Arctic Wolf says Qilin is breaching networks through a PAN-OS GlobalProtect authentication bypass, and separately, two SonicWall SMA1000 vulnerabilities were run as zero-days against customer appliances for weeks before either vendor's disclosure caught up. Both cases follow the same shape: a VPN gateway sitting on the network perimeter, exploited in the field, patched only after someone outside the vendor noticed the traffic. Custom malware went onto the SonicWall boxes during that window. The GlobalProtect bypass gave Qilin the initial foothold it needed before ransomware ever touched a file server.
Neither disclosure names a date range for when exploitation actually started, only when it was caught. For a CISO running either product, the test isn't whether the patch is applied. It's whether SMA1000 and GlobalProtect logs from the unpatched period get pulled and checked for the indicators Arctic Wolf and the SonicWall advisory already published, because a patched appliance and a clean appliance are not the same claim.