Cisco alerts to surge in password spraying attacks on VPNs

April 19, 2024
1 min read


TLDR:

– Cisco Talos warns of a massive increase in brute-force attacks targeting VPN services, SSH services, and Web application authentication interfaces

– Attackers are indiscriminately targeting VPNs from Cisco and several other vendors

Attackers are targeting VPN services, SSH services, and web application authentication interfaces in a massive surge of brute-force attacks, according to a warning from Cisco Talos. The attacks involve using generic and valid usernames to gain initial access to victim environments and are impacting organizations using Cisco Secure Firewall VPN devices and technologies from other vendors. The increasing interest among threat actors in VPNs has led to a significant rise in vulnerabilities, prompting advisories from cybersecurity agencies. The attacks, believed to be a reconnaissance effort, involve password-spraying attacks against remote access VPN services.


Latest from Blog

Top 20 Linux Admin Tools for 2024

TLDR: Top Linux Admin Tools in 2024 Key points: Linux admin tools streamline system configurations, performance monitoring, and security management. Popular Linux admin tools include Webmin, Puppet, Zabbix, Nagios, and Ansible. Summary

Bogus job tempts aerospace, energy workers

TLDR: A North Korean cyberespionage group is posing as job recruiters to target employees in aerospace and energy sectors. Mandiant reports that the group uses fake job descriptions stored in malicious archives