Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
2026-05-31T01:23:28Z•3ddd26af0902203e8fe5cd3d1c87a020463130f4df243f06e2a86cbc097645c3
CIFSwitchCVE-2026-0257CVE-2026-35616Charter CommunicationsChatGPT abuseDBSCDDoS-as-a-ServiceEKZFortiClient EMSGlobalProtectGoogle ChromeGreyVibe threat cluster','BTMOB','Android RAT','FIFA fraud','23&LinuxPalo Alto NetworksShinyHuntersVPNbotnetbotnet takedowndata breachinfostealerlocal privilege escalationmalwarephishingsession cookie protectionsocial engineering
What happened
Multiple active threats and high-impact incidents reported: attackers are actively exploiting a PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) to breach corporate networks, and an authentication bypass in FortiClient EMS (CVE-2026-35616) is being used to deploy an infostealer (EKZ). A new local Linux kernel privilege escalation called “CIFSwitch” can yield root on multiple distributions. Threat actors are also abusing ChatGPT share links to host fake outage pages to deliver malware, commercial DDoS-as-a-service markets and a 17M‑device botnet takedown were highlighted, and several大
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 3ddd26af0902203e8fe5cd3d1c87a020463130f4df243f06e2a86cbc097645c3
- Enrichment time
- 2026-05-31T01:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.