Home » leak
GlobalProtect VPN login attack surge showing high-volume malicious authentication attempts

GlobalProtect Login Surge 2025: 2.3M VPN Attempts Exposed

Security teams should treat the recent spike in login traffic against GlobalProtect portals as a serious alarm. Between November 14 and 19, 2025, threat-intelligence sensors logged roughly 2.3 million sessions hitting the /global-protect/login.esp endpoint on PAN-OS and GlobalProtect gateways. That represents a nearly 40× increase in daily scan volume, hitting the highest level seen in…

Read More
Cyberattack disrupting OnSolve CodeRED emergency alert systems used by U.S. public safety agencies

Crisis24’s OnSolve CodeRED Exposes Data and Disrupts Alerts

A cyberattack on Crisis24’s OnSolve CodeRED platform disrupted emergency alerts for cities, counties, police and fire agencies across the U.S. The INC Ransom group claims responsibility, with stolen resident data, clear-text passwords and a rollback to older backups now forcing agencies to rebuild their notification capabilities and review credential hygiene.

Read More
CISA warns federal agencies to patch Cisco ASA/FTD zero-days and validate compromise under ED 25-03

Cisco firewall zero-days: CISA says patch & retire EOS hardware

CISA warned that multiple federal agencies still haven’t fully patched Cisco ASA/FTD devices despite active exploitation. Because the campaign targets the VPN web server and enables device takeover, teams must apply fixes for CVE-2025-20333/20362, follow ED 25-03 inventory and validation steps, and disconnect end-of-support hardware. This analysis explains impact, attack flow, high-signal detection, and fast remediation so defenders can reduce edge-device risk without slowing operations.

Read More