Tuesday , September 15 2026
PAN-OS

Hackers targeting Palo Alto’s GlobalProtect VPN with 2.3 million attacks

Since November 14, 2025, hackers launched over 2.3 million attacks on Palo Alto Networks’ GlobalProtect VPN portals, as reported by GreyNoise. A 40-fold increase in activity within 24 hours marks the highest level in 90 days, indicating rising risks to global remote access systems.

Attacks aim at the /global-protect/login.esp URI on Palo Alto PAN-OS and GlobalProtect systems, using brute-force methods to gain unauthorized access to corporate networks.

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

GreyNoise researchers observed a surge in activity last week, driven by organizations relying on VPNs for secure remote work. This campaign poses a risk of data breaches and exposes ongoing vulnerabilities in popular network security tools.

Surge Linked to Coordinated Threat Actors:

Key indicators include consistent TCP and JA4t fingerprints across incidents, shared infrastructure via recurring Autonomous System Numbers (ASNs), and synchronized timing in activity spikes.

The patterns suggest a complex operation, possibly state-sponsored or linked to cybercrime, aimed at testing corporate security for vulnerabilities.

62% of the attack sessions come from AS200373 (3xK Tech GmbH), a German company, making it the main part of the infrastructure.

An extra 15% is linked to the same ASN but goes through Canadian clusters, suggesting efforts to avoid detection. There are also contributions from AS208885 (Noyobzoda Faridduni Saidilhom), showing a coordinated presence across continents.

Targets are concentrated in specific regions, with the United States, Mexico, and Pakistan receiving about the same number of login attempts. This might indicate that attackers are focusing on valuable areas or using stolen credential lists from various sources.

For defensive hunting, GreyNoise highlighted two JA4t fingerprints covering all observed activity: 65495_2-4-8-1-3_65495_7 and 33280_2-4-8-1-3_65495_7.

GreyNoise has noted that spikes in Fortinet VPN brute-force attacks typically happen within six weeks before vulnerability disclosures, a trend first observed in July 2025.

Surges affected Palo Alto portals in April and October 2025, leading to advisories tied to wider attacks on Cisco and Fortinet devices.

Organizations should review their exposed GlobalProtect portals, use multi-factor authentication, and keep an eye on these indicators to prevent potential exploits.

Check Also

ShinyHunters

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center …