A critical vulnerability in Palo Alto's GlobalProtect VPN has been exploited by the Qilin ransomware gang to bypass authentication and breach victim networks. This flaw, identified in PAN-OS, allows attackers to gain unauthorized access without credentials. The Qilin gang's exploitation of this bug marks a significant escalation in their tactics, underscoring the need for prompt patching and mitigation. Arctic Wolf has reported that the vulnerability is being actively exploited in ransomware attacks1. The fact that a prominent ransomware gang is leveraging this bug to infiltrate networks highlights the severity of the issue. As a result, organizations using affected GlobalProtect VPN versions must take immediate action to apply patches and secure their infrastructure. This breach has significant implications for the security posture of affected organizations, so what matters most to practitioners is the potential for downstream regulatory and supply-chain repercussions that may arise from such a high-profile vulnerability exploitation.