ThreatCluster

Surge in Malicious Traffic Targeting Palo Alto Networks' GlobalProtect

First seen 20 Nov 2025, 16:18 UTC Theregister 24

Article Content

Browse articles
ThreatCluster

On November 14, 2025, malicious traffic aimed at Palo Alto Networks' GlobalProtect portals surged nearly 40-fold, reaching a 90-day high. This spike, which involved approximately 2.3 million sessions targeting the 'global-protect/login.esp' endpoint, primarily originated from a single network, AS200373 (3xK Tech GmbH).