惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
V
Vulnerabilities – Threatpost
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V
Visual Studio Blog
月光博客
月光博客
IT之家
IT之家
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Tailwind CSS Blog
罗磊的独立博客
S
SegmentFault 最新的问题
博客园 - 三生石上(FineUI控件)
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
量子位
V
V2EX
Jina AI
Jina AI
The GitHub Blog
The GitHub Blog
小众软件
小众软件
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
阮一峰的网络日志
阮一峰的网络日志
Recent Announcements
Recent Announcements
MongoDB | Blog
MongoDB | Blog
Y
Y Combinator Blog
H
Help Net Security
博客园_首页
Cyberwarzone
Cyberwarzone
T
Tenable Blog
A
Arctic Wolf
C
CERT Recently Published Vulnerability Notes
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
Threat Research - Cisco Blogs
aimingoo的专栏
aimingoo的专栏
Google DeepMind News
Google DeepMind News
博客园 - 叶小钗
C
Cyber Attacks, Cyber Crime and Cyber Security
美团技术团队
Attack and Defense Labs
Attack and Defense Labs
GbyAI
GbyAI
博客园 - 【当耐特】
Cloudbric
Cloudbric
NISL@THU
NISL@THU
B
Blog RSS Feed
K
Kaspersky official blog
Hugging Face - Blog
Hugging Face - Blog
P
Privacy International News Feed
博客园 - Franky
博客园 - 司徒正美
Microsoft Azure Blog
Microsoft Azure Blog
Apple Machine Learning Research
Apple Machine Learning Research
Webroot Blog
Webroot Blog
Microsoft Security Blog
Microsoft Security Blog

Arctic Wolf

Home-Field Disadvantage: AiTM, QR-Code Phishing, and Infostealers at the 2026 FIFA World Cup arcticwolf.com arcticwolf.com Celebrating Arctic Wolf’s 2026 Partner of the Year Winners at Global Partner Kickoff Die Auswahl Einer Vulnerability Management-Lösung The Hidden Economics of the Agentic SOC The Hidden Economics of the Agentic SOC | Arctic Wolf Security Operations in Maschinen-Geschwindigkeit Aurora Mobile Threat Defense — Addressing Your Highest‑Trusted, Least Protected Endpoints - Arctic Wolf Aurora Mobile Threat Defense — Addressing Your Highest‑Trusted, Least Protected Endpoints - Arctic Wolf How Aurora Managed Endpoint Defense Combines Experts and Technology to Simplify Security Aurora Endpoint Sicherheitsportfolioa | Arctic Wolf From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services arcticwolf.com arcticwolf.com Arctic Wolf Product Updates: May 2026 arcticwolf.com Arctic Wolf Product Updates: May 2026 FortiClient EMS Exploited via CVE-2026-35616 to Deliver EKZ Infostealer Disguised as a Fortinet Patch - Arctic Wolf FortiClient EMS Exploited via CVE-2026-35616 to Deliver EKZ Infostealer Disguised as a Fortinet Patch What’s New What’s Next with Arctic Wolf: May 2026 Update Cybersecurity Trends in the Age of AI arcticwolf.com Arctic Wolf、AI搭載のモバイル脅威防御ソリューションを発表、 増加するモバイル端末を標的としたサイバー攻撃から組織を保護 How Arctic Wolf Aurora Mobile Threat Defense Protects the Mobile Attack Surface How AI Is Transforming Detection Engineering 「Aurora Mobile Threat Defense」の提供が開始されました Accelerating Cloud Security Outcomes Together: Why Arctic Wolf and Wiz are Redefining What’s Possible - Arctic Wolf InfoSecurity Europe 2026 OpenAI Daybreak and the Future of Secure Software Development - Arctic Wolf OpenAI Daybreak and the Future of Secure Software Development Turning Security Telemetry Into Actionable Insights | Arctic Wolf Detecting Identity Attacks at Scale with Herd Immunity Detecting Identity Attacks at Scale with Herd Immunity | Arctic Wolf arcticwolf.com arcticwolf.com PowerShell Security | Arctic Wolf How to Gain Visibility and Reduce Exposure with Aurora Attack Surface Management arcticwolf.com Mini Shai-Hulud: Supply Chain Malware Attack arcticwolf.com arcticwolf.com arcticwolf.com arcticwolf.com arcticwolf.com arcticwolf.com arcticwolf.com arcticwolf.com arcticwolf.com Arctic Wolf Introduces the Next Era of Exposure Management to Help Organizations Outpace AI-Accelerated Vulnerability Discovery Arctic Wolf Launches AI-Powered Mobile Threat Defense to Protect Organizations Against Growing Mobile-based Cyber Threats Aurora Mobile Threat Defense is Now Available Turning Visibility Into Action: Introducing Aurora Exposure Management Protecting Against IOT Security Risks | Arctic Wolf CVE-2026-0300 — Critical Buffer Overflow in PAN-OS User-ID Authentication Portal IoT Security Risks | Arctic Wolf arcticwolf.com Should Your Organization Rely on XDR? | Arctic Wolf 止まらないランサムウェア被害 - Qilinの事案から読み解く、検知、対応と経営判断 arcticwolf.com Why Cybersecurity Still Matters Even If AI Improves Secure Development | Arctic Wolf Aurora® Attack Surface Management For Healthcare arcticwolf.com arcticwolf.com arcticwolf.com arcticwolf.com arcticwolf.com CVE-2026-41940: Critical Exploited Authentication Bypass Vulnerability in cPanel & WHM Why Vulnerability Prioritization Requires More Than a Score | Arctic Wolf Token Bingo: Don’t Let Your Code be the Winner EFM Philadelphia IT Symposium MN Bankers Operations and Technology Conference SecureMiami 2025 Cyber Identity Summit – Ottawa MISA Exec Summit – Victoria Arkansas IT Symposium – efmEvents Cybersecurity Summit – Boston Houston Technology Summit – elevateIT Nevada Public Sector Cybersecurity Summit SecureWorld Philadelphia Nick Schneider of Arctic Wolf named Entrepreneur Of The Year® 2026 Heartland finalist by EY US arcticwolf.com arcticwolf.com Introducing Decipio: A Community Tool to Catch Credential Theft in the Act with Defense First AI Arctic Wolf Introduces Decipio, a Community Tool to Catch Credential Theft with Defense‑First AI Proxy Server Endpoint Endpoint Detection and Response AIマルウェアの急増:その挙動、攻撃主体の特定、防御体制の備え arcticwolf.com arcticwolf.com Project Glasswing Marks a Turning Point for Cybersecurity Frontier AI Models Mark a Turning Point for Cybersecurity arcticwolf.com arcticwolf.com Building Cyber Resilience with Arctic Wolf: A Practical Approach for Security Leaders Arctic Wolf、東映デジタルラボ株式会社を Aurora Managed Endpoint Defenseで保護 Arctic Wolf Named a 2026 Gartner® Peer Insights™ Customers’ Choice for Managed Detection and Response arcticwolf.com
Arctic Wolf Observes an Increase in Palo Alto Networks GlobalProtect Authentication Bypass Exploitation via CVE-2026-0257
Arctic Wolf Labs · 2026-06-11 · via Arctic Wolf

Key Takeaways

  • Arctic Wolf observed a wave of CVE-2026-0257 exploitation activity in late May and early June 2026, following the publication of working exploit code and technical details about the vulnerability. The campaign is still ongoing as of this publication.
  • Successful exploitation requires specific configuration conditions, including GlobalProtect portal or gateway exposure, authentication override cookies, and reuse or exposure of the certificate used for those cookies.
  • Initial malicious activity consisted of suspicious cookie-based GlobalProtect administrative login activity from virtual private server hosting infrastructure.
  • In intrusions that progressed beyond initial authentication bypass, threat actors established IPSec tunnels and quickly generated internal SMB and NTLM activity consistent with Impacket-based reconnaissance from the assigned VPN client address.

