Hackers Scanning From 24,000 IPs to Gain Access to Palo Alto Networks GlobalProtect Portals
ID: 42a244de-8614-5082-ad1d-af9d63af0f15
STIX ID: report--42a244de-8614-5082-ad1d-af9d63af0f15
Feed Name: cybersecurityNews.com
Researchers observed a surge of malicious scanning activity against Palo Alto Networks GlobalProtect VPN portals between March 17–26, 2025, involving ~24,000 unique source IPs (predominantly US and Canada). GreyNoise classified most sources as suspicious and identified three JA4h fingerprints tied to the login scanner tool, with a large share of traffic linked to ASN200373 (3xK Tech GmbH); the report references CVE-2024-3400 (PAN-OS command injection, CVSS 10.0) and advises immediate log review, threat hunting, patching, and blocking of identified IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
