logo

New password spraying attacks target Cisco, PAN VPN gateways

ID: a9b0094a-7578-50f1-ab6c-733fbf18120a

STIX ID: report--a9b0094a-7578-50f1-ab6c-733fbf18120a

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2025-12-18

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

An automated credential-stuffing campaign has been observed targeting GlobalProtect and Cisco SSL VPN portals, peaking at 1.7 million login attempts over ~16 hours and originating from thousands of IPs hosted by 3xK GmbH; activity exhibits consistent user-agent and request structure indicating scripted probes rather than exploitation, and GreyNoise found no evidence tying this activity to the recently disclosed Cisco AsyncOS zero-day. Vendors advise using strong passwords and MFA, and administrators are urged to audit appliances, monitor for unexpected logins, and block known malicious IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.