Executive Summary
In early October 2025, cybersecurity firm GreyNoise detected a sharp 500% spike in reconnaissance scans targeting Palo Alto Networks GlobalProtect and PAN-OS login portals. Over 1,285 unique suspicious IP addresses, predominantly from the U.S., but also from the UK, Canada, the Netherlands, and Russia, launched automated probes against these authentication portals. The campaign appeared targeted, leveraging data from public scanning platforms like Shodan and Censys. No verified exploit or compromise has been confirmed, with Palo Alto Networks asserting their systems remain secure and attributing much of the observed activity to external fingerprinting, not internal breach.
This incident highlights a broader escalation in focused reconnaissance tactics against major infrastructure platforms, often preceding attempts to weaponize new vulnerabilities. Organizations should remain vigilant about emerging threats, monitor authentication endpoints, and proactively patch known and zero-day-related risks.
Why This Matters Now
The surge in scanning for Palo Alto Networks login portals signals heightened pre-attack activity targeting vital infrastructure management interfaces. Security teams must act quickly to validate their exposure and harden authentication surfaces, as similar surges have preceded critical zero-day exploit campaigns.
Attack Path Analysis
Attackers initiated a widespread scanning campaign targeting publicly-exposed Palo Alto Networks GlobalProtect and PAN-OS login portals, likely seeking exploitable vulnerabilities or weak configurations. Should a vulnerable device or misconfiguration be discovered, the attackers could have carried out privilege escalation through exploitation of a zero-day or n-day flaw. Once inside, lateral movement to additional internal resources or cloud environments could follow, leveraging compromised access. The threat actors would set up command and control channels to maintain persistence and orchestrate further actions. Exfiltration of sensitive data or credentials might then occur via outbound traffic. Finally, adversaries could attempt disruptive actions, such as data destruction, further lateral attacks, or delivery of ransomware, leading to business impact.
Kill Chain Progression
Initial Compromise
Description
Adversaries performed targeted reconnaissance and large-scale scanning against public-facing Palo Alto Networks login portals to identify potential vulnerabilities or weak authentication points.
Related CVEs
CVE-2024-3400
CVSS 10A command injection vulnerability in PAN-OS allows unauthenticated remote attackers to execute arbitrary code with root privileges.
Affected Products:
Palo Alto Networks PAN-OS – 10.2, 11.0, 11.1
Exploit Status:
exploited in the wildCVE-2024-9473
CVSS 2.4A privilege escalation vulnerability in the GlobalProtect app on Windows allows local users to gain SYSTEM privileges via the repair functionality of the installer.
Affected Products:
Palo Alto Networks GlobalProtect App – < 6.0.10-c823, < 6.1.4-c720, < 6.2.5, < 6.3.1-c383
Exploit Status:
proof of conceptCVE-2024-5915
CVSS 5.2A privilege escalation vulnerability in the GlobalProtect app on Windows enables local users to execute programs with elevated privileges.
Affected Products:
Palo Alto Networks GlobalProtect App – < 6.0.10-c823, < 6.1.4-c720, < 6.2.5, < 6.3.1-c383
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Active Scanning
Vulnerability Scanning
Gather Victim Host Information
Network Service Scanning
Exploit Public-Facing Application
Exploitation for Privilege Escalation
Data Obfuscation
Valid Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – External Vulnerability Scans
Control ID: 11.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management – Identification of Vulnerabilities
Control ID: Art 9(2)(a)
CISA Zero Trust Maturity Model (ZTMM) 2.0 – Continuous Monitoring and Anomaly Detection
Control ID: Identity Pillar – Monitoring & Analytics
NIS2 Directive – Technical and Organizational Measures
Control ID: Article 21(2)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer/Network Security
Direct targeting of Palo Alto Networks infrastructure exposes security vendors to reconnaissance attacks, potentially compromising customer trust and security posture validation capabilities.
Financial Services
Banking institutions heavily relying on Palo Alto GlobalProtect face elevated reconnaissance risks threatening compliance frameworks including PCI DSS and critical financial data protection.
Government Administration
Government networks using targeted Palo Alto devices face nation-state reconnaissance threats, with particular vulnerability in US and Pakistan-focused attack clusters identified by researchers.
Information Technology/IT
IT infrastructure providers managing Palo Alto Networks and Grafana systems face dual threat vectors requiring immediate patch management and enhanced monitoring capabilities.
Sources
- Massive surge in scans targeting Palo Alto Networks login portalshttps://www.bleepingcomputer.com/news/security/massive-surge-in-scans-targeting-palo-alto-networks-login-portals/Verified
- Palo Alto Networks Releases Guidance for Vulnerability in PAN-OS, CVE-2024-3400https://www.cisa.gov/news-events/alerts/2024/04/12/palo-alto-networks-releases-guidance-vulnerability-pan-os-cve-2024-3400Verified
- CVE-2024-9473 GlobalProtect App: Local Privilege Escalation (PE) Vulnerabilityhttps://securityadvisories.paloaltonetworks.com/CVE-2024-9473Verified
- Nearly 24,000 IPs behind wave of Palo Alto Global Protect scanshttps://www.bleepingcomputer.com/news/security/nearly-24-000-ips-behind-wave-of-palo-alto-global-protect-scans/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust segmentation, centralized visibility, east-west traffic controls, and robust egress policies would have greatly limited unauthorized reconnaissance, prevented lateral movement, and enabled rapid detection of anomalies. Encrypted traffic enforcement and workload microsegmentation significantly reduce the attacker's ability to escalate privileges or exfiltrate data in cloud environments.
Control: Cloud Firewall (ACF)
Mitigation: Blocks unauthorized inbound reconnaissance attempts at the cloud perimeter.
Control: Zero Trust Segmentation
Mitigation: Limits scope of compromise by enforcing least-privilege network access to management interfaces.
Control: East-West Traffic Security
Mitigation: Blocks unsanctioned lateral movement between cloud workloads or segments.
Control: Egress Security & Policy Enforcement
Mitigation: Detects and blocks suspicious outbound C2 traffic.
Control: Encrypted Traffic (HPE)
Mitigation: Prevents unmonitored data exfiltration by enforcing strong encryption and visibility into outbound flows.
Rapidly detects and alerts on destructive or anomalous activity, enabling fast incident response.
Impact at a Glance
Affected Business Functions
- Network Security
- Remote Access Services
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive network configurations and user credentials due to unauthorized access.
Recommended Actions
Key Takeaways & Next Steps
- • Segment management interfaces from public internet access using Zero Trust network policies and cloud firewalls.
- • Enforce east-west traffic controls and microsegmentation to block lateral movement from compromised accounts or devices.
- • Deploy centralized visibility and anomaly detection to enable rapid detection of reconnaissance and privilege escalation attempts.
- • Strictly control egress with DNS/FQDN filtering to prevent outbound exfiltration and command & control.
- • Regularly audit and update access policies and vulnerabilities on critical cloud services and management portals.



