CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Coordinated Credential-Based Campaign Targets Cisco and Palo Alto Networks VPN Gateways

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1868

As cited

Copy frozen at (site build).

threat intel

Coordinated Credential-Based Campaign Targets Cisco and Palo Alto Networks VPN Gateways

GreyNoise has identified a coordinated, automated campaign attempting to compromise enterprise VPN gateways through credential-based attacks targeting Cisco SSL VPN and Palo Alto Networks GlobalProtect services. The campaign appears to be systematically probing authentication infrastructure across multiple organizations.

Why it matters: Organizations using Cisco SSL VPN or Palo Alto Networks GlobalProtect should review access logs for brute force activity and enforce strong authentication controls, as successful compromise could grant attackers remote access to internal networks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Coordinated Credential-Based Campaign Targets Cisco and Palo Alto Networks VPN Gateways

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Coordinated Credential-Based Campaign Targets Cisco and Palo Alto Networks VPN Gateways

GreyNoise is tracking an automated, credential-based campaign targeting enterprise virtual private network (VPN) authentication infrastructure. The activity focuses on Cisco SSL VPN and Palo Alto Networks GlobalProtect services. The campaign appears coordinated and widespread across affected systems.

Why it matters: Organizations running Cisco SSL VPN or Palo Alto Networks GlobalProtect are under active credential attack and should review authentication logs, implement multifactor authentication (MFA) if not present, and monitor for unauthorized access attempts.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Coordinated Credential-Based Campaign Targets Cisco and Palo Alto Networks VPN Gateways

GreyNoise is tracking an automated, credential-based campaign targeting enterprise virtual private network (VPN) authentication infrastructure. The activity focuses on Cisco SSL VPN and Palo Alto Networks GlobalProtect services. The