CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple Customers

2026-06-01T02:51:48Z9b57e2003782b8540cbe26631a1d85288131558be5361467b51889b302417da5
active-exploitationai-assisted-malwareaptasocksauthentication-bypassbackup-recovery-keysbotnetcookie-forgerycrypto-stealercve-2026-0257cve-2026-26980data-leakghost-cmsglobalprotectgreyvibepalo-altopan-osphishingrapid7shinyhunterssignalsupply-chaintrapdoorvpnwindows-zero-day-dumps','btmob','android-rat

What happened

The feed highlights a critical active exploitation: CVE-2026-0257 in Palo Alto Networks PAN-OS (GlobalProtect portal/gateway) allows attackers to forge authentication cookies and bypass VPN login; Rapid7 confirmed active exploitation across multiple customers since May 17 despite a PAN-OS patch released May 13. Other notable items: Ghost CMS mass compromises via CVE-2026-26980 now used in ClickFix attacks; a TrapDoor crypto-stealer supply-chain campaign affecting npm/PyPI/Crates.io packages; a Signal-targeted phishing campaign that steals backup recovery keys; a ShinyHunters data leak of (al)l

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
9b57e2003782b8540cbe26631a1d85288131558be5361467b51889b302417da5
Enrichment time
2026-06-01T02:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple Customers · Baitaphish