Palo Alto Networks has revealed that it is seeing brute-force login attempts on PAN-OS GlobalProtect gateways. It is worth noting that a few days ago, researchers had warned of an increase in suspicious scanning activity targeting the company's devices.

“Our teams are seeing activity consistent with password-related attacks, such as brute-force attacks. This activity does not indicate an exploit of a vulnerability,” a company spokesperson told The Hacker News. “We continue to actively monitor this situation and analyze the reported activity to determine its potential impact and identify whether any action is necessary.”
See also: New Double-Edged Email Attack Steals Office365 Credentials
Brute force attacks are a type of cyberattack in which an attacker tries to “guess” passwords to gain access to an account or service. This is done by trying all possible combinations until the correct one is found. Typically, attackers use automated tools that try thousands or even millions of possible combinations.
About a week ago, GreyNoise warned of in suspicious login scanning targeting PAN-OS GlobalProtect gateways. The activity began on March 17, peaking at 23,958 unique IP addresses, before ceasing late last month. According to researchers, this pattern indicates a coordinated effort to probe a network's potential defenses and identify exposed or vulnerable systems.
See also: PoisonSeed carries out Seed Phrase Poisoning attacks

The login scanning activity has primarily targeted systems in the United States, the United Kingdom, Ireland, Russia, and Singapore.
It is currently unknown how widespread these efforts are and whether they are the work of a specific hacking group.
See also: What are whale-phishing attacks and how to protect yourself
In the meantime, all customers are encouraged to run the latest versions of PAN-OS. It is also recommended to enforce multi-factor authentication (MFA), configure GlobalProtect to facilitate MFA notifications, set security policies to detect and block brute-force attacks , and limit unnecessary online exposure.
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
