logo

Cisco Warns of Global Surge in Brute-Force Attacks Targeting VPN and SSH Services

ID: 8551e139-a50f-5e58-b4a9-c7779e9f948e

STIX ID: report--8551e139-a50f-5e58-b4a9-c7779e9f948e

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-04-17

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Cisco Talos warns of a global surge in brute-force and password-spray attacks (since March 18, 2024) against VPNs, SSH and web authentication interfaces — activity largely routed through Tor exit nodes and various proxy services — while Fortinet reports exploitation of CVE-2023-1389 in TP-Link Archer AX21 routers to deliver multiple DDoS botnet families (AGoent, Condi, Gafgyt, Mirai, Miori, MooBot); organizations are advised to patch devices, monitor for proxy/Tor-sourced login attempts, and consult published IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.