Summary

In late May and early June 2026, Arctic Wolf began observing increased exploitation of CVE-2026-0257, a high-severity authentication bypass vulnerability affecting Palo Alto Networks PAN-OS GlobalProtect and Prisma Access.

The increase in CVE-2026-0257 exploitation began on May 30, 2026, following a smaller initial wave that had taken place between May 17 and May 21. Initial exploitation activity was consistent in some respects with behavior initially reported on by Rapid7, where a variable number of authentication failures were followed by successful authentication. In contrast with the original cluster of activity described, Arctic Wolf observed a set of intrusions with follow-on Impacket activity soon after VPN tunnel establishment.

Arctic Wolf is sharing technical details from this campaign to help defenders identify similar activity and hunt for related indicators of compromise in PAN-OS deployments.

Background

CVE-2026-0257 is an authentication bypass vulnerability that allows remote, unauthenticated threat actors to forge GlobalProtect authentication override cookies and establish unauthorized VPN sessions when three configuration conditions are met:

  1. GlobalProtect portal or gateway is enabled.
  2. Authentication override cookies are enabled. Authentication override cookies are an optional GlobalProtect feature that allow previously authenticated users to reconnect without re-entering credentials for a configured time period.
  3. The certificate used for authentication override cookies is reused or exposed in another context. For example, if the same certificate is used for the GlobalProtect portal or gateway HTTPS service, a remote attacker may be able to retrieve the public certificate and use it to forge authentication override cookies that the appliance accepts.

CVE-2026-0257 was first publicly disclosed by Palo Alto Networks on May 13, 2026, via a security advisory. The vulnerability was initially assigned a CVSS score of 4.7 (medium). However, on May 29, 2026, after Rapid7 published its technical analysis and a working proof-of-concept script, Palo Alto Networks revised the CVSS score upward to 7.8 (high). That same day, CISA added CVE-2026-0257 to the Known Exploited Vulnerabilities (KEV) catalog.

Technical details

Campaign Characteristics

In May 2026, the initial wave of suspicious cookie-based admin login activity from virtual private server (VPS) hosting providers appears to have begun on the 17th, with low volume continuing until the 21st. During this phase of the campaign, suspicious login activity was tied to two IP addresses: 104.207.144[.]154 and 179.43.172[.]213. These two IP addresses were not observed again following the 21st.

The next wave of exploitation began on May 30, 2026, where a notable uptick in activity was observed involving a variety of ASNs. The source infrastructure utilized throughout this phase was broad, spanning across numerous ASNs, including DigitalOcean, The Constant Company, Hivelocity, Clouvider, BL Networks, M247, Frantech Solutions, and others.

Figure 1: Suspicious admin logins on GlobalProtect devices from VPS hosting IP space between May 17, 2026 and June 9, 2026.

Exploitation was observed across a variety of sectors, including insurance, finance, manufacturing, education, engineering, and healthcare. Impacted organizations were located in Europe and North America, with the heaviest concentration in the United States. The pattern of exploitation showed signs of being opportunistic, with successful logins spanning across hundreds of devices in an assortment of sectors rather than being limited to a narrow targeting criteria.

Observed activity targeted the admin account primarily. Additionally, we identified kali as a device name artifact, which strongly suggested the direct use of Kali Linux offensive tooling by at least a subset of the operators involved in this campaign. Additional device names included generic DESKTOP– prefixed names, GP-CLIENT, and several others. In contrast with the earlier activity observed by Rapid7, MAC spoofing was not consistently observed across all intrusions.

Suspicious Cookie-Based GlobalProtect Authentication

The exploitation activity observed across multiple intrusions followed a consistent sequence of events that were similar to Rapid7’s published proof-of-concept behavior.

The broadest pattern observed by Arctic Wolf was successful suspicious cookie-based authentication against GlobalProtect portals and gateways, predominately from VPS hosting providers. The activity often included combinations of the following GlobalProtect events:

  • portal-prelogin success
  • gateway-prelogin success
  • portal-auth failure
  • saml-client-redirect
  • gateway-auth success
  • portal-auth success

In some instances, authentication failures were caused by cookie handling errors such as Cannot decrypt cookie, followed quickly by successful cookie-based authentication. However, this error message was not universally observed across all intrusions.

In several cases, the activity included repeated authentication failures interspersed with SAML redirection events prior to eventual authentication success. This behavior suggested iterative authentication attempts or manipulation of the authentication workflow before successful session establishment.

However, successful GlobalProtect authentication events alone did not necessarily mean threat actors proceeded to move laterally within victim environments. Follow-on activity typically involved tunnel establishment and assigning a client IP address.

VPN Session Establishment

While threat actors generated successful authentication activity, only a subset of observed intrusions progressed beyond authentication activity into full VPN session establishment.

In cases of successful authentication, additional gateway and tunnel establishment events typically followed, including:

  • portal-getconfig success
  • gateway-getconfig success
  • gateway-register success
  • gateway-setup-ipsec success
  • gateway-hip-check success
  • gateway-connected success

These events indicated that the client successfully authenticated to the GlobalProtect gateway and established a functional VPN tunnel, resulting in network-level access to the internal environment.

Figure 2: Event sequence from a representative intrusion with successful VPN tunnel establishment. (NOTE: The remote IP address shown here belongs to the attacker.)

In a representative intrusion, within a few seconds, the same remote IP generated a cookie-based portal-auth failure with Cannot decrypt cookie, successfully authenticated as admin, retrieved portal and gateway configuration, registered with the gateway, and completed gateway-setup-ipsec before reaching gateway-connected.

In some instances we observed gateway-setup-ssl failure events from suspicious IP addresses. Palo Alto documentation states that GlobalProtect clients preferentially attempt IPsec tunnel establishment and may automatically fall back to SSL VPN transport if IPSec negotiation fails or is unavailable. However, we did not identify any successful SSL-VPN connection across the activity we reviewed; successfully established tunnels we observed were limited to IPsec.

Post-Compromise

In a subset of investigated intrusions, successful VPN session establishment was quickly followed by an SMB session setup request and automated internal SMB reconnaissance consistent with Impacket tooling. The threat actor conducted limited internal network scanning, including network share enumeration and domain user discovery. In some instances, the SMB activity followed GlobalProtect gateway-connected events within a minute.

In situations where follow-on activities occurred, affected hosts initiated rapid SMB authentication and session negotiation activity. The authentication traffic leveraged NTLM negotiation and repeatedly attempted access using the admin account, likely intended to identify reachable systems and test potential authentication pathways within the environment.

Figure 3: A selection of NTLM authentication events in rapid succession from a representative intrusion.

In some environments, within minutes of a gateway-connected event, internal network discovery was conducted, including NTLM anonymous logon attempts consistent with host and service discovery.

Despite evidence of successful post-authentication access in a handful of intrusions, observed follow-on activity remained limited. Across investigated cases, the activity did not progress substantially beyond the initial SMB session setup and lightweight reconnaissance behavior commonly associated with Impacket tooling.

Arctic Wolf identified and disrupted the activity before the threat actors could establish persistence or conduct broader post-compromise operations within affected environments.

Notably, this post-exploitation activity differed from the majority of observed intrusion attempts, which primarily consisted of repeated GlobalProtect authentication failures and limited portal or gateway authentication activity without clear evidence of successful VPN tunnel establishment or subsequent internal network interaction.

Conclusion

The observed activity associated with CVE-2026-0257 demonstrated that, under vulnerable configurations, threat actors were able to successfully interact with and, in some cases, abuse the GlobalProtect authentication workflow to establish unauthorized VPN access.

Across investigated intrusions, most activity was limited to repeated authentication attempts and intermittent successful portal or gateway authentication activity without clear evidence of successful post-authentication operations. However, a smaller subset of intrusions progressed further into authenticated VPN session establishment and limited internal network interaction.

In cases where VPN connectivity was successfully established, Arctic Wolf observed immediate follow-on activity consistent with Impacket tooling, including SMB session setup requests, NTLM anonymous logon activity, network share enumeration, and limited domain user discovery. The rapid transition from VPN session establishment to internal reconnaissance strongly suggested the threat actors intended to leverage unauthorized VPN access as an initial foothold for subsequent post-compromise operations.

For defenders, the priority should be to identify which suspicious GlobalProtect sessions from IP space associated with VPS hosting became working tunnels and then determine what those tunnel IPs did next. Arctic Wolf has detections in place for the activities observed in this campaign through our Managed Detection and Response service.

How Arctic Wolf Protects Its Customers

Arctic Wolf is committed to ending cyber risk, and when active campaigns are identified, we move quickly to protect our customers. We have leveraged threat intelligence around this campaign to enhance detections in the Arctic Wolf® Managed Detection and Response (MDR) service, subject to the customer environment and available telemetry. Customers in scope of this campaign have been notified; detections and response recommendations have been deployed to affected accounts.

As we track this campaign and discover new information, we may further refine our detections to account for additional indicators of compromise (IOCs) and techniques leveraged by the threat actors behind this malicious activity.

Detection Guidance

GlobalProtect Authentication Plane

Defenders should focus on authentication anomalies combined with unexpected VPN session establishment from non-corporate infrastructure. These are the earliest high-signal indicators.

  • CVE-2026-0257 exploitation signals:
    • Cookie decryption error followed immediately by successful authentication in the same session.
    • Failed authentication attempt (cookie error) immediately preceding a clean authentication success.
  • Suspicious authentication activity:
    • Successful GlobalProtect logins as admin or other privileged accounts from VPS hosting provider ASNs.
    • Logins from Tor exit nodes, VPS IP addresses, or unfamiliar geographies.
    • Authentication events from machine names including GP-CLIENT, DESKTOP-GP01, or kali.
    • Connections using spoofed MAC address aa:bb:cc:dd:ee:ff.

Post-Exploitation Behavior

Focus on rapid automated activity immediately following VPN session establishment.

  • Anomalous authentication and enumeration activity:
    • Signs of Impacket or suspicious NTLM activity following VPN session establishment.
    • Rapid SMB authentication attempts against multiple hosts.
    • NTLM anonymous logon attempts from VPN-assigned IPs.

Network Monitoring

Focus on source IP infrastructure and session characteristics that deviate from expected corporate VPN usage.

  • High-signal source indicators:
    • Successful authentication from known VPS hosting provider ASNs.
    • Connections from Tor exit nodes (e.g., AS60729, AS215125).
  • Session characteristics:
    • Kali Linux or browser-based client fingerprints in VPN connection logs.

Appendix

For additional Appendix sections referenced in this report, please see our public GitHub repository.

Legal disclaimer: Attribution reflects Arctic Wolf Labs’ assessment as of the report period and may evolve with new evidence. References to threat actor identity, nexus, and intent are analytical judgments, not statements of legal fact. This alert is provided for informational purposes only and does not constitute a guarantee of detection or prevention. Defensive effectiveness varies by environment, configuration, and available telemetry. 

References

About Arctic Wolf Labs

Arctic Wolf Labs is a group of elite security researchers, data scientists, and security development engineers who explore security topics to deliver cutting-edge threat research on new and emerging adversaries, develop and refine advanced threat detection models with artificial intelligence and machine learning, and drive continuous improvement in the speed, scale, and detection efficacy of Arctic Wolf’s solution offerings.

Arctic Wolf Labs brings world-class security innovations to not only Arctic Wolf’s customer base, but the security community at large.