On October 3, 2025, threat intelligence firm GreyNoise detected a dramatic surge in scanning activity targeting Palo Alto Networks login portals, marking a nearly 500% increase in unique IP addresses involved compared to previous daily averages. This spike represented the highest level of such activity recorded in the past 90 days, with approximately 1,300 unique IP addresses participating in the scans, up from the typical 200. The vast majority of these IP addresses, about 93%, were classified as suspicious, while 7% were deemed malicious, indicating a significant threat level associated with the activity. Most of the scanning IPs were geolocated in the United States, but notable clusters also originated from the United Kingdom, the Netherlands, Canada, and Russia. The scanning was highly targeted, focusing on Palo Alto Networks login portals, including GlobalProtect and PAN-OS, and was primarily directed at emulated profiles set up by GreyNoise for monitoring purposes. Analysis revealed that the scanning activity was structured and likely derived from public internet scanning tools such as Shodan and Censys, or from attacker-originated reconnaissance efforts. Distinct clusters of scanning traffic were observed, with one group focusing on U.S.-based targets and another on Pakistan, each exhibiting unique but sometimes overlapping TLS fingerprints. The surge in Palo Alto scanning coincided with similar activity targeting Cisco ASA devices, with both sets of scans sharing regional clustering and fingerprinting overlaps, particularly a dominant TLS fingerprint linked to infrastructure in the Netherlands. GreyNoise noted that previous surges in scanning activity against Palo Alto technologies have sometimes preceded the disclosure of new vulnerabilities within six weeks, although not all such surges have led to new CVEs. The company referenced a similar incident in April 2025, which prompted Palo Alto Networks to urge customers to update their software. GreyNoise continues to monitor the situation closely, as such scanning activity can be an early indicator of forthcoming vulnerability disclosures or exploitation attempts. The targeted nature of the scans suggests that attackers may be seeking to identify vulnerable Palo Alto devices for potential compromise. The report underscores the importance for organizations using Palo Alto Networks products to ensure their systems are fully patched and to monitor for unusual login activity. The scanning activity's scale and coordination raise concerns about possible coordinated reconnaissance campaigns by threat actors. GreyNoise's research highlights the value of early warning signals in anticipating potential security incidents. The overlap in scanning techniques between Palo Alto and Cisco ASA devices may indicate shared attacker infrastructure or toolsets. Organizations are advised to block suspicious IPs identified in the scans and to review their exposure of management interfaces. The incident serves as a reminder of the persistent threat posed by automated and targeted internet scanning against critical network infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On October 3, 2025, GreyNoise publicly reported that scanning targeting Palo Alto Networks portals had surged over the prior 48 hours. The company described the activity as targeted and structured, noted similarities to recent Cisco ASA scanning, and advised organizations to run the latest software.
By October 3, 2025, GreyNoise observed a sharp spike in reconnaissance against Palo Alto Networks login portals, including GlobalProtect and PAN-OS profiles. The activity peaked at roughly 1,285 to 1,300 unique IPs, about 500% above normal levels, with most sources geolocated in the United States and the majority classified as suspicious or malicious.
On September 28, 2025, GreyNoise detected 110 unique malicious IPs attempting to exploit Grafana's path traversal flaw CVE-2021-43798. The activity was largely attributed to IPs geolocated in Bangladesh and primarily targeted systems in the United States, Slovakia, and Taiwan.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcethecyberthrone.in
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourcegreynoise.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.