Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Launch Widespread Attacks on Palo Alto GlobalProtect Portals from 7,000+ IPs

Hackers Launch Widespread Attacks on Palo Alto GlobalProtect Portals from 7,000+ IPs

Posted on December 7, 2025December 7, 2025 By CWS

In an escalating marketing campaign focusing on distant entry infrastructure, menace actors have initiated energetic exploitation makes an attempt in opposition to Palo Alto Networks’ GlobalProtect VPN portals.

GrayNoise monitoring exercise report scans and exploitation efforts originating from greater than 7,000 distinctive IP addresses worldwide, elevating alarms for organizations counting on the favored VPN resolution for safe distant work.

Ip’s Noticed focusing on (Supply: GreyNoise)

The assaults, first detected in late November 2025, deal with vulnerabilities in GlobalProtect gateways, significantly these uncovered on the web through UDP port 4501.

In line with knowledge from Shadowserver and different menace intelligence feeds, the IP sources span residential proxies, bulletproof internet hosting suppliers, and compromised VPS situations throughout Asia, Europe, and North America.

“This isn’t opportunistic scanning; actors are probing for weak configurations and chaining them with identified exploits,” famous a researcher from a serious cybersecurity agency, who spoke on situation of anonymity.

Palo Alto Networks’ GlobalProtect has lengthy been a main goal as a result of its ubiquity in enterprise environments. Historic flaws, corresponding to CVE-2024-3400 (a vital command injection vulnerability patched in April 2024 with CVSS rating 9.8), proceed to hang-out unpatched techniques.

Current waves exploit misconfigurations permitting pre-authentication entry, together with default credentials or uncovered admin portals. Attackers deploy instruments like customized scripts mimicking Metasploit modules to enumerate portals, brute-force logins, and drop malware for persistence.

Mandiant’s newest menace report attributes related techniques to Chinese language state-affiliated teams like UNC4841, although no single actor has been definitively linked to this surge.

Indicators of compromise embrace anomalous UDP site visitors spikes to port 4501, adopted by HTTP requests to /global-protect/login.urd endpoints. In confirmed breaches, intruders have exfiltrated session tokens, enabling lateral motion into company networks.

Palo Alto Networks issued an pressing advisory on December 5, urging clients to implement multi-factor authentication (MFA), limit portal publicity through firewalls, and apply the newest patches.

“GlobalProtect stays safe when correctly configured, however internet-facing portals are high-value targets,” the corporate said. CISA has added associated IOCs to its Identified Exploited Vulnerabilities catalog, advising federal businesses to patch inside 72 hours.

Specialists suggest air-gapping vital portals, implementing zero-trust segmentation, and monitoring for beaconing to C2 servers like these hosted on AWS or Azure. As hybrid work persists, this marketing campaign underscores the fragility of legacy VPNs in opposition to industrialized assaults.

Observe us on Google Information, LinkedIn, and X for day by day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:Alto, Attacks, GlobalProtect, Hackers, IPs, Launch, Palo, Portals, Widespread

Post navigation

Previous Post: New FvncBot Android Banking Attacking Users to Log Keystrokes and Inject Malicious Payloads
Next Post: LockBit 5.0 Infrastructure Exposed in New Server, IP and Domain Leak

Related Posts

Gcore Highlights 150% Rise in DDoS Threats Gcore Highlights 150% Rise in DDoS Threats Cyber Security News
Google Introduces MTCs to Secure HTTPS from Quantum Risks Google Introduces MTCs to Secure HTTPS from Quantum Risks Cyber Security News
NCSC Warns of Oracle E-Business Suite 0-Day Vulnerability Actively Exploited in Attacks NCSC Warns of Oracle E-Business Suite 0-Day Vulnerability Actively Exploited in Attacks Cyber Security News
Sendmarc appoints Rob Bowker as North American Region Lead Sendmarc appoints Rob Bowker as North American Region Lead Cyber Security News
2 Chinese Hackers Trained Cisco Program Now Attacking Cisco Devices 2 Chinese Hackers Trained Cisco Program Now Attacking Cisco Devices Cyber Security News
Malicious NPM Package with 56K Downloads Steals WhatsApp Messages Malicious NPM Package with 56K Downloads Steals WhatsApp Messages Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Cisco Firewall Vulnerability Urges Immediate Action
  • SharePoint Vulnerability Abused After PoC Emerges
  • WordPress Urges Update to Fix Critical RCE Vulnerability
  • Hundreds of Fake VPN Extensions Divert Browser Traffic
  • Critical VMware vCenter Vulnerability Exploited by Hackers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Cisco Firewall Vulnerability Urges Immediate Action
  • SharePoint Vulnerability Abused After PoC Emerges
  • WordPress Urges Update to Fix Critical RCE Vulnerability
  • Hundreds of Fake VPN Extensions Divert Browser Traffic
  • Critical VMware vCenter Vulnerability Exploited by Hackers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark