logo

Massive brute force attack uses 2.8 million IPs to target VPN devices

ID: dc6d7740-f6ed-54f0-a0cc-311b358f5f54

STIX ID: report--dc6d7740-f6ed-54f0-a0cc-311b358f5f54

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-02-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A sustained, large-scale brute-force credential campaign is ongoing that uses roughly 2.8 million daily source IPs—likely botnets or residential proxy networks—to attempt logins against internet-exposed edge/security appliances (firewalls, VPNs, gateways) across many vendors and geographies; monitoring by Shadowserver shows widespread distribution and high scale, and the report recommends stronger passwords, MFA, allowlists, disabling web admin interfaces, and timely firmware updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.