Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

2026-05-31T01:23:28Z3ddd26af0902203e8fe5cd3d1c87a020463130f4df243f06e2a86cbc097645c3
CIFSwitchCVE-2026-0257CVE-2026-35616Charter CommunicationsChatGPT abuseDBSCDDoS-as-a-ServiceEKZFortiClient EMSGlobalProtectGoogle ChromeGreyVibe threat cluster','BTMOB','Android RAT','FIFA fraud','23&LinuxPalo Alto NetworksShinyHuntersVPNbotnetbotnet takedowndata breachinfostealerlocal privilege escalationmalwarephishingsession cookie protectionsocial engineering

What happened

Multiple active threats and high-impact incidents reported: attackers are actively exploiting a PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) to breach corporate networks, and an authentication bypass in FortiClient EMS (CVE-2026-35616) is being used to deploy an infostealer (EKZ). A new local Linux kernel privilege escalation called “CIFSwitch” can yield root on multiple distributions. Threat actors are also abusing ChatGPT share links to host fake outage pages to deliver malware, commercial DDoS-as-a-service markets and a 17M‑device botnet takedown were highlighted, and several大

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
3ddd26af0902203e8fe5cd3d1c87a020463130f4df243f06e2a86cbc097645c3
Enrichment time
2026-05-31T01:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.