN.
One action today
Message your IT provider today to confirm whether you use Palo Alto GlobalProtect and, if yes, that mitigations/updates are applied and VPN logs have been reviewed for unusual access.
Related Actions On Cyber resource
Actions On Cyber checklist: “Ransomware readiness in 30 minutes (backups, access, restore test)”
Sources
- Critical Palo Alto VPN bug now exploited by Qilin ransomware gang (BleepingComputer)
- Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access (The Hacker News)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.