
This week a long-dormant Palo Alto flaw came back to life in GreyNoise data. GlobalProtect CVE-2019-1579 (unauth RCE, CISA KEV) drew only isolated activity through late June, then more than 120 malicious hosts probed it on 06 July, almost all from a single hosting network. Separately, two coordinated hosting fleets ran the week's highest-volume web exploitation, roughly 7.5M connection attempts. Access our public preview At The Edge Clear: https://www.greynoise.io/resources/at-the-edge-clear-070626 GreyNoise customers get the full weekly brief.
Post summary
The post reports active exploitation of CVE-2019-1579 on Palo Alto GlobalProtect, noting over 120 malicious probes and millions of connection attempts, with no PoC, code, or patch reference provided.
