Attackers launch dual campaign on GlobalProtect portals and SonicWall APIs
Summary
A hacking campaign has been targeting GlobalProtect logins and scanning SonicWall APIs since December 2, 2025. The attack is significant due to its scale, involving over 7,000 IP addresses linked to a German hosting provider, indicating a coordinated effort that poses a serious threat to the security of affected systems.
Original Article Summary
A hacking campaign is targeting GlobalProtect logins and scannig SonicWall APIs since December 2, 2025. A campaign began on December 2 targeting Palo Alto GlobalProtect portals with login attempts and scanning SonicWall SonicOS API endpoints. The activity came from over 7,000 IPs tied to German hosting provider 3xK GmbH, which operates its own BGP network […]
Impact
Palo Alto GlobalProtect portals, SonicWall SonicOS API endpoints
In the Wild
Yes
Timeline
Ongoing since December 2, 2025
Remediation
Organizations should implement strong authentication measures, monitor access logs for unusual login attempts, and ensure that their SonicWall APIs are properly secured and updated.