Threat intelligence firm GreyNoise revealed on Friday that it has seen a sharp increase in scanning activity targeting Palo Alto Networks login portals. The company reported a nearly 500% increase in IP addresses scanning the company’s login portals on October 3, 2025. This is the highest level recorded in the past three months.

The traffic was described as targeted and structured, with Palo Alto Networks gateways being the primary target. In total, 1,300 unique IP addresses were involved in this effort, a significant increase from the approximately 200 unique IP addresses previously observed. Of these IP addresses, 93% were classified as suspicious and 7% as malicious.
See also: Discord: Data leak via third-party provider
The majority of IP addresses are geographically located in the US, with smaller groups detected in the UK, the Netherlands, Canada, and Russia.
“This increase in Palo Alto Networks scans shares characteristics with the Cisco ASA scan that has been occurring over the past 48 hours,” GreyNoise noted. “In both cases, the scanners exhibited regional concentration and fingerprinting overlap in the tools used.”

“Login scanning traffic from both Cisco ASA and Palo Alto Networks over the past 48 hours shares a dominant TLS fingerprint associated with infrastructure in the Netherlands“.
See also: Vulnerability in Unity platform allows arbitrary code execution
Palo Alto Networks: In the target of hackers
In April 2025, GreyNoise reported similar suspicious scanning activity targeting Palo Alto Networks PAN-OS GlobalProtect gateways . At the time, the network security company was prompted to urge customers to ensure they were running the latest versions of the software.
This development comes as GreyNoise noted in its “Early Warning Signals” report in July 2025 that increases in malicious scanning, brute-forcing, and exploitation attempts are often followed by the disclosure of a new CVE affecting the same technology within six weeks.

In early September, GreyNoise warned of suspicious scans that had been occurring since late August, targeting Cisco Adaptive Security Appliance (ASA) devices. The first wave came from over 25,100 IP addresses, primarily from Brazil, Argentina, and the US. Weeks later, Cisco disclosed two new zero-days in Cisco ASA (CVE-2025-20333 and CVE-2025-20362) that had been used in real-world attacks to deploy malware families such as RayInitiator and LINE VIPER.
See also: Oracle fixes zero-day used by Clop
Data from the Shadowserver Foundation shows that over 45,000 Cisco ASA/FTD instances (more than 20,000 located in the U.S. and about 14,000 in Europe) are still vulnerable to the two vulnerabilities.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
