logo

Hackers Actively Attacking Cisco and Palo Alto Networks VPN Gateways to Gain Login Access

ID: bf0d5558-aca0-570e-8cd1-9cf8b99a95cd

STIX ID: report--bf0d5558-aca0-570e-8cd1-9cf8b99a95cd

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-18

Date Updated: 2026-04-21

Author: Guru Baran

...
...

GreyNoise reported a large mid-December 2025 credential-stuffing campaign against enterprise VPN gateways — primarily Palo Alto GlobalProtect and Cisco SSL VPN — involving roughly 1.7 million sessions and thousands of attacking IPs sourced from cloud ranges tied to Germany’s 3xK GmbH; the activity used scripted credential stuffing (not zero-day exploits), exhibited consistent TCP/user-agent fingerprints, and rapidly pivoted between vendors. GreyNoise recommends enforcing MFA, strong unique passwords, auditing VPN logs, and blocking tagged IPs; no confirmed breaches or evidence of exploitation beyond brute-force stuffing were reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.