A major spike in scanning activity has been detected targeting the GlobalProtect VPN login portals of Palo Alto Networks, according to intelligence from GreyNoise Intelligence. Between 14 and 19 November 2025, roughly 2.3 million sessions hit the /global-protect/login.esp endpoint — marking a dramatic increase in threat actor interest.
GreyNoise data shows that scanning activity began climbing on 14 November and, within 24 hours, spiked to a level 40 times higher than typical baseline traffic, representing a 90-day high for the platform.
Key Findings from the Scan Campaign
- The scanning sessions targeted the web-login URI used by GlobalProtect VPN portals running on PAN-OS firewalls.
- Attack traffic disproportionately originated from certain Autonomous System Numbers (ASNs), notably AS200373 (3xK Tech GmbH), responsible for approximately 62% of source IPs (primarily in Germany), and AS208885 (Noyobzoda Faridduni Saidilhom) contributing further volume.
- Geographically, the U.S., Mexico and Pakistan were among the most targeted destinations—though the campaign appears globally distributed.
- Historically, GreyNoise notes that scanning surges like this often precede vulnerability disclosures. In fact, prior spikes in GlobalProtect-related scanning tied to earlier flaw exploitations (such as CVE-2025-0108 and CVE-2025-0111) have been observed.
Context & Background: Why This Matters
VPN gateways like GlobalProtect serve as the front door for remote access into corporate networks, making them prime targets for adversaries. The volume and concentration of scans suggest mounting pressure on defenders to harden these entry points.
In early October, GreyNoise had already flagged a 500 % increase in IPs scanning GlobalProtect and PAN-OS endpoints, with 91 % of the IPs classified as “suspicious” and 7 % as clearly malicious. Earlier this year in April, a similar albeit smaller scale campaign involved 24,000 IPs targeting the same surface.
The fact that scanning peaks often precede publicly disclosed vulnerabilities adds urgency: organizations running GlobalProtect portals may be exposed even if no known exploit is currently in the wild.
For organisations still relying on VPNs for remote access, securing portals and monitoring for anomalous login or scan behavior becomes a critical defensive priority.
Analyst Insight: Proactive Defence Is Key
While no active exploit linked to this precise surge has yet been publicly confirmed, the pattern is consistent with reconnaissance that precedes exploitation.
As GreyNoise notes, “These scanning spikes typically precede the disclosure of new security flaws in 80 % of cases, with the correlation being even stronger for Palo Alto Networks’ products.”
Cyber-defence practitioners should therefore treat this campaign not as benign background noise, but as a red-flag indicator. Recommended actions include:
- Enable and monitor web-login endpoints for abnormal traffic volumes, source IP churn, and repeated failed authentications
- Apply all relevant patches and updates for PAN-OS and GlobalProtect without delay
- Enforce multi-factor authentication (MFA) for all remote-access users and portals
- Segment remote-access networks to reduce the blast radius of any successful compromise
- Configure logging and alerting to detect post-authentication anomaly (e.g., lateral movement, privilege escalation)
Experts say firms can’t assume the absence of a publicly known exploit means they’re safe—unseen vulnerabilities may already be under reconnaissance.
Time to Harden the Doors
The recent scan storm targeting GlobalProtect VPN portals is a clear warning to organisations: remote-access infrastructure remains a high-value target, and the reconnaissance phase often signals an attack to come. With millions of probe sessions observed over just a few days and a well-documented track-record of follow-on exploits, defenders need to remain vigilant and proactive.
Applying good hygiene — strong authentication, segmentation, logging — remains the foundational layer of defence. But given the scale of the observed activity and the asymmetric advantage enjoyed by threat actors, success in this arena depends on moving from reactive to anticipatory mode.
Please subscribe to the Newsletter so that you do not miss any critical update
