Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Launch Widespread Attacks on Palo Alto GlobalProtect Portals from 7,000+ IPs

Recent activities have indicated an increase in exploitation attempts targeting Palo Alto Networks' GlobalProtect VPN portals. These actions are part of a broader campaign against remote access infrastructure.

Recent activities have indicated an increase in exploitation attempts targeting Palo Alto Networks' GlobalProtect VPN portals. These actions are part of a broader campaign against remote access infrastructure.

According to GrayNoise tracking, scans and exploitation efforts have been detected from over 7,000 unique IP addresses globally. This situation poses a significant concern for organizations utilizing GlobalProtect for secure remote access.

The attacks, first observed in late November 2025, exploit vulnerabilities in GlobalProtect gateways, specifically those accessible via UDP port 4501 on the internet.

Reports from Shadowserver and other threat intelligence sources indicate that the IP addresses involved originate from a variety of sources, including residential proxies, bulletproof hosting services, and compromised VPS instances across Asia, Europe, and North America.

Palo Alto Networks' GlobalProtect has been a frequent target due to its widespread use in enterprise environments. Unaddressed vulnerabilities, such as CVE-2024-3400, remain a risk for systems that have not been updated with the latest patches.

Recent activities have indicated an increase in exploitation attempts targeting Palo Alto Networks' GlobalProtect VPN portals.
Olivia Harper · Thehackingpost

Recent attacks leverage misconfigurations that allow pre-authentication access, such as default credentials or exposed admin portals. Attackers have been employing tools and scripts to enumerate portals, conduct brute-force login attempts, and deploy malware for persistent access.

Mandiant's latest threat report suggests that similar tactics have been used by groups affiliated with state actors, although no definitive attribution has been made for the current wave of attacks.

Unusual UDP traffic spikes to port 4501 HTTP requests to /global-protect/login.urd endpoints

Confirmed breaches have resulted in the exfiltration of session tokens, enabling further unauthorized access within corporate networks.

Advertisement

On December 5, Palo Alto Networks released an advisory recommending the enforcement of multi-factor authentication (MFA), restriction of portal exposure through firewall configurations, and application of the latest patches.

CISA has included relevant indicators of compromise (IOCs) in its Known Exploited Vulnerabilities catalog, advising federal agencies to apply patches within 72 hours.

Experts suggest air-gapping critical portals, implementing zero-trust segmentation, and monitoring for communications with command-and-control servers, particularly those hosted on platforms like AWS or Azure.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories