HomeSecurityNearly 24,000 IPs behind Palo Alto GlobalProtect scans

Nearly 24,000 IPs behind Palo Alto GlobalProtect scans

A significant increase has been observed in scanning activity targeting Palo Alto Network GlobalProtect, with researchers concerned that it may be a prelude to an upcoming attack or vulnerability exploit.

See also: Palo Alto Networks flags new firewall flaw as exploitable

Palo Alto IP

According to GreyNoise, which reports this activity, the scan includes over 24,000 unique Palo Alto IP addresses. The activity peaked on March 17, 2025, reaching 20,000 unique IP addresses per day, and continued at that level until March 26.

Of these IP addresses, 23,800 are classified as “suspicious,” while 154 were confirmed by the threat monitoring company as “malicious,” leaving little doubt about the true intentions of the activity. Most of the scanning attempts originate from the United States and Canada. Most of the systems targeted are located in the United States, although other countries are also targets.

GreyNoise observed that in the past, such increases in network scanning have been linked to preemptive reconnaissance, which was typically followed by the disclosure of vulnerabilities two to four weeks later.

See also: Hackers exploit vulnerability in Palo Alto firewalls

GreyNoise highlighted the stability of the scanning process, suggesting that it may be part of an effort to test network defenses before executing a targeted exploit.

Nearly 24,000 IPs behind Palo Alto GlobalProtect scans
Nearly 24,000 IPs behind Palo Alto GlobalProtect scans

Researchers have also identified a connection to another activity they have been monitoring recently, related to a PAN-OS scanner, which showed a spike on March 26, 2025, with 2,580 IP addresses in its scans.

GreyNoise noted that this activity is reminiscent of the espionage campaign Cisco Talos attributed to the ' ArcaneDoor ' hackers about a year ago, which targeted edge devices .

At this time, the exact nature and objectives of this large-scale activity remain unclear, however, administrators of Palo Alto Networks systems exposed online should be on high alert for detection and potential exploitation efforts.

GreyNoise recommends reviewing logs from mid-March to assess whether you have been targeted, look for signs of a breach, strengthen your connection gateways, and block known malicious Palo Alto IP addresses (which are mentioned in the report).

See also: Palo Alto Networks fixes vulnerability in PAN-OS Software

An IP address (Internet Protocol Address) is a unique numerical label used to locate and identify devices on a network, such as the Internet or a local area network (LAN). Every device connected to the Internet or a network is assigned an IP address so that it can communicate with other devices.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS