🚨 Palo Alto Login Portal Scanning Surges ~500%
GreyNoise reports ~1,300 unique IPs triggered Palo Alto Networks Login Scanner in 48 hours, marking a 90-day high. 93% of IPs are suspicious, 7% malicious. Activity primarily targets GlobalProtect and PAN-OS profiles, with geolocations in the US, UK, Netherlands, Canada & Russia.
⚠️ Defenders: block suspicious IPs and monitor for potential exploitation. Could coordinated behavior with Cisco ASA scans indicate larger trends? Discuss below and follow TechNadu for more alerts.
#PaloAlto #CyberSecurity #GreyNoise #NetworkSecurity #LoginScanner #ThreatIntel #Infosec #Reconnaissance #ZeroDay