VPN login attempts increased sharply in early December as attackers launched a coordinated campaign against exposed GlobalProtect portals. The activity included large brute-force waves and widespread scans of SonicWall API endpoints. Security teams now track the surge closely because it targets systems that often protect core enterprise networks.
Large-scale attacks hit GlobalProtect systems
The campaign began with aggressive brute-force attempts against GlobalProtect VPN portals. Thousands of unique IP addresses participated, and many used similar client fingerprints. The uniform behavior suggests that the activity came from a single organized effort rather than random noise.
Attackers continued by probing API endpoints on SonicWall SonicOS devices. These endpoints handle management actions, so unauthorized access could provide deep control over network settings. The overlap between VPN brute-force activity and API scanning raised concerns about broader reconnaissance.
Because GlobalProtect remains a common entry point for corporate networks, any surge in login attempts increases the risk of credential compromise. Attackers often use brute-force waves to test stolen passwords or identify weak accounts. This pattern aligns with known methods used by access brokers who sell footholds to ransomware groups.
Intensity increased during peak periods
Security telemetry reported millions of sessions directed at GlobalProtect endpoints. During one peak, researchers observed more than two million attempts within a few days. Traffic surged further during a single twenty-four-hour period, reaching the highest level recorded in several months.
These numbers show that the attackers used automation on a large scale. Because the campaign involved many IP addresses, simple blocking measures became less effective. Such tactics allow attackers to bypass basic rate limits and disguise individual sources behind a wider pool of infrastructure.
Why the targets matter
GlobalProtect portals serve as gateways for remote employees, partners and administrators. When attackers test these portals, they often search for weak credentials or misconfigurations. Because many organizations still expose VPN login pages to the internet, the surface area remains significant.
The SonicWall scans reveal another concern. API endpoints on firewalls can provide access to configuration controls. If attackers find a weakness, they may disable protections, create new rules or move deeper into internal networks. This combination of VPN and firewall reconnaissance signals more than simple scanning noise.
Recommended defensive actions
Organizations should reduce exposure wherever possible. Administrators can restrict access to VPN portals with IP allowlists, geoblocking or private access gateways. Strong authentication, including MFA, remains essential. Because attackers often test old credentials, password hygiene also matters.
Security teams should review firewall policies and confirm that management APIs do not remain open to the public internet. Updated versions of PAN-OS and SonicOS address known flaws, so timely patching reduces risk. Logging and alerting should identify repeated login failures or unusual scan patterns.
Proactive monitoring helps detect early signs of credential-stuffing or brute-force activity. Because attackers often return to previously scanned targets, long-term visibility matters.
Conclusion
VPN login attempts surged in a coordinated campaign that targeted GlobalProtect and SonicWall systems. Attackers used brute-force methods, automated scans and distributed infrastructure to probe critical network entry points. Although no major breaches have been confirmed, the scale of the activity shows that organizations must harden remote-access systems and secure firewall management paths. Strong authentication, reduced exposure and timely updates provide the most effective defense against future waves.


0 responses to “VPN login attempts surge against GlobalProtect portals”