Cybersecurity researchers have detected a sharp rise in Palo Alto Networks scans aimed at identifying vulnerable login portals. The spike suggests that attackers may be preparing for larger exploitation campaigns targeting GlobalProtect VPN and PAN-OS devices.

Massive Increase in Scanning Activity

According to data from GreyNoise, the number of IPs scanning Palo Alto Networks portals surged by more than 500% in early October.
On October 3, over 1,285 unique IP addresses attempted to access GlobalProtect and PAN-OS login pages, compared to the usual average of around 200.

Most of the scanning activity originated from the United States, followed by the United Kingdom, the Netherlands, Canada, and Russia.
GreyNoise classified 91% of the IPs as suspicious and another 7% as malicious.

The scans mainly targeted emulated Palo Alto Networks endpoints hosted by GreyNoise. Analysts believe attackers are testing how these systems respond before attempting real-world intrusions.

Possible Motives Behind the Surge

The growing wave of Networks scans may be linked to reconnaissance campaigns. Hackers often perform large-scale scans to detect vulnerable versions, open ports, or misconfigured VPN gateways.
Once they identify potential weaknesses, they can deploy targeted exploits or credential attacks.

Similar scanning activity has recently targeted Grafana servers, which face renewed exploitation attempts through the CVE-2021-43798 path traversal vulnerability. Researchers suspect that threat actors may be broadening their focus across multiple enterprise platforms.

Security Recommendations

Organizations using Palo Alto Networks firewalls or GlobalProtect VPN should:

  • Monitor access logs for abnormal login attempts or unauthorized access.
  • Enable multi-factor authentication to reduce credential-based attack risks.
  • Patch and update all PAN-OS devices to the latest versions.
  • Restrict external access to management interfaces and monitor network behavior for anomalies.

Conclusion

The sudden rise in Palo Alto Networks scans underlines the increasing interest of cybercriminals in enterprise infrastructure. While no direct exploits have surfaced yet, the scanning surge shows that attackers are mapping potential targets.
Proactive patching, strict access control, and continuous monitoring remain essential to keeping corporate systems safe.


0 responses to “Palo Alto Networks Scans Surge as Hackers Target Login Portals”