logo

Surge in networks scans targeting Cisco ASA devices raise concerns

ID: 0ff3c0dd-2d55-57bd-8a59-76ea30c54512

STIX ID: report--0ff3c0dd-2d55-57bd-8a59-76ea30c54512

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2025-09-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

GreyNoise and independent researchers observed a coordinated, large-scale scanning campaign in late August 2025 targeting Cisco ASA appliances and Cisco IOS Telnet/SSH, with spikes involving up to 25,000 unique IPs and a second wave largely driven by a ~17,000-IP Brazilian botnet; NadSec reported up to 200,000 hits within 20 hours. The scans used overlapping Chrome-like user agents suggesting a common origin and are consistent with reconnaissance that often precedes vulnerability disclosures; recommended mitigations include applying patches, enforcing MFA, avoiding direct exposure of ASA management interfaces, and using VPN concentrators, reverse proxies, geo-blocking, and rate limiting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.