HomeSecurity500% increase in scanning for Palo Alto Networks portals

500% increase in scanning for Palo Alto Networks portals

Threat intelligence firm GreyNoise revealed on Friday that it has seen a sharp increase in scanning activity targeting Palo Alto Networks login portals. The company reported a nearly 500% increase in IP addresses scanning the company’s login portals on October 3, 2025. This is the highest level recorded in the past three months.

 Palo Alto Networks

The traffic was described as targeted and structured, with Palo Alto Networks gateways being the primary target. In total, 1,300 unique IP addresses were involved in this effort, a significant increase from the approximately 200 unique IP addresses previously observed. Of these IP addresses, 93% were classified as suspicious and 7% as malicious.

See also: Discord: Data leak via third-party provider

The majority of IP addresses are geographically located in the US, with smaller groups detected in the UK, the Netherlands, Canada, and Russia.

This increase in Palo Alto Networks scans shares characteristics with the Cisco ASA scan that has been occurring over the past 48 hours,” GreyNoise noted. “In both cases, the scanners exhibited regional concentration and fingerprinting overlap in the tools used.”

500% increase in scanning for Palo Alto Networks portals

Login scanning traffic from both Cisco ASA and Palo Alto Networks over the past 48 hours shares a dominant TLS fingerprint associated with infrastructure in the Netherlands“.

See also: Vulnerability in Unity platform allows arbitrary code execution

Palo Alto Networks: In the target of hackers

In April 2025, GreyNoise reported similar suspicious scanning activity targeting Palo Alto Networks PAN-OS GlobalProtect gateways . At the time, the network security company was prompted to urge customers to ensure they were running the latest versions of the software.

This development comes as GreyNoise noted in its “Early Warning Signals” report in July 2025 that increases in malicious scanning, brute-forcing, and exploitation attempts are often followed by the disclosure of a new CVE affecting the same technology within six weeks.

500% increase in scanning for Palo Alto Networks portals

In early September, GreyNoise warned of suspicious scans that had been occurring since late August, targeting Cisco Adaptive Security Appliance (ASA) devices. The first wave came from over 25,100 IP addresses, primarily from Brazil, Argentina, and the US. Weeks later, Cisco disclosed two new zero-days in Cisco ASA (CVE-2025-20333 and CVE-2025-20362) that had been used in real-world attacks to deploy malware families such as RayInitiator and LINE VIPER.

See also: Oracle fixes zero-day used by Clop

Data from the Shadowserver Foundation shows that over 45,000 Cisco ASA/FTD instances (more than 20,000 located in the U.S. and about 14,000 in Europe) are still vulnerable to the two vulnerabilities.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS