Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Attacks on Palo Alto PAN-OS Global Protect Login Portals Surge from 2,200 IPs

As of Sat, Oct 7, 2025, over 2,200 unique IP addresses have been identified conducting reconnaissance operations targeting Palo Alto Networks PAN-OS GlobalProtect login portals. This marks a significant increase from the 1,300 IP addresses recorded…

As of Sat, Oct 7, 2025, over 2,200 unique IP addresses have been identified conducting reconnaissance operations targeting Palo Alto Networks PAN-OS GlobalProtect login portals. This marks a significant increase from the 1,300 IP addresses recorded earlier in the week, representing the highest scanning activity in the past 90 days, as per GreyNoise Intelligence.

Significant Increase in Scanning Activity

The reconnaissance campaign began on Mon, Oct 3, 2025, with a 500% increase in scanning activity observed by researchers, involving approximately 1,300 unique IP addresses. This initial surge was notable as the largest scanning event recorded in three months, with daily volumes previously not exceeding 200 IPs during the preceding 90-day period.

Analysis by GreyNoise indicates that 91% of the malicious IP addresses are geolocated in the United States, with additional clusters found in the United Kingdom, the Netherlands, Canada, and Russia. Approximately 12% of all ASN11878 subnets have been allocated to scanning Palo login portals, indicating a significant infrastructure commitment to the operation. The attacks are characterized by systematic iterations through large credential databases, indicative of automated brute-force operations against GlobalProtect SSL VPN portals.

GreyNoise has released a dataset containing unique usernames and passwords from Palo login attempts observed in the past week, aiding security teams in assessing potential credential exposure. Technical analysis reveals that 93% of participating IP addresses were classified as suspicious, while 7% were designated as malicious. The scanning activity exhibits regional clustering patterns with distinct TCP fingerprints, suggesting multiple coordinated threat groups operating simultaneously.

Technical analysis reveals that 93% of participating IP addresses were classified as suspicious, while 7% were designated as malicious.
Robert Langley · Thehackingpost

Correlations with Other Reconnaissance Operations

Potential correlations have been identified between the surge in Palo Alto scanning and concurrent reconnaissance operations targeting Cisco ASA devices . Both campaigns share dominant TCP fingerprints linked to infrastructure in the Netherlands, along with similar regional clustering behaviors and tooling characteristics. This suggests a broader reconnaissance campaign against enterprise remote access solutions, though the exact relationship between these activities is still under investigation.

Security teams should consider the following measures:

Implement IP blocklisting of known malicious addresses. Enhance monitoring of GlobalProtect portal authentication logs. Implement additional access controls for remote VPN connections.

Advertisement

The targeted nature of these attacks suggests the use of public reconnaissance platforms like Shodan or Censys, or proprietary fingerprinting operations to identify vulnerable Palo Alto devices.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories