DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home Tech News

Mass scanning of Palo Alto Networks, Cisco and Fortinet Login portals

DigitalCIO Bureau by DigitalCIO Bureau
October 13, 2025
in Tech News
0
Mass scanning of Palo Alto Networks, Cisco and Fortinet Login portals
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Cybersecurity intelligence firm GreyNoise has observed an alarming increase in scanning activity against network equipment from major vendors in recent days. Scanning of Palo Alto Networks login portals has increased by approximately 500% in 48 hours, the highest level in 90 days. This pattern of targeted reconnaissance exercises is now associated with a high degree of certainty with similar escalations against Cisco ASA devices and Fortinet SSL VPNs.

The findings indicate that the same threat actors are behind a coordinated series of attacks targeting vulnerable login portals of critical network infrastructure.

Starting October 3rd, GreyNoise noticed a sharp increase in the number of unique IP addresses scanning Palo Alto Networks PAN-OS GlobalProtect login portals. On October 7th, activity peaked at over 2,200 unique IP addresses.

On October 8, GreyNoise confirmed the correlation between three recent campaigns:

Scanning Cisco ASA devices.

Increased login attempts against Palo Alto login portals.

A spike in brute force attempts against Fortinet SSL VPNs.

This link is supported by a recurring fingerprint (shared TCP fingerprints), the use of the same subnets, and the simultaneous escalation of activities. The most frequently used subnets are linked to AS200373 (3xK Tech GmbH) and AS11878 (tzulo, Inc.).

Increased risk of zero-day vulnerabilities

The increased scanning is particularly concerning given previous observations by GreyNoise. Previous research in July indicated that spikes in brute force attempts against Fortinet VPNs are often followed by the public disclosure of new Fortinet VPN vulnerabilities within six weeks. While such a correlation has not yet been proven in Palo Alto, the current escalation calls for increased vigilance from defenders.

Furthermore, the rapid succession of login attempts against Palo Alto suggests that threat actors are attempting to test a large data set of stolen or leaked credentials.

Call for defense teams

Defense teams are strongly advised to immediately tighten their firewall and VPN security. This activity is classified as targeted reconnaissance and is clearly distinct from routine background scanning.

Organizations can take preventive measures by:

Instantly block IPs involved in Fortinet VPN brute forcing and Palo Alto scanning.

Implement additional layers of defense given the coordinated nature of the attacks across different technology platforms.

GreyNoise has published a list of usernames and passwords used in recent Palo Alto and Fortinet campaigns for defense teams to review. Threat actors appear to be broadening their focus, given the increase in unique autonomous systems (ASNs) involved in the scans.

Tags: GreyNoise
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

Kyndryl launches agentic AI framework and services for the mainframe

by DigitalCIO Bureau
November 28, 2025
0
Kyndryl launches agentic AI framework and services for the mainframe

Kyndryl has announced new AI-powered services that combine the company’s deep mainframe expertise with agentic AI and hybrid IT computing capabilities to accelerate application and solutions development, increase operational...

Read moreDetails

AI Skillsets Critical to Address Cybersecurity Skills Gap Solution in India

by DigitalCIO Bureau
November 26, 2025
0
AI Adoption In Cybersecurity Surges Across India

Fortinet has released its 2025 Global Cybersecurity Skills Gap Report, shedding light on the new and persistent challenges Indian organizations face due to the cybersecurity skills gap. The...

Read moreDetails

 Cloudera Announces Updates to its Platform

by DigitalCIO Bureau
November 25, 2025
0
 Cloudera Announces Updates to its Platform

Cloudera has announced a major platform update that integrates Trino, Cloudera Shared Data Experience (SDX), and Cloudera Octopai Data Lineage to deliver unified data access, control, smarter governance,...

Read moreDetails

Salesforce Blocks Gainsight Apps After Detecting Suspicious Activity

by DigitalCIO Bureau
November 24, 2025
0
Salesforce Acquires AI Customer Service Startup Airkit.ai

CRM giant Salesforce has immediately blocked access to applications from software vendor Gainsight after detecting "unusual activity." The incident may have led to unauthorized access to customer data...

Read moreDetails

Employees in India Lack Clear Guidance on Using AI at Work

by DigitalCIO Bureau
November 21, 2025
0
Employees in India Lack Clear Guidance on Using AI at Work

Udemy has released a research report, ‌“Ready or Not: The Emerging Gap Between Awareness and Action in ‌AI Transformation.” Drawing on a new survey conducted by YouGov, the...

Read moreDetails
Next Post
Visakhapatnam’s First 50 MW AI Edge Data Center Foundation Laid

Visakhapatnam's First 50 MW AI Edge Data Center Foundation Laid

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

CybeReady Releases Data Privacy CISO Training Toolkit

CybeReady Releases Data Privacy CISO Training Toolkit

January 25, 2024

Uber launches a new app that connects workers with businesses

October 4, 2019
DataStax Unveils Astra DB Vertex Extension For Google Cloud

DataStax Unveils Astra DB Vertex Extension For Google Cloud

September 4, 2023

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Barracuda Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Digital Transformation Dynatrace E-books Fortinet Gartner GenAI Generative AI Google Cloud IBM Infographics Internet of Things (IoT) Kaspersky Microsoft Netskope New Relic NTT DATA NVIDIA Palo Alto Networks Panel Discussion Qlik Salesforce Sophos Tenable Trend Micro Veeam Veeam Software Vertiv Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?