GlobalProtect VPN login attack surge showing high-volume malicious authentication attempts

GlobalProtect Login Surge 2025: 2.3M VPN Attempts Exposed

Security teams should treat the recent spike in login traffic against GlobalProtect portals as a serious alarm. Between November 14 and 19, 2025, threat-intelligence sensors logged roughly 2.3 million sessions hitting the /global-protect/login.esp endpoint on PAN-OS and GlobalProtect gateways. That represents a nearly 40× increase in daily scan volume, hitting the highest level seen in…

Read More
Logo of Sanchar Saathi mobile app displayed on a smartphone overlaid on Indian flag background

India Pulls Back on “Sanchar Saathi” App Mandate Surveillance

India’s telecom ministry rescinded its controversial order forcing all new and existing smartphones to pre-install the government-run “Sanchar Saathi” app. The reversal follows widespread criticism over privacy risks, consent violations, and potential mass surveillance, raising fresh questions about digital rights and security oversight in a market of over a billion mobile users.

Read More
BRICKSTORM malware used in Chinese cyber operations targeting VMware vSphere and government networks

CISA Report on Chinese Operations: BRICKSTORM Malware

The latest Cybersecurity and Infrastructure Security Agency (CISA) advisory reveals that PRC-linked hackers use a backdoor called BRICKSTORM to gain long-term access to VMware vSphere and Windows environments, affecting government and IT networks. This article unpacks the attack chain, impacted sectors and critical defensive steps organizations should take now.

Read More