A significant increase has been observed in scanning activity targeting Palo Alto Network GlobalProtect, with researchers concerned that it may be a prelude to an upcoming attack or vulnerability exploit.
See also: Palo Alto Networks flags new firewall flaw as exploitable

According to GreyNoise, which reports this activity, the scan includes over 24,000 unique Palo Alto IP addresses. The activity peaked on March 17, 2025, reaching 20,000 unique IP addresses per day, and continued at that level until March 26.
Of these IP addresses, 23,800 are classified as “suspicious,” while 154 were confirmed by the threat monitoring company as “malicious,” leaving little doubt about the true intentions of the activity. Most of the scanning attempts originate from the United States and Canada. Most of the systems targeted are located in the United States, although other countries are also targets.
GreyNoise observed that in the past, such increases in network scanning have been linked to preemptive reconnaissance, which was typically followed by the disclosure of vulnerabilities two to four weeks later.
See also: Hackers exploit vulnerability in Palo Alto firewalls
GreyNoise highlighted the stability of the scanning process, suggesting that it may be part of an effort to test network defenses before executing a targeted exploit.

Researchers have also identified a connection to another activity they have been monitoring recently, related to a PAN-OS scanner, which showed a spike on March 26, 2025, with 2,580 IP addresses in its scans.
GreyNoise noted that this activity is reminiscent of the espionage campaign Cisco Talos attributed to the ' ArcaneDoor ' hackers about a year ago, which targeted edge devices .
At this time, the exact nature and objectives of this large-scale activity remain unclear, however, administrators of Palo Alto Networks systems exposed online should be on high alert for detection and potential exploitation efforts.
GreyNoise recommends reviewing logs from mid-March to assess whether you have been targeted, look for signs of a breach, strengthen your connection gateways, and block known malicious Palo Alto IP addresses (which are mentioned in the report).
See also: Palo Alto Networks fixes vulnerability in PAN-OS Software
An IP address (Internet Protocol Address) is a unique numerical label used to locate and identify devices on a network, such as the Internet or a local area network (LAN). Every device connected to the Internet or a network is assigned an IP address so that it can communicate with other devices.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
