logo

Global Surge of VPN Exploits: Brute-Force, Blast-RADIUS and Password Spray

ID: 6d097a66-70b6-5011-a7fa-9cb26d6dd252

STIX ID: report--6d097a66-70b6-5011-a7fa-9cb26d6dd252

Feed Name: WatchGuard Secplicity Blog

Threat Score
88/100

Date Published: 2025-10-01

Date Updated: 2026-05-01

Author: Carla Roncato

...
...

This timeline outlines widespread brute-force and password-spray campaigns and multiple critical vulnerabilities (including a protocol-level RADIUS flaw “Blast-RADIUS” and several vendor-specific CVEs/zero-days) actively exploited against VPNs and network appliances (Cisco, Fortinet, SonicWall, Ivanti, etc.), notes credential theft and ransomware (Akira) follow-on activity, and provides defensive recommendations such as MFA, patching, and migrating to RADIUS over TLS.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.