logo

GlobalProtect VPN portals probed with 2.3 million scan sessions

ID: 01ec06e3-f9a1-57a3-986e-197f1bb28dd2

STIX ID: report--01ec06e3-f9a1-57a3-986e-197f1bb28dd2

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2025-11-20

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

GreyNoise reported a significant escalation in malicious scanning of Palo Alto Networks GlobalProtect VPN login portals beginning 14 November 2025, with a 40x 24-hour surge and ~2.3 million sessions to the /global-protect/login.esp endpoint observed through 19 November. The activity is linked to prior campaigns by recurring fingerprints and ASN reuse (notably AS200373 and AS208885), targets regions including the US, Mexico and Pakistan, and—while historically such spikes often precede vulnerability disclosures—Palo Alto Networks reported no evidence of compromise after investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.