logo

Attackers Love Your VPN To-Do List

ID: 511a8765-2125-5ad1-ac2a-873544ff076b

STIX ID: report--511a8765-2125-5ad1-ac2a-873544ff076b

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2026-04-17

Date Updated: 2026-04-28

...
...

This Huntress blog outlines real SOC-observed incidents where VPN credential compromises (FortiGate and SonicWall) enabled attackers to deploy publicly available exploitation tools (BlueHammer, RedSun, UnDefend attributed to Nightmare-Eclipse), perform environment discovery and persistence (including BYOVD tactics), and attempt Play ransomware; the post emphasizes missing logs, absent MFA, and lack of segmentation as primary enablers and recommends enforcing MFA, auditing privileged accounts, centralizing logs, and monitoring anomalous logins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.