As cited
Copy frozen at (site build).
threat intel
A Hidden Pattern Within Months of Credential-Based Attacks Against Palo Alto GlobalProtect
GreyNoise observed over 7,000 IP addresses attempting to log into Palo Alto GlobalProtect, with attack signatures matching earlier SonicWall API scanning and previous Palo Alto campaigns. The incidents indicate a sustained pattern of credential-based attacks spanning several months against these security vendors' products.
Why it matters: Security teams running GlobalProtect or other Palo Alto products need to monitor for unauthorized login attempts and review access logs immediately, as this represents an active, widespread credential attack campaign.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
A Hidden Pattern Within Months of Credential-Based Attacks Against Palo Alto GlobalProtect
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
A Hidden Pattern Within Months of Credential-Based Attacks Against Palo Alto GlobalProtect
GreyNoise observed over 7,000 unique IP addresses targeting Palo Alto Networks GlobalProtect with credential-based login attempts. The activity shares characteristics with prior SonicWall application programming interface scanning and earlier Palo Alto campaigns, indicating a recurring attack pattern.
Why it matters: Organizations using GlobalProtect should verify authentication logs for brute-force attempts and harden credential policies.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
A Hidden Pattern Within Months of Credential-Based Attacks Against Palo Alto GlobalProtect
GreyNoise observed over 7,000 unique IP addresses targeting Palo Alto Networks GlobalProtect with credential-based login attempts. The activity shares characteristics with prior SonicWall application programming interface scanning and earlier Palo Alto campaigns, indicating a recurring attack pattern.
Why it matters: Organizations using GlobalProtect should verify authentication logs for brute-force attempts and harden credential policies.
- Source published
- First seen by Cybersecurity Tracker