GlobalProtect VPN portals probed with 2.3 million scan sessions
ID: 01ec06e3-f9a1-57a3-986e-197f1bb28dd2
STIX ID: report--01ec06e3-f9a1-57a3-986e-197f1bb28dd2
Feed Name: Bleeping Computer
GreyNoise reported a significant escalation in malicious scanning of Palo Alto Networks GlobalProtect VPN login portals beginning 14 November 2025, with a 40x 24-hour surge and ~2.3 million sessions to the /global-protect/login.esp endpoint observed through 19 November. The activity is linked to prior campaigns by recurring fingerprints and ASN reuse (notably AS200373 and AS208885), targets regions including the US, Mexico and Pakistan, and—while historically such spikes often precede vulnerability disclosures—Palo Alto Networks reported no evidence of compromise after investigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
