DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Tech News

Mass scanning of Palo Alto Networks, Cisco and Fortinet Login portals

DigitalCIO Bureau by DigitalCIO Bureau
October 13, 2025
in Tech News
0
Mass scanning of Palo Alto Networks, Cisco and Fortinet Login portals
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Cybersecurity intelligence firm GreyNoise has observed an alarming increase in scanning activity against network equipment from major vendors in recent days. Scanning of Palo Alto Networks login portals has increased by approximately 500% in 48 hours, the highest level in 90 days. This pattern of targeted reconnaissance exercises is now associated with a high degree of certainty with similar escalations against Cisco ASA devices and Fortinet SSL VPNs.

The findings indicate that the same threat actors are behind a coordinated series of attacks targeting vulnerable login portals of critical network infrastructure.

Starting October 3rd, GreyNoise noticed a sharp increase in the number of unique IP addresses scanning Palo Alto Networks PAN-OS GlobalProtect login portals. On October 7th, activity peaked at over 2,200 unique IP addresses.

On October 8, GreyNoise confirmed the correlation between three recent campaigns:

Scanning Cisco ASA devices.

Increased login attempts against Palo Alto login portals.

A spike in brute force attempts against Fortinet SSL VPNs.

This link is supported by a recurring fingerprint (shared TCP fingerprints), the use of the same subnets, and the simultaneous escalation of activities. The most frequently used subnets are linked to AS200373 (3xK Tech GmbH) and AS11878 (tzulo, Inc.).

Increased risk of zero-day vulnerabilities

The increased scanning is particularly concerning given previous observations by GreyNoise. Previous research in July indicated that spikes in brute force attempts against Fortinet VPNs are often followed by the public disclosure of new Fortinet VPN vulnerabilities within six weeks. While such a correlation has not yet been proven in Palo Alto, the current escalation calls for increased vigilance from defenders.

Furthermore, the rapid succession of login attempts against Palo Alto suggests that threat actors are attempting to test a large data set of stolen or leaked credentials.

Call for defense teams

Defense teams are strongly advised to immediately tighten their firewall and VPN security. This activity is classified as targeted reconnaissance and is clearly distinct from routine background scanning.

Organizations can take preventive measures by:

Instantly block IPs involved in Fortinet VPN brute forcing and Palo Alto scanning.

Implement additional layers of defense given the coordinated nature of the attacks across different technology platforms.

GreyNoise has published a list of usernames and passwords used in recent Palo Alto and Fortinet campaigns for defense teams to review. Threat actors appear to be broadening their focus, given the increase in unique autonomous systems (ASNs) involved in the scans.

Tags: GreyNoise
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

AI Skillsets Critical to Cybersecurity Skills Gap Solution

by DigitalCIO Bureau
October 14, 2025
0
Fortinet Expands Universal SASE Coverage with Two New India-Based Data Centres   

Fortinet has released its 2025 Global Cybersecurity Skills Gap Report, shedding light on the new and persistent challenges organizations face due to the cybersecurity skills gap. The global...

Read moreDetails

Visakhapatnam’s First 50 MW AI Edge Data Center Foundation Laid

by DigitalCIO Bureau
October 14, 2025
0
Visakhapatnam’s First 50 MW AI Edge Data Center Foundation Laid

In a major boost to the Andhra Pradesh government’s digital initiatives, Hon’ble Minister for IT, Electronics and Communications, Real Time Governance and Human Resources Development, Government of Andhra...

Read moreDetails

Hitachi Vantara And Supermicro to Drive Enterprise AI

by DigitalCIO Bureau
October 13, 2025
0
3i Infotech Partners with Databricks

Hitachi Vantara has announced it is working towards a strategic partnership with Supermicro, an IT solution provider for AI, cloud, storage and 5G/edge. The collaboration combines Supermicro’s GPU and...

Read moreDetails

The Hartford Opens Technology Center In Hyderabad

by DigitalCIO Bureau
October 13, 2025
0
The Hartford Opens Technology Center In Hyderabad

U.S.-based insurance company The Hartford has announced the opening of its new India Technology Center in Hyderabad’s Financial District. This strategic expansion reinforces the company’s commitment to advancing...

Read moreDetails

Omdia: Hyperscaler Cloud Marketplace Sales To Hit $163 Billion By 2030

by DigitalCIO Bureau
October 10, 2025
0
IDC: Public Cloud Investment To Reach $1.35 Trillion In 2027

New research from Omdia has revealed that enterprise software sales through hyperscaler cloud marketplaces - led by AWS, Microsoft, and Google Cloud - are projected to surge from $30...

Read moreDetails
Next Post
Visakhapatnam’s First 50 MW AI Edge Data Center Foundation Laid

Visakhapatnam's First 50 MW AI Edge Data Center Foundation Laid

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Machine learning can create meaningful conversations on death

December 10, 2019
SolarWinds Announces the Next Generation of SolarWinds Observability

SolarWinds Announces the Next Generation of SolarWinds Observability

October 3, 2024
Gartner: Generative AI Has Become An Emerging Risk for Enterprises

Gartner: Generative AI Has Become An Emerging Risk for Enterprises

September 15, 2023

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Barracuda Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Digital Transformation Dynatrace E-books Fortinet Gartner GenAI Generative AI Google Cloud HCLTech Honeywell IBM Infographics Internet of Things (IoT) Kaspersky Microsoft Netskope NTT DATA Palo Alto Networks Panel Discussion Qlik Salesforce Sophos Tenable Trend Micro Veeam Veeam Software Vertiv Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?