Cisco warns of password-spraying attacks targeting VPN services
ID: 041f3e9b-7326-561c-bb3c-675e425e0c1c
STIX ID: report--041f3e9b-7326-561c-bb3c-675e425e0c1c
Feed Name: Bleeping Computer
Threat Score
Cisco warned of active password-spraying campaigns targeting remote access VPN services (notably Cisco Secure Firewall/AnyConnect) and published IoCs and mitigation steps; security researchers link the activity to a new botnet dubbed “Brutus” that uses ~20,000 rotating IPs, targets multiple VPN vendors and AD-backed web apps, and may have ties to APT29.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
