CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Palo Alto Scanning Surges 40X in 24 Hours, Marking 90-Day High

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1873

As cited

Copy frozen at (site build).

vulnerabilities

Palo Alto Scanning Surges 40X in 24 Hours, Marking 90-Day High

GreyNoise detected a 40-fold surge in scanning activity targeting Palo Alto Networks GlobalProtect portals starting on November 14, 2025, within a 24-hour period, reaching the highest level observed in the previous 90 days. This escalation indicates increased malicious reconnaissance efforts against the internet-facing authentication gateway. The activity suggests either exploitation attempts following a newly disclosed vulnerability or an organized campaign targeting known Palo Alto deployments.

Why it matters: Organizations running Palo Alto Networks GlobalProtect should immediately review access logs, verify gateway security configurations, and confirm patch status, as the surge indicates active reconnaissance that could precede intrusion attempts.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Palo Alto Scanning Surges 40X in 24 Hours, Marking 90-Day High

GreyNoise detected a 40-fold surge in scanning activity targeting Palo Alto Networks GlobalProtect portals starting on November 14, 2025, within a 24-hour period, reaching the highest level observed in the previous 90 days. This escalation indicates increased malicious reconnaissance efforts against the internet-facing authentication gateway. The activity suggests either exploitation attempts following a newly disclosed vulnerability or an organized campaign targeting known Palo Alto deployments.

Why it matters: Organizations running Palo Alto Networks GlobalProtect should immediately review access logs, verify gateway security configurations, and confirm patch status, as the surge indicates active reconnaissance that could precede intrusion attempts.

VendorsPalo Alto Networks
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary