As cited
Copy frozen at (site build).
vulnerabilities
Palo Alto Scanning Surges 40X in 24 Hours, Marking 90-Day High
GreyNoise detected a 40-fold surge in scanning activity targeting Palo Alto Networks GlobalProtect portals starting on November 14, 2025, within a 24-hour period, reaching the highest level observed in the previous 90 days. This escalation indicates increased malicious reconnaissance efforts against the internet-facing authentication gateway. The activity suggests either exploitation attempts following a newly disclosed vulnerability or an organized campaign targeting known Palo Alto deployments.
Why it matters: Organizations running Palo Alto Networks GlobalProtect should immediately review access logs, verify gateway security configurations, and confirm patch status, as the surge indicates active reconnaissance that could precede intrusion attempts.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Palo Alto Scanning Surges 40X in 24 Hours, Marking 90-Day High
GreyNoise detected a 40-fold surge in scanning activity targeting Palo Alto Networks GlobalProtect portals starting on November 14, 2025, within a 24-hour period, reaching the highest level observed in the previous 90 days. This escalation indicates increased malicious reconnaissance efforts against the internet-facing authentication gateway. The activity suggests either exploitation attempts following a newly disclosed vulnerability or an organized campaign targeting known Palo Alto deployments.
Why it matters: Organizations running Palo Alto Networks GlobalProtect should immediately review access logs, verify gateway security configurations, and confirm patch status, as the surge indicates active reconnaissance that could precede intrusion attempts.
- Source published
- First seen by Cybersecurity Tracker