Threat reportCampaignTL-2026-1469

Coordinated Scanning Campaign Against Fortinet SSL VPN and Palo Alto GlobalProtect Infrastructure Detected via GreyNoise Vendor CVE / Tag Spike Signals

mediumACTIVE

Coordinated Scanning Campaign Against Fortinet SSL VPN and (TL-2026-1469) is a medium-severity campaign, first published 2026-01-25. It has no confirmed attribution, affects Fortinet FortiOS SSL-VPN (sslvpnd), maps to 12 MITRE ATT&CK techniques (T1046, T1078, T1090), and is covered by 9 detection rules and 22 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
12MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-1469

Threat ID
TL-2026-1469
Severity
MEDIUM
Status
ACTIVE
Category
CAMPAIGN
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, critical-infrastructure, enterprise, finance, technology
Target regions
North America, Europe
Detection rules
9
Indicators of compromise
22

Malware and tooling in Coordinated Scanning Campaign Against Fortinet SSL VPN and

Malware and tooling: GreyNoise tag: Cisco ASA Arbitrary File Retrieval Attempt, GreyNoise tag: Cisco ASA CVE-2020-3259 Information Disclosure Attempt, GreyNoise tag: Cisco ASA Scanner, GreyNoise tag: Fortinet SSL VPN Bruteforcer, GreyNoise tag: Palo Alto Networks Login Scanner

How Coordinated Scanning Campaign Against Fortinet SSL VPN and works

GreyNoise's new Vendor CVE Spike and Tag Spike Event Feed signals surfaced elevated, coordinated scanning/brute-force activity against Fortinet SSL VPN and Palo Alto Networks GlobalProtect portal infrastructure during the week of 2026-01-19. This activity follows the same pattern as a documented multi-vendor campaign (Cisco ASA, Palo Alto GlobalProtect, Fortinet SSL-VPN) observed Aug-Oct 2025, in which GreyNoise found 80% of such vendor-wide activity spikes were followed by a new CVE disclosure for that vendor within six weeks — including the Cisco ASA/FTD zero-days CVE-2025-20333 and CVE-2025-20362.

GreyNoise introduced two new Event Feed signal types — Vendor CVE Spike (monitors exploitation/scanning activity across a vendor's entire product portfolio rather than per-CVE) and Tag Spike (tracks sudden increases in IP counts matching a specific GreyNoise behavioral tag over rolling 2-hour windows, useful before a CVE exists) — explicitly to close the detection gap between the start of opportunistic internet-wide scanning and formal vulnerability disclosure. During the week of 2026-01-19, these feeds flagged a coordinated elevation in scanning and targeting activity against both Fortinet SSL VPN appliances and Palo Alto Networks GlobalProtect portals simultaneously, framed by GreyNoise as a probable early-warning signal for a forthcoming CVE affecting one or both vendors.

This pattern mirrors a well-documented precedent from Aug-Oct 2025: GreyNoise tracked a synchronized, cross-vendor reconnaissance campaign against Cisco ASA/FTD, Palo Alto GlobalProtect, and Fortinet SSL-VPN devices. It began with a 25,000+ IP scanning surge against Cisco ASA (2025-08-26, `/+CSCOE+/logon.html` probing), continued with brute-force waves against Fortinet SSL-VPN (780+ IPs on 2025-08-03, a second wave with a distinct TCP signature and FortiManager/FGFM targeting on 2025-08-05), and culminated in a ~500% surge (from a ~200 IP/day baseline to 1,300, then 2,200+ unique IPs) against Palo Alto GlobalProtect portals beginning 2025-10-03. GreyNoise assessed with high confidence that the three campaigns were at least partially driven by the same threat actor(s), citing shared TCP/client fingerprints, overlapping source subnets, and close temporal alignment. The Cisco ASA scanning wave preceded Cisco's 2025-09-25 disclosure of two zero-day vulnerabilities (CVE-2025-20333, CVSS 9.9; CVE-2025-20362, CVSS 6.5) in Secure Firewall ASA/FTD WebVPN, linked separately to the China-nexus ArcaneDoor espionage campaign and serious enough that CISA issued its third-ever Emergency Directive (ED 25-03).

GreyNoise's broader Fortinet-specific research found that spikes matching the 'Fortinet SSL VPN Bruteforcer' tag are significantly correlated with subsequently disclosed FortiOS/FortiGate vulnerabilities, consistent with Fortinet's history of pre-auth RCE flaws in SSL-VPN components (CVE-2022-42475, CVE-2023-27997, CVE-2024-21762) that were each exploited in the wild at or shortly after disclosure. No CVE, specific IP list, or ASN breakdown has yet been published for the 2026-01-19 Fortinet/Palo Alto spike itself; this record documents the signal and its historical analog so downstream detection/response teams can pre-stage monitoring ahead of an anticipated disclosure.

MITRE ATT&CK techniques used in TL-2026-1469

Discovery

T1046 Network Service Discovery

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

command-and-control

T1090 Proxy

Credential Access

T1110 Brute Force

Lateral Movement

T1210 Exploitation of Remote Services

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure

Reconnaissance

T1590 Gather Victim Network Information; T1592 Gather Victim Host Information; T1595 Active Scanning

Affected products and versions in Coordinated Scanning Campaign Against Fortinet SSL VPN and

  • Fortinet — FortiOS SSL-VPN (sslvpnd)
    Vulnerable versions: unspecified - pre-CVE scanning/brute-force target
  • Fortinet — FortiManager (FGFM protocol)
    Vulnerable versions: unspecified - secondary target profile observed 2025-08-05
  • Palo Alto Networks — PAN-OS GlobalProtect portal
    Vulnerable versions: unspecified - pre-CVE scanning/login-brute-force target
  • Cisco — Secure Firewall ASA / FTD (WebVPN)
    Vulnerable versions: ASA/FTD software prior to fix for CVE-2025-20333/CVE-2025-20362
    Fixed in: patched releases per Cisco advisory for CVE-2025-20333 and CVE-2025-20362

Remediation for Coordinated Scanning Campaign Against Fortinet SSL VPN and

Patches

  • Apply Cisco ASA/FTD patches for CVE-2025-20333 and CVE-2025-20362 immediately if not already applied
  • Keep FortiOS, FortiGate, and FortiManager on current patched releases (history: CVE-2022-42475, CVE-2023-27997, CVE-2024-21762 pre-auth RCE)
  • Monitor Fortinet PSIRT and Palo Alto Networks security advisories for a new disclosure in the coming weeks per the Vendor CVE Spike signal

Immediate actions

  • Alert on and rate-limit/block traffic from source ASNs and IPs matching GreyNoise 'Fortinet SSL VPN Bruteforcer', 'Palo Alto Networks Login Scanner', and 'Cisco ASA Scanner' tags
  • Enforce MFA on all Fortinet SSL-VPN and Palo Alto GlobalProtect portal logins to blunt credential brute-force/spraying
  • Restrict management-plane exposure (FortiManager/FGFM, ASA WebVPN admin) to trusted networks only
  • Subscribe to GreyNoise Vendor CVE Spike and Tag Spike webhook alerts for Fortinet and Palo Alto Networks to get early warning ahead of formal CVE disclosure

Workarounds

  • Disable unused or legacy SSL-VPN/GlobalProtect web portals where remote access is not required
  • Enforce unique, high-entropy credentials and lockout policies on VPN portals to reduce brute-force/credential-stuffing success

Longer-term hardening

  • Given GreyNoise's 80%-within-six-weeks correlation between vendor-wide scanning spikes and new CVE disclosures, pre-stage patch-management and emergency-change processes for Fortinet FortiOS/FortiManager and Palo Alto PAN-OS now
  • Deploy edge-device logging/EDR and centralize SSL-VPN/GlobalProtect authentication logs to a SIEM for anomaly detection
  • Reduce internet-facing SSL-VPN/GlobalProtect attack surface via geofencing, allow-listing, or migration to broker/proxy-fronted remote access

Timeline of Coordinated Scanning Campaign Against Fortinet SSL VPN and

  • GreyNoise observes an earlier, smaller Fortinet SSL-VPN scanning spike with a unique client TLS/TCP signature, later recognized as a precursor pattern.
  • 780+ unique IPs trigger GreyNoise's 'Fortinet SSL VPN Bruteforcer' tag in a single day, well above the sub-baseline norm, targeting FortiOS SSL-VPN login.
  • A second Fortinet-targeting wave begins with a distinct TCP signature; targeting shifts from FortiOS toward FortiManager/FGFM management protocol.
  • 25,000+ unique IPs scan Cisco ASA devices in a single day (16,794 matching the 'Cisco ASA Scanner' tag); ~80% traced to a single Brazil-based botnet cluster probing /+CSCOE+/logon.html.
  • Cisco ASA brute-force activity abruptly halts at approximately 6 PM EST.
  • Brute-force activity resumes around 1 PM EST the same day Cisco discloses two zero-day vulnerabilities (CVE-2025-20333, CVSS 9.9; CVE-2025-20362, CVSS 6.5) in Secure Firewall ASA/FTD WebVPN, linked to the ArcaneDoor espionage campaign.
  • CISA issues Emergency Directive ED 25-03 (its third-ever) in response to active exploitation of the Cisco ASA/FTD zero-days; GreyNoise publishes its Executive SITREP on the Cisco ASA scanning surge.
  • Palo Alto GlobalProtect portal scanning jumps ~500% in 48 hours to ~1,300 unique IPs, against a 90-day baseline that rarely exceeded 200 IPs/day; 93% of source IPs classified suspicious, 7% malicious.
  • Palo Alto GlobalProtect scanning activity peaks at 2,200+ unique IPs; GreyNoise assesses shared TCP fingerprints, overlapping subnets, and temporal alignment linking the Cisco, Fortinet, and Palo Alto waves to a common actor or coordinated cluster with high confidence.
  • GreyNoise and multiple outlets (SecurityWeek, TheHackerNews, DarkReading) publicly report the coordinated multi-vendor Cisco/Fortinet/Palo Alto reconnaissance and brute-force campaign.
  • Follow-on credential-based/password-spraying activity against Palo Alto GlobalProtect and Cisco VPN infrastructure is separately reported (CSO Online), consistent with continuation of the coordinated targeting.
  • GreyNoise's newly launched Vendor CVE Spike and Tag Spike Event Feed signals detect a renewed, coordinated elevation in scanning/targeting activity against both Fortinet SSL VPN and Palo Alto GlobalProtect infrastructure during this week, ahead of any new CVE assignment for either vendor.
  • GreyNoise publishes 'Introducing Vendor CVE and Tag Spike,' documenting the new detection capability and citing the Fortinet/Palo Alto activity as an example of the signal working as designed ahead of expected disclosure.

Sources cited for Coordinated Scanning Campaign Against Fortinet SSL VPN and

Detection coverage for TL-2026-1469

As of 2026-01-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1469 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats