Global Surge of VPN Exploits: Brute-Force, Blast-RADIUS and Password Spray
ID: 6d097a66-70b6-5011-a7fa-9cb26d6dd252
STIX ID: report--6d097a66-70b6-5011-a7fa-9cb26d6dd252
Feed Name: WatchGuard Secplicity Blog
Threat Score
This timeline outlines widespread brute-force and password-spray campaigns and multiple critical vulnerabilities (including a protocol-level RADIUS flaw “Blast-RADIUS” and several vendor-specific CVEs/zero-days) actively exploited against VPNs and network appliances (Cisco, Fortinet, SonicWall, Ivanti, etc.), notes credential theft and ransomware (Akira) follow-on activity, and provides defensive recommendations such as MFA, patching, and migrating to RADIUS over TLS.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
