Close Menu
    Main Menu
    • Home
    • News
    • Tech
    • Robotics
    • ML & Research
    • AI
    • Digital Transformation
    • AI Ethics & Regulation
    • Thought Leadership in AI

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Alexa Simply Obtained a Mind Improve — However You May Not Just like the Effective Print

    October 15, 2025

    Chinese language Hackers Exploit ArcGIS Server as Backdoor for Over a 12 months

    October 14, 2025

    Leaving Home windows 10 in the present day? The best way to clear your new Home windows 11 PC cache (and begin recent)

    October 14, 2025
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Home»AI Ethics & Regulation»Scanning Exercise on Palo Alto Networks Portals Leap 500% in One Day
    AI Ethics & Regulation

    Scanning Exercise on Palo Alto Networks Portals Leap 500% in One Day

    Declan MurphyBy Declan MurphyOctober 5, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Scanning Exercise on Palo Alto Networks Portals Leap 500% in One Day
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    Oct 04, 2025Ravie LakshmananVulnerability / Community Safety

    Risk intelligence agency GreyNoise disclosed on Friday that it has noticed an enormous spike in scanning exercise focusing on Palo Alto Networks login portals.

    The corporate stated it noticed an almost 500% improve in IP addresses scanning Palo Alto Networks login portals on October 3, 2025, the best degree recorded within the final three months. It described the visitors as focused and structured, and aimed primarily at Palo Alto login portals.

    As many as 1,300 distinctive IP addresses have participated within the effort, a major leap from round 200 distinctive IP addresses noticed earlier than. Of those IP addresses, 93% are labeled as suspicious and seven% as malicious.

    The overwhelming majority of the IP addresses are geolocated to the U.S., with smaller clusters detected within the U.Okay., the Netherlands, Canada, and Russia.

    DFIR Retainer Services

    “This Palo Alto surge shares traits with Cisco ASA scanning occurring up to now 48 hours,” GreyNoise famous. “In each instances, the scanners exhibited regional clustering and fingerprinting overlap within the tooling used.”

    “Each Cisco ASA and Palo Alto login scanning visitors up to now 48 hours share a dominant TLS fingerprint tied to infrastructure within the Netherlands.”

    When reached for remark concerning the spike in exercise, a spokesperson for the corporate stated there aren’t any indicators of compromise.

    “The safety of our clients is all the time our high precedence,” Palo Alto Networks stated. “We have now investigated the reported scanning exercise and located no proof of a compromise.”

    “Palo Alto Networks is protected by our personal Cortex XSIAM platform, which stops 1.5 million new assaults day by day and autonomously reduces 36 billion safety occasions into probably the most vital threats to make sure our infrastructure stays safe. We stay assured in our strong safety posture and our skill to guard our community.”

    In April 2025, GreyNoise reported an identical suspicious login scanning exercise focusing on Palo Alto Networks PAN-OS GlobalProtect gateways, prompting the community safety firm to induce clients to make sure that they’re working the newest variations of the software program.

    The event comes as GreyNoise famous in its Early Warning Alerts report again in July 2025 that surges in malicious scanning, brute-forcing, or exploit makes an attempt are sometimes adopted by the disclosure of a brand new CVE affecting the identical expertise inside six weeks.

    In early September, GreyNoise warned about suspicious scans that occurred as early as late August, focusing on Cisco Adaptive Safety Equipment (ASA) units. The primary wave originated from over 25,100 IP addresses, primarily positioned in Brazil, Argentina, and the U.S.

    CIS Build Kits

    Weeks later, Cisco disclosed two new zero-days in Cisco ASA (CVE-2025-20333 and CVE-2025-20362) that had been exploited in real-world assaults to deploy malware households like RayInitiator and LINE VIPER.

    Knowledge from the Shadowserver Basis reveals that over 45,000 Cisco ASA/FTD situations, out of which greater than 20,000 are positioned within the U.S. and about 14,000 are positioned in Europe, are nonetheless prone to the 2 vulnerabilities.

    (The story was up to date after publication to incorporate a response from Palo Alto Networks.)

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Declan Murphy
    • Website

    Related Posts

    Chinese language Hackers Exploit ArcGIS Server as Backdoor for Over a 12 months

    October 14, 2025

    Prison IP to Showcase ASM and CTI Improvements at GovWare 2025 in Singapore

    October 14, 2025

    SonicWall VPNs face a breach of their very own after the September cloud-backup fallout

    October 14, 2025
    Top Posts

    Evaluating the Finest AI Video Mills for Social Media

    April 18, 2025

    Utilizing AI To Repair The Innovation Drawback: The Three Step Resolution

    April 18, 2025

    Midjourney V7: Quicker, smarter, extra reasonable

    April 18, 2025

    Meta resumes AI coaching utilizing EU person knowledge

    April 18, 2025
    Don't Miss

    Alexa Simply Obtained a Mind Improve — However You May Not Just like the Effective Print

    By Amelia Harper JonesOctober 15, 2025

    Amazon has lastly pulled again the curtain on its next-generation voice assistant, and let’s simply…

    Chinese language Hackers Exploit ArcGIS Server as Backdoor for Over a 12 months

    October 14, 2025

    Leaving Home windows 10 in the present day? The best way to clear your new Home windows 11 PC cache (and begin recent)

    October 14, 2025

    EncQA: Benchmarking Imaginative and prescient-Language Fashions on Visible Encodings for Charts

    October 14, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    UK Tech Insider
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms Of Service
    • Our Authors
    © 2025 UK Tech Insider. All rights reserved by UK Tech Insider.

    Type above and press Enter to search. Press Esc to cancel.