Hackers Launch Widespread Attacks on Palo Alto GlobalProtect Portals from 7,000+ IPs
ID: 0d880dfd-bc6e-5ffa-8f3d-7b560addc7de
STIX ID: report--0d880dfd-bc6e-5ffa-8f3d-7b560addc7de
Feed Name: cybersecurityNews.com
Threat actors have initiated a widespread exploitation campaign against internet-facing Palo Alto GlobalProtect VPN portals, leveraging known critical vulnerabilities and misconfigurations (including pre-auth access and weak/default credentials). Scanning and exploitation activity from thousands of IPs has been observed targeting UDP port 4501 and GlobalProtect endpoints, with confirmed cases of session token exfiltration, lateral movement, and malware persistence; vendors and CISA have issued urgent advisories and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
