Cyber Threat Brief — October 11 2026
1. Palo Alto GlobalProtect — CVE-2026-0257 now tied to Qilin and Settra ransomware
TL;DR: ReliaQuest says the Qilin and Settra ransomware groups are using the GlobalProtect authentication bypass CVE-2026-0257 to get VPN sessions without a password, and Arctic Wolf had already traced Qilin encryptions to it. Check every portal and gateway for authentication override cookies, patch or disable them, then end all active GlobalProtect sessions.
What’s New:
- ReliaQuest’s update, reported on Oct 11, adds Settra alongside Qilin and mentions Cobalt Strike, BloodHound, and SharpHound activity after the VPN login. ReliaQuest’s own page was not reachable, so this comes from Cyber Security News coverage.
- Arctic Wolf’s July report ties June Qilin intrusions to this flaw, with the ransomware staged at
C:\PerfLogs\win.exeand domain-wide encryption in some cases. - The flaw is in CISA KEV since May 29, and exposure needs authentication override cookies enabled plus a specific certificate configuration, per the PAN advisory.
- Patching does not end sessions an attacker already holds, so end active GlobalProtect sessions after the upgrade.
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
| GlobalProtect portal or gateway on PAN-OS older than 12.1.7, 11.2.12, 11.1.15, or 10.2.18-h6 (or the branch hotfix in the advisory) with authentication override cookies enabled (CVE-2026-0257) | Vulnerable configuration | T1190 | PAN-OS configuration / Panorama | In each portal Agent profile, Authentication tab, and each gateway Authentication Override tab, look for “Generate cookie for authentication override” or “Accept cookie for authentication override”. Upgrade to the fixed build, or untick both options, or give the cookie its own dedicated certificate. |
GlobalProtect log subtype gateway-auth with authentication method Cookie, user admin, and result success | IOC | T1190 | PAN-OS GLOBALPROTECT log (Splunk pan:globalprotect) | Search back to 2026-05-13 for gateway-auth with method Cookie and user admin, and list the source IPs and their ASNs (Rapid7’s sample shows Cookie/admin logins from 104.207.144[.]154 and 146.19.216[.]125). Treat any hit that also has a gateway-connected event as a working VPN session. |
Client machine name kali (also GP-CLIENT and DESKTOP-GP01) on a GlobalProtect session | IOC | T1133 | PAN-OS GLOBALPROTECT log, machine name field | Search GlobalProtect logs for machine name kali, GP-CLIENT, or DESKTOP-GP01. ReliaQuest says kali alone is a lead, not proof, so confirm with the user. |
Spoofed MAC aa:bb:cc:dd:ee:ff | IOC | T1133 | PAN-OS GLOBALPROTECT log, host ID / MAC field | Search for this exact MAC on any GlobalProtect login. Rapid7 and Unit 42 saw it in both May waves. |
Source IP 108.61.229[.]217 | IOC | T1133 | Firewall / PAN-OS GLOBALPROTECT log | Block 108.61.229[.]217 and search since 2026-06-01 for any GlobalProtect session from it. Arctic Wolf saw it in multiple intrusions as both the exploit source and the VPN session origin. |
C:\PerfLogs\win.exe run as C:\PerfLogs\win.exe --password <value> --no-admin through C:\Windows\SysWOW64\cmd.exe | Ransomware payload | T1486 | Sysmon 1 and 11 / EDR | Alert on any executable created or launched from C:\PerfLogs\. If win.exe is present, isolate the host and look for the same file at \\<host>\c$\Windows\Temp\win.exe. |
rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump <lsass pid> C:\Windows\Temp\output.odt full | Process behavior | T1003.001 | Sysmon 1 / Windows 4688 | Hunt for rundll32.exe with comsvcs.dll and MiniDump in the command line, and for the file C:\Windows\Temp\output.odt. Arctic Wolf saw it run from a service with a random name. |
ntdsutil.exe "activate instance ntds" "ifm" "create full C:\Windows\Temp\NTDS" | Process behavior | T1003.003 | Sysmon 1 / Windows 4688 | Hunt for ntdsutil.exe with ifm and create full, and for the folder C:\Windows\Temp\NTDS\ on any host that is not a domain controller maintenance box. |
Registry Run value name matching *[a-z]{6} in a Run key, with data pointing to C:\PerfLogs\win.exe | Persistence | T1547.001 | Sysmon 13 / EDR registry events | Query Run-key writes where the value name is an asterisk plus six lowercase letters and the data contains C:\PerfLogs\. Arctic Wolf suspects this is a Qilin builder trait. |
PowerShell [System.Diagnostics.Eventing.Reader.EventLogSession]::GlobalSession.ClearLog looped over Get-WinEvent -ListLog * | Process behavior | T1070.001 | PowerShell 4104 / Windows Security 1102 | Search script block logs for GlobalSession.ClearLog, and alert on Security event 1102 on more than one host in an hour. This is the step just before encryption. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | Partial — Dump LSASS via comsvcs DLL; Ntdsutil Export NTDS | Both cover only the credential-theft steps. No analytic reads GlobalProtect cookie authentication. |
| Elastic | Partial — Potential Credential Access via Windows Utilities | It matches rundll32 with MiniDump and ntdsutil with cr*fu*, but nothing reads the gateway login. |
| Sigma | Partial — Process Memory Dump Via Comsvcs.DLL; Invocation of Active Directory Diagnostic Tool (ntdsutil.exe) | The only GlobalProtect rules are for CVE-2024-3400, not this flaw. Nothing covers C:\PerfLogs\win.exe or the Run-key pattern. |
Detection index: local mirrors of Splunk security_content, elastic detection-rules, and SigmaHQ as present on the box; commit hashes were not recorded and the mirrors were not refreshed on 2026-10-11.
Hunt hint: Export GlobalProtect logs since 2026-05-13 and keep only gateway-auth events with method Cookie. For each source IP, check whether a gateway-connected event followed, because only a minority of attempts became tunnels. For every tunnel, pull the assigned VPN client address and look for SMB and NTLM activity from it within minutes, which Arctic Wolf tied to Impacket-style reconnaissance. Also check for PSEXESVC.exe service creation and C$ writes from that address. Arctic Wolf’s other kali session sources were 108.61.75[.]232, 199.247.22[.]193, 2.188.33[.]52, and 70.34.205[.]43, and Unit 42 lists earlier May sources such as 104.207.144[.]154. If you find a tunnel from any of them, assume domain credentials are lost and plan for a double KRBTGT reset.
Sources: Palo Alto Networks advisory · Arctic Wolf, Qilin intrusions · Rapid7 analysis and log samples · Unit 42 threat brief · Cyber Security News on the ReliaQuest update · X post relaying ReliaQuest · CISA KEV entry for CVE-2026-0257
Status Updates
- CVE-2026-105133 and CVE-2026-105134 (AhsayCBS): Ahsay now says its 10.3.4.0 release did not fully fix either flaw, and v10 partners must install hotfix 10.3.4.45 and reboot. Check the build, restrict the admin interface, and investigate hosts that were exposed. Ahsay alert, Huntress, original brief.
- CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199, CVE-2023-22894 (Flax Typhoon KEV additions): The CISA due date is today, Sunday 2026-10-11, and no further KEV additions have appeared since Oct 8. Original brief.
- CVE-2026-82077 (PaperCut NG/MF): watchTowr published a full unauthenticated chain and a detection artefact generator on Oct 9 for 26.0.4-PO build 76508. The flaw is fixed in 26.0.5, and an X post from a Huntress analyst reports possible exploitation in one case that is unconfirmed. watchTowr, X post, original PaperCut brief.
- CVE-2026-102255 (SonicWall SMA1000): No change today, and still no vendor confirmation of exploitation or KEV listing. Original brief.
- HPE ClearPass (HPESBNW05158, not yet briefed): Still no ITW or public PoC; we retire it from the deferred queue on 2026-10-12 if that holds.
- Deferred, not yet briefed: Telegram Desktop CVE-2026-107181 (fixed in 7.2.9, public PoC, no exploitation seen), WatchGuard PSKMAD CVE-2026-13043 (public PoC, local attack, no exploitation seen), and the Claude “Adception” ClickFix lure (still a single origin).
- Watching (no change): CVE-2026-85097 (10-09), CVE-2026-107406 (10-09), GhostAction (10-10), CVE-2026-104286 (10-02), CVE-2026-102489 and CVE-2026-102490 (10-03), CVE-2026-88779 (10-04), CVE-2026-61500 and CVE-2026-88062 (10-04), CVE-2026-76504 (10-01), CVE-2026-21589 (10-06), CVE-2026-83548 and CVE-2026-83549 (09-03).