BoletimSecJuly 22, 2026🇵🇹Translated from Portuguese

Qilin Ransomware Operators Exploit Palo Alto PAN-OS VPN Flaw CVE-2026-0257

Operators linked to the Qilin ransomware have exploited an authentication bypass flaw in Palo Alto Networks PAN-OS to breach corporate networks and encrypt systems. The attacks, first observed in June 2026, began through the GlobalProtect VPN service installed on Palo Alto firewalls.

Tracked as CVE-2026-0257, the vulnerability allows attackers to circumvent authentication and establish VPN sessions without valid credentials. Exploitation requires the use of crafted authentication-replacement cookies combined with specific certificate configurations.

After obtaining initial access, the intruders collected credentials from Windows and Active Directory, including data extracted from LSASS processes and NTDS databases. Compromised administrative accounts were then used to reach servers, workstations, and backup systems.

Lateral movement was conducted primarily via PsExec and administrative shares. Additional tools observed in some intrusions included AnyDesk, Ngrok, LogMeIn, NetExec, and various network scanners employed to expand and maintain access.

Prior to encryption, the operators disabled Microsoft Defender real-time protection and cleared event logs. The ransomware payload was stored as win.exe, typically inside the C:\PerfLogs\ directory. Some victims experienced only partial encryption of their systems.

The flaw impacts vulnerable versions of PAN-OS 10.2, 11.1, 11.2, and 12.1, as well as certain editions of Prisma Access. Panorama and Cloud NGFW are not affected. The vendor has confirmed limited exploitation attempts against unpatched devices.

Related articles

BoletimSecRansomware & Extortion

Cl0p Exploits Critical Windchill Vulnerability CVE-2026-12569 to Steal Industrial Designs

The Cl0p extortion group is actively targeting internet-exposed PTC Windchill and FlexPLM servers to exfiltrate engineering projects, technical specifications, and other sensitive data. The campaign focuses on organizations in the industrial, automotive, aerospace, defense, and retail sectors. Attackers leverage the critical remote code execution vulnerability CVE-2026-12569, which stems from unsafe deserialization and carries a CVSS score of 9.8, allowing unauthenticated exploitation over the network. The intrusion chain also combines a WSDL endpoint information disclosure in FlexPLM with a login mechanism weakness in Windchill to gain initial access and execute commands without valid credentials. After compromise, operators deploy JSP web shells to maintain persistence, explore files, and prepare data for exfiltration. Affected systems often contain unreleased product designs, engineering drawings, and strategic manufacturing documents. The activity began in early June 2026, with extortion emails sent to hundreds of employees starting July 20 to increase internal pressure ahead of potential data leaks.

BoletimSecRansomware & Extortion

Chaos Ransomware Group Uses msaRAT Trojan to Hide C2 Traffic Through Invisible Chrome and Edge Browsers

The Chaos ransomware group has adopted a new Rust-based trojan called msaRAT to conceal its command-and-control communications inside legitimate browser sessions. The malware launches Chrome or Edge in invisible mode and controls it via the Chrome DevTools Protocol, keeping all outbound traffic restricted to localhost. It then injects JavaScript to negotiate a WebRTC connection through Cloudflare Workers before routing data over Twilio TURN servers, preventing the attackers' real infrastructure from appearing in network logs. Commands are executed through cmd.exe, and the implant includes queuing mechanisms that support reliable transfer of files, screenshots, and larger data volumes. In the analyzed incident, operators delivered the malware via an MSI installer disguised as a Windows update that loaded the msaRAT DLL directly into memory. The technique does not exploit any vulnerabilities in Chrome or Edge and is designed to blend malicious traffic with normal corporate browser activity.

BoletimSecRansomware & Extortion

Ransomware Attack Hits Coca-Cola Subsidiary Fairlife, Temporarily Halting US Production Systems

Fairlife, a company owned by Coca-Cola, temporarily suspended production operations in the United States after detecting unauthorized access to parts of its systems in a ransomware incident. The breach, publicly disclosed by Coca-Cola on July 16, 2026, affected environments directly linked to industrial production, prompting an immediate shutdown while investigations and recovery efforts continue. Fairlife manufactures milk, protein beverages, and other dairy products sold across the North American market, making the incident potentially disruptive to product availability, logistics, and internal processes. The company activated its incident response and business continuity protocols and engaged external cybersecurity specialists and consultants to assist with containment, investigation, and system restoration. No information has yet been released regarding data exfiltration, file encryption, or ransom demands, and the full scope of the attack remains under assessment. Coca-Cola has notified law enforcement authorities about the incident, while operations at Fairlife facilities in Canada were confirmed to be unaffected.

securitylab_nRansomware & Extortion

Six Weeks of Inactivity and 37 Years of History Lost: Cyberattack Forces German Textile Firm ZEGO into Bankruptcy

A prolonged cyberattack that halted operations for nearly six weeks has driven the Bavarian textile company ZEGO Textilveredelungszentrum into insolvency proceedings, ending 37 years of business activity. The firm, which specialized in fabric finishing and processing for the automotive sector, workwear producers, and technical textiles, was unable to recover from the severe financial strain caused by the production standstill that began after the incident on 29 March 2026. Managing Director Johannes Zenglein described the decision to seek creditor protection as one of the most difficult in the company’s history, noting that the financial burden had become insurmountable. Although the company has not disclosed whether ransomware was involved or whether attackers accessed customer or employee data, it confirmed that the operational shutdown alone pushed the business to the brink of collapse. ZEGO now hopes to continue limited production while insolvency administrators explore restructuring options to preserve jobs and relationships with clients and suppliers. The case echoes other high-profile incidents, such as the bankruptcy of British logistics company KNP Logistics after 158 years of operation following a ransomware attack that encrypted its systems.