Cisco Warns of Massive Surge in Password-Spraying Attacks on VPNs
ID: a353b94e-ff29-5c7c-a55e-ed28d64010a3
STIX ID: report--a353b94e-ff29-5c7c-a55e-ed28d64010a3
Feed Name: Dark Reading
Cisco Talos warned of a rapid surge in brute-force/password‑spraying attacks beginning around March 28 that indiscriminately target VPNs (including Cisco Secure Firewall and products from Checkpoint, Fortinet, SonicWall, Mikrotik, Draytek), SSH, and web authentication interfaces; attackers are using common usernames/passwords and proxy services (Tor, Nexus Proxy, Space Proxies, BigMama), and Cisco published IOCs and mitigation recommendations including logging, hardening VPN profiles, and blocking malicious sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
