Edge Appliances Become Ransomware’s Preferred Front Door

Perimeter boxes are no longer just exposed services to patch. Qilin is already using the GlobalProtect authentication bypass as a foothold, and the same edge-access pattern is spreading across VPN and firewall products from multiple vendors. Arctic Wolf says CVE-2026-0257 in Palo Alto GlobalProtect portal and gateway was exploited within days of disclosure, with intrusions in June tied to Qilin. The same cluster also points to Fortinet FortiGate, Citrix NetScaler, and Check Point Remote Access VPN, which shows the attack surface is the trust boundary itself, not one brand or one CVE. That changes the defensive problem. Once the edge device falls, it becomes a trusted path into the internal network for ransomware staging and follow-on access, so patching one appliance class no longer covers the risk.

Part of the PlainSec briefing for 2026-07-25

Sources