Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Operation Master exploited GlobalProtect CVE-2026-0257, deployed AdaptixC2, and ran large-scale credential theft and invoice fraud.
Researchers detailed Operation Master, a cybercrime campaign that exploited CVE-2026-0257, an authentication-bypass flaw in Palo Alto Networks GlobalProtect portals and gateways. Palo Alto confirmed active exploitation and advised installing fixed PAN-OS or Prisma Access releases and disabling unneeded Authentication Override. The actor scanned 277.5 million addresses, selected 81 organizations, used SQL injection and xp_cmdshell for PowerShell execution, stole NTDS and registry hives, and deployed AdaptixC2. Stolen data fed a fraud platform that generated more than 2.4 million email and SMS messages and 622,666 phishing links before going offline in mid-September.