Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

June 26, 2026

The Security Coverage Gap is a Math Problem

June 26, 2026

China-Linked Hackers Strike Asian CNI with New Backdoor

June 26, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Scanning of Palo Alto Portals Surges 500%
News

Scanning of Palo Alto Portals Surges 500%

Team-CWDBy Team-CWDOctober 6, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Security experts have observed a massive increase in reconnaissance activity targeted at login portals for Palo Alto Networks products.

Real-time intelligence provider GreyNoise said it saw around 1300 IP addresses target its Palo Alto Networks Login Scanner tag on October 3. By contrast, daily volumes rarely topped 200 IPs over the previous 90 days.

The firm said that the activity is targeted and “likely derived” from public or attacker-originated scans.

Some 91% of IPs were located in the US, with smaller clusters in the UK, Netherlands, Canada and Russia. The vast majority (93%) of these are classed as “suspicious,” with 7% confirmed as malicious.

Read more on Palo Alto Networks threats: Hackers Chain Exploits of Three Palo Alto Networks Firewall Flaws

The 500% surge is the biggest observed by GreyNoise for Palo Alto login portals in three months.

“GreyNoise research in July found that surges in activity against Palo Alto technologies have, in some cases, been followed by new vulnerability disclosures within six weeks,” the firm continued.

“However, surges against GreyNoise’s Palo Alto Networks Login Scanner tag have not shown this correlation. GreyNoise will continue monitoring in case this activity precedes a new Palo Alto disclosure, which would represent an additive signal to our July research.”

Cisco Also Targeted

GreyNoise has also detected increases in scanning of other remote access services including SonicWall, Ivanti, Pulse Secure and Cisco ASA products.

“GreyNoise analysis shows that this Palo Alto surge shares characteristics with Cisco ASA scanning occurring in the past 48 hours. In both cases, the scanners exhibited regional clustering and fingerprinting overlap in the tooling used,” it said.

“Both Cisco ASA and Palo Alto login scanning traffic in the past 48 hours share a dominant TLS fingerprint tied to infrastructure in the Netherlands. This comes after GreyNoise initially reported an ASA scanning surge before Cisco’s disclosure of two ASA zero-days.”

However, GreyNouse couldn’t say for certain if the activity was carried out by the same operator and/or with the same intent.

Security products remain a popular target for threat actors. Last week, Infosecurity reported an increase in attacks from the Akira ransomware group aimed at hijacking SonicWall SSL VPN appliances.

AI is also helping groups to scale up reconnaissance and exploitation efforts.

The NCSC warned in a May report: “Cyber-threat actors are almost certainly already using AI to enhance existing tactics, techniques and procedures (TTPs) in victim reconnaissance, vulnerability research and exploit development, access to systems through social engineering, basic malware generation and processing exfiltrated data.”

Image credit: Poetra.RH / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleNew COLDRIVER Malware Campaign Joins BO Team and Bearlyfy in Russia-Focused Cyberattacks
Next Article Researchers Expose Phishing Threats Distributing CountLoader and PureRAT
Team-CWD
  • Website

Related Posts

News

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

June 26, 2026
News

China-Linked Hackers Strike Asian CNI with New Backdoor

June 26, 2026
News

How to Find Hidden Access Risks Inside Your Network

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Fixing trivial passwords is as easy as 123456

May 7, 2026

How the always-on generation can level up their cybersecurity game

September 11, 2025

Beware of Winter Olympics scams and other cyberthreats

February 2, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.