Hackers target Check Point VPNs to breach enterprise networks
ID: 52d61b3f-0625-54f2-9af6-0d3b931bcbee
STIX ID: report--52d61b3f-0625-54f2-9af6-0d3b931bcbee
Feed Name: Bleeping Computer
Check Point warns of an ongoing campaign targeting Remote Access VPNs by abusing legacy local accounts configured with password-only authentication; the vendor observed a small number of login attempts, released a hotfix to block password-only local accounts, and advises customers to migrate to stronger authentication or delete vulnerable accounts. The article also places this activity within broader brute-force/password-spraying campaigns impacting multiple vendors (including activity attributed to a botnet dubbed "Brutus" and state-backed activity against Cisco devices).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
