Attackers Love Your VPN To-Do List
ID: 511a8765-2125-5ad1-ac2a-873544ff076b
STIX ID: report--511a8765-2125-5ad1-ac2a-873544ff076b
Feed Name: Huntress Blog
This Huntress blog outlines real SOC-observed incidents where VPN credential compromises (FortiGate and SonicWall) enabled attackers to deploy publicly available exploitation tools (BlueHammer, RedSun, UnDefend attributed to Nightmare-Eclipse), perform environment discovery and persistence (including BYOVD tactics), and attempt Play ransomware; the post emphasizes missing logs, absent MFA, and lack of segmentation as primary enablers and recommends enforcing MFA, auditing privileged accounts, centralizing logs, and monitoring anomalous logins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
