# Coordinated Scanning Campaign Against Fortinet SSL VPN and Palo Alto GlobalProtect Infrastructure Detected via GreyNoise Vendor CVE / Tag Spike Signals

> GreyNoise's new Vendor CVE Spike and Tag Spike Event Feed signals surfaced elevated, coordinated scanning/brute-force activity against Fortinet SSL VPN and Palo Alto Networks GlobalProtect portal infrastructure during the week of 2026-01-19. This activity follows the same pattern as a documented multi-vendor campaign (Cisco ASA, Palo Alto GlobalProtect, Fortinet SSL-VPN) observed Aug-Oct 2025, in which GreyNoise found 80% of such vendor-wide activity spikes were followed by a new CVE disclosure for that vendor within six weeks — including the Cisco ASA/FTD zero-days CVE-2025-20333 and CVE-2025-20362.

- **Published:** 2026-01-25T00:00:00Z
- **Last reviewed:** 2026-01-25T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1469
- **ID:** TL-2026-1469
- **Severity:** MEDIUM
- **Category:** CAMPAIGN
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)

## Description

GreyNoise introduced two new Event Feed signal types — Vendor CVE Spike (monitors exploitation/scanning activity across a vendor's entire product portfolio rather than per-CVE) and Tag Spike (tracks sudden increases in IP counts matching a specific GreyNoise behavioral tag over rolling 2-hour windows, useful before a CVE exists) — explicitly to close the detection gap between the start of opportunistic internet-wide scanning and formal vulnerability disclosure. During the week of 2026-01-19, these feeds flagged a coordinated elevation in scanning and targeting activity against both Fortinet SSL VPN appliances and Palo Alto Networks GlobalProtect portals simultaneously, framed by GreyNoise as a probable early-warning signal for a forthcoming CVE affecting one or both vendors.

This pattern mirrors a well-documented precedent from Aug-Oct 2025: GreyNoise tracked a synchronized, cross-vendor reconnaissance campaign against Cisco ASA/FTD, Palo Alto GlobalProtect, and Fortinet SSL-VPN devices. It began with a 25,000+ IP scanning surge against Cisco ASA (2025-08-26, `/+CSCOE+/logon.html` probing), continued with brute-force waves against Fortinet SSL-VPN (780+ IPs on 2025-08-03, a second wave with a distinct TCP signature and FortiManager/FGFM targeting on 2025-08-05), and culminated in a ~500% surge (from a ~200 IP/day baseline to 1,300, then 2,200+ unique IPs) against Palo Alto GlobalProtect portals beginning 2025-10-03. GreyNoise assessed with high confidence that the three campaigns were at least partially driven by the same threat actor(s), citing shared TCP/client fingerprints, overlapping source subnets, and close temporal alignment. The Cisco ASA scanning wave preceded Cisco's 2025-09-25 disclosure of two zero-day vulnerabilities (CVE-2025-20333, CVSS 9.9; CVE-2025-20362, CVSS 6.5) in Secure Firewall ASA/FTD WebVPN, linked separately to the China-nexus ArcaneDoor espionage campaign and serious enough that CISA issued its third-ever Emergency Directive (ED 25-03).

GreyNoise's broader Fortinet-specific research found that spikes matching the 'Fortinet SSL VPN Bruteforcer' tag are significantly correlated with subsequently disclosed FortiOS/FortiGate vulnerabilities, consistent with Fortinet's history of pre-auth RCE flaws in SSL-VPN components (CVE-2022-42475, CVE-2023-27997, CVE-2024-21762) that were each exploited in the wild at or shortly after disclosure. No CVE, specific IP list, or ASN breakdown has yet been published for the 2026-01-19 Fortinet/Palo Alto spike itself; this record documents the signal and its historical analog so downstream detection/response teams can pre-stage monitoring ahead of an anticipated disclosure.

## MITRE ATT&CK

- T1595 Active Scanning
- T1592 Gather Victim Host Information
- T1583 Acquire Infrastructure
- T1190 Exploit Public-Facing Application
- T1133 External Remote Services
- T1110 Brute Force
- T1046 Network Service Discovery
- T1090 Proxy
- T1590 Gather Victim Network Information
- T1584 Compromise Infrastructure
- T1078 Valid Accounts
- T1210 Exploitation of Remote Services

## Sources

- [Introducing Vendor CVE and Tag Spike](https://www.greynoise.io/blog/introducing-vendor-cve-and-tag-spike)
- [Cisco, Fortinet, Palo Alto Networks Devices Targeted in Coordinated Campaign](https://www.securityweek.com/cisco-fortinet-palo-alto-networks-devices-targeted-in-coordinated-campaign/)
- [Palo Alto Scanning Surges ~500% in 48 Hours, Marking 90-Day High](https://www.greynoise.io/blog/palo-alto-scanning-surges)
- [Scanning Surge Targets Cisco ASA Devices](https://www.greynoise.io/blog/scanning-surge-cisco-asa-devices)
- [Coordinated Brute Force Campaign Targets Fortinet SSL VPN](https://www.greynoise.io/blog/vulnerability-fortinet-vpn-bruteforce-spike)
- [Scanning Activity on Palo Alto Networks Portals Jump 500% in One Day](https://thehackernews.com/2025/10/scanning-activity-on-palo-alto-networks.html)
- [Surge in Scans on PAN GlobalProtect VPNs Hints at Attacks](https://www.darkreading.com/perimeter/scans-pan-globalprotect-vpns-attacks)
- [Attackers bring their own passwords to Cisco and Palo Alto VPNs](https://www.csoonline.com/article/4109488/attackers-bring-their-own-passwords-to-cisco-and-palo-alto-vpns.html)
- [GreyNoise Links Coordinated Firewall Scans to Potential Multi-Vendor Attack Campaign](https://www.enterprisesecuritytech.com/post/greynoise-links-coordinated-firewall-scans-to-potential-multi-vendor-attack-campaign)
- [GreyNoise finds attacker activity surges before vulnerability disclosures](https://www.scworld.com/news/greynoise-finds-attacker-activity-surges-before-vulnerability-disclosures)
- [Fortinet says SSL-VPN pre-auth RCE bug is exploited in attacks](https://www.bleepingcomputer.com/news/security/fortinet-says-ssl-vpn-pre-auth-rce-bug-is-exploited-in-attacks/)
- [Building an Exploit for FortiGate Vulnerability CVE-2023-27997](https://bishopfox.com/blog/building-exploit-fortigate-vulnerability-cve-2023-27997)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1469
