TLDR:
– Cisco Talos warns of a massive increase in brute-force attacks targeting VPN services, SSH services, and Web application authentication interfaces
– Attackers are indiscriminately targeting VPNs from Cisco and several other vendors
Attackers are targeting VPN services, SSH services, and web application authentication interfaces in a massive surge of brute-force attacks, according to a warning from Cisco Talos. The attacks involve using generic and valid usernames to gain initial access to victim environments and are impacting organizations using Cisco Secure Firewall VPN devices and technologies from other vendors. The increasing interest among threat actors in VPNs has led to a significant rise in vulnerabilities, prompting advisories from cybersecurity agencies. The attacks, believed to be a reconnaissance effort, involve password-spraying attacks against remote access VPN services.