// 5 CVE · 4 EXPLOIT IN THE LAST 24H→
The Operation Master group exploited CVE-2026-0257 in Palo Alto Networks GlobalProtect to breach corporate infrastructure across four countries, steal data from over nine databases, and feed a multi-tenant fraud platform that generated 2.4 million messages aimed at consumers.

On September 28, 2026, the full arc of a campaign that turned a bypassed authentication into an assembly line of personalized fraud came to light. The Operation Master group exploited CVE-2026-0257 in Palo Alto Networks GlobalProtect gateways to compromise corporate infrastructure in four countries, steal data from more than nine databases, and reinvest it in a multi-tenant fraud platform that generated 2.4 million messages directed at consumers. The operation, active from April through mid-September, represents an operational mutation: traditional perimeter access becomes a direct pipeline to reputational and financial damage against unwitting customers.

Key Takeaways
  • CVE-2026-0257, a GlobalProtect authentication bypass with CVSS 7.8, enabled VPN sessions without valid credentials on seven gateways across four countries
  • Operation Master reconstructed 24,558 debtor records from a single theft and generated 622,666 personalized links for individual victim targeting
  • The fraud platform sent 2,468,335 emails and 1,487,294 SMS by September 16, 2026, hijacking 12 Microsoft 365 mailboxes and 8 SMS gateways
  • Rapid7 observed active exploitation from May 17, 2026, four days after vendor disclosure; CISA added the vulnerability to the KEV catalog on May 29

The CVE That Opened the Door: From 4.7 to 7.8 in Five Weeks

CVE-2026-0257 was initially rated CVSS 4.7 by Palo Alto Networks. Severity was raised to 7.8 after confirmation of active exploitation on unpatched devices lacking mitigations, according to the vendor advisory and Rapid7 analysis. The vulnerability affects the GlobalProtect component of PAN-OS: an authentication bypass that allows establishing VPN sessions without presenting valid credentials.

Rapid7 observed large-scale exploitation starting May 17, 2026, four days after the advisory publication. On May 29, 2026, CISA added CVE-2026-0257 to the Known Exploited Vulnerabilities catalog. According to the researcher's analysis, attackers used spoofed MAC addresses, specific machine names, and recurring IP addresses to bypass authentication controls.

The operational significance lies in the reaction speed: four days between disclosure and massive exploitation. This window allowed Operation Master to establish persistence before most organizations completed patching.

Industrial Reconnaissance: 277 Million Hosts for 81 Targets

After VPN access, the group conducted systematic scanning of the internal perimeter. According to the SOCRadar report, Operation Master assessed 277,480,448 hosts in 22 cumulative masscan runs, isolating 1,506,516 distinct endpoints and selecting 81 priority organizations after relevance filtering. Reconnaissance led to the identification of internal databases vulnerable to SQL injection, with subsequent pivot to remote execution via xp_cmdshell.

At least nine databases were compromised. From a single theft, researchers reconstructed 24,558 debtor records containing identities, amounts, and contractual references. The data was initially offered for sale on underground forums by the identity "masterblack," associated with the email address cyberkill2025@gmail.com, with the energy sector among the first categories listed.

The double exfiltration used DNS subdomain tunneling and rclone for cloud storage synchronization. For internal posture control, the group employed AdaptixC2 on at least two Windows server identities, maintaining privileged access during reconnaissance and data staging phases.

From Data Sale to Invoice Factory: 2.4 Million Messages and a Multi-Tenant Panel

The qualitative shift in the campaign occurred in the reuse of data. The same organizations appeared in sales lists weeks before their details were loaded into fraud campaigns, according to SOCRadar's reconstruction. This indicates a dual-tier monetization: first raw sale, then direct use in automated platforms.

The fraud panel, active from April through mid-September 2026, generated 622,666 personalized links for individual targeting. As of September 16, 2026, 2,468,335 emails and 1,487,294 SMS had been sent, with 317,696 click events recorded by September 14. The delivery infrastructure hijacked 12 legitimate Microsoft 365 mailboxes and 8 SMS gateways, with WhatsApp templates directing to fraudulent invoice documents.

Payment records in the panel indicate a total generated invoice value of R$ 150.4 million, with R$ 38.9 million corresponding to invoices with at least one click. These figures represent exposure and logged billing, not confirmed collections. The panel included a serverless PIX proxy to manage transactions on the Brazilian banking network, integrating the monetary circuit from message dispatch to potential collection.

"Operation Master highlights a dangerous convergence in the modern threat landscape: perimeter exploits long associated with cyber espionage and ransomware are now being systematically industrialized to fuel automated, localized financial fraud ecosystems" — SOCRadar Threat Research Unit

AI-Assisted Tooling and Multi-Tenant Architecture

The SOCRadar report documents an AI-agent workspace with over 36 automation subagents, employed to generate message variants, adapt invoice templates, and manage routing logic for personalized links. The use of AI-assisted tools enabled contextual localization of communications: invoices reproduced layouts, terminology, and references derived from stolen databases, reducing recipient recognition rates.

The panel's multi-tenant architecture suggests a design oriented toward scalability and recycling for multiple actors or campaigns. The infrastructure went offline in mid-September 2026; its subsequent operational status is not determinable from the available dossier.

What to Do Now

For organizations with GlobalProtect/PAN-OS gateways, priority actions derive directly from verified sources:

  • Verify patch application for CVE-2026-0257 on all affected PAN-OS versions, prioritizing internet-exposed gateways without intermediate mitigations
  • Check VPN session logs for connections from anomalous MAC addresses, non-standard machine names, and recurring access patterns on May 17–31, 2026, per Rapid7's published IOCs
  • Inspect Microsoft 365 mailboxes and corporate SMS gateways for signs of compromise or unauthorized forwarding, given Operation Master's systematic use of these assets
  • Review internal databases accessible from the VPN network for SQL injection vulnerabilities and xp_cmdshell status, with particular attention to systems containing customer/debtor data

Why the Risk Perimeter Has Shifted

Operation Master's campaign redefines the value chain of perimeter breaches. No longer exfiltration for ransomware or industrial espionage, but direct conversion into damage against the breached organization's customer base. Targeted consumers received invoices with their own real data, on authentic channels, with plausible payment instructions. The reputational damage for the source enterprises is separate from and potentially greater than the technical cost of the incident.

For the threat intelligence sector, the case documents an operational convergence: initial access tools remain conventional, while monetization adopts automated, AI-assisted, multi-tenant tooling. The temporal proximity between disclosure and exploitation—four days—and the campaign's five-month duration indicate that patching speed remains the determining factor, but is insufficient without monitoring of internal posture post-access.

Sources

Information has been verified against cited sources and updated at time of publication.

Sources


Sources and references
  1. cybersecuritynews.com
  2. cryptika.com
  3. csoonline.com
  4. security.paloaltonetworks.com
  5. rapid7.com
  6. socradar.io