GlobalProtect VPN login attack surge showing high-volume malicious authentication attempts

GlobalProtect Login Surge 2025: 2.3M VPN Attempts Exposed

Security teams should treat the recent spike in login traffic against GlobalProtect portals as a serious alarm. Between November 14 and 19, 2025, threat-intelligence sensors logged roughly 2.3 million sessions hitting the /global-protect/login.esp endpoint on PAN-OS and GlobalProtect gateways. That represents a nearly 40× increase in daily scan volume, hitting the highest level seen in…

Read More
VMware Tools and Aria zero-day exploit granting root access

VMware Tools & Aria Zero-Day Exploited for Root Access

Security researchers have identified a critical zero-day flaw (CVE-2025-41244) affecting VMware Tools and VMware Aria. The bug enables local privilege escalation to root, a dangerous step in potential exploitation chains. The issue lies in service discovery mechanisms built into VMware, which allow guest and management systems to interact. Attackers are abusing this trust to escalate…

Read More