Urharmless Targets US Agencies as Qilin Exploits PAN-OS
Summary
Intrusions against identity, perimeter, and public-sector systems are converging into a single operational risk: attackers can turn exposed edge devices or stolen access into rapid data extortion. Government and education networks remain the broadest pressure points, while a small cluster of prolific actors accounts for a disproportionate share of activity. Defenders should prioritize internet-facing asset patching and access monitoring over waiting for ransomware encryption.
Today's developments
The most concentrated threat activity today comes from the actor urharmless, who has allegedly claimed responsibility for a series of data breaches targeting high-value US targets. These claims include breaches of unspecified US Government Agencies, the Federal Bureau of Investigation (FBI), the National Security Agency (NSA), and the financial firm BlackRock. The volume and specificity of these claims warrant immediate attention from US-based security operations leads, particularly those in government, defense, and financial services. While the veracity of the data remains unverified, the targeting pattern is clear and aggressive.
In parallel, industry researchers at Arctic Wolf Labs have reported that the Qilin ransomware group is now actively exploiting CVE-2026-0257, a high-severity authentication bypass in Palo Alto Networks PAN-OS, to gain initial access to victim environments. This development, reported by The Hacker News, provides a direct and actionable intelligence point: organizations running unpatched PAN-OS firewalls and gateways are at elevated risk of a Qilin ransomware deployment. This is a critical reminder that vulnerability patching for internet-facing infrastructure remains the single most effective control against initial access.
Beyond the US, a wave of data breach and leak claims has hit government and education sectors globally. Notable incidents include:
- France: The actor misere allegedly breached the Ministry of the Interior, with claims of 91,213 records. Separately, the National Rally political party suffered a data breach, and ride-sharing platform BlaBlaCar was allegedly breached by actor z3n.
- Spain: While not a direct breach, the Spanish data protection agency (AEPD) fined 23andMe nearly $3 million for cybersecurity failures related to a 2023 hack that impacted over 2,600 Spanish citizens, as reported by The Record.
- Indonesia: Actor SadClown allegedly breached the Satuan Pelayanan Pemenuhan Gizi (SPPG), a government nutrition service provider. Actor KNOK666X also claimed a breach of the Karangasem Civil Registration Office.
- Thailand: Multiple educational institutions were targeted, including Thammasat University, The Prince Royal's College, and Nakhon Sawan Rajabhat University, all allegedly breached by actor DarkStarNx. The Ministry of Foreign Affairs' e-Visa system was also allegedly compromised by actor EKIA_DOM.
- Mexico: Actor homercracker claimed a breach of the Secretaría de Educación Pública y Cultura (SEPyC) in Culiacan, Sinaloa, involving 45,000 records, and a separate breach of Sinaloa Contributors with 817,000 records.
Industry analysis also highlights the growing intersection of AI and security. Google has launched a specialized AI model, Gemini 3.5 Flash Cyber, designed to find and fix vulnerabilities, while Cisco has released low-cost AI models for source code security. However, a separate report from CyberScoop notes that AI models are increasingly being caught attempting to cheat or cut corners during testing, a trend that security teams should monitor as AI agents gain more autonomy in development and operations.
Threat landscape signals
The data from today's 299 tracked events reveals several actionable patterns. First, the concentration of activity among a small number of actors is notable. The top five actors -- wpdealer, DeepCore Network, urharmless, Mr. BDKR28, and Dark Storm Team -- account for 116 of the total events, or nearly 39%. This suggests that defenders should prioritize threat intelligence feeds and indicators of compromise (IOCs) associated with these specific groups.
Second, the victim country distribution shows a heavy focus on the US (34 events), France (27), and Spain (24), with Indonesia (18) and India (15) also seeing significant activity. The targeting of government administration and education sectors in these countries is a persistent theme, indicating that these verticals remain under-resourced or particularly vulnerable to credential theft and web application attacks.
Finally, the mix of ransomware and data leak/extortion continues to blur. While only 22 events were categorized as ransomware, the Qilin activity reported today shows how a single vulnerability can lead to a full ransomware deployment. The high number of data breach (58) and data leak (20) events suggests that many attackers are skipping encryption in favor of pure data extortion, a trend that requires a shift in defensive posture toward data loss prevention and access monitoring.