A sudden and dramatic increase in malicious traffic targeting Palo Alto Networks' GlobalProtect portals was observed, with activity surging 40-fold within a 24-hour period starting November 14, 2025. Security researchers at GreyNoise recorded approximately 2.3 million sessions directed at the global-protect/login.esp endpoint, marking a 90-day high in scanning activity. The majority of this traffic originated from the AS200373 (3xK Tech GmbH) network, primarily geolocated in Germany and Canada, with a secondary contribution from AS208885. The scanning was broad, affecting systems in the US, Mexico, and Pakistan, and is believed to be opportunistic rather than targeted.
GreyNoise analysts have identified recurring technical fingerprints and infrastructure linking this surge to previous campaigns, suggesting the involvement of the same threat actor(s). Historical patterns indicate that such spikes in scanning activity often precede the disclosure or exploitation of new vulnerabilities in the targeted vendor's products. Defenders are advised to monitor for further developments and consider blocking suspicious IPs using available threat intelligence solutions, as the risk of an imminent vulnerability disclosure or exploitation campaign remains elevated.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
As the scanning spike was reported publicly, there was still no confirmed exploit tied to the activity and Palo Alto Networks had not issued a new advisory explaining the traffic flood. This left the cause of the surge unresolved despite the scale of the probing.
GreyNoise assessed with high confidence that the surge is connected to earlier campaigns targeting Palo Alto devices based on recurring TCP and JA4t fingerprints and reused infrastructure. The company also released a dedicated blocklist and advised defenders to tighten access controls, monitor login anomalies, and prepare blocking or IPS measures if the activity escalates.
Within 24 hours, malicious traffic against GlobalProtect portals increased nearly 40-fold and reached a 90-day high, totaling about 2.3 million scan sessions. Most traffic was attributed to AS200373 (3xK Tech GmbH), with additional probing from AS208885, and affected systems in the US, Mexico, and Pakistan at similar levels.
A large wave of malicious scanning targeting Palo Alto Networks GlobalProtect portals began on November 14, focusing on the PAN-OS/GlobalProtect endpoint global-protect/login.esp. GreyNoise observed the activity as broad opportunistic probing rather than a narrowly targeted campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourcegreynoise.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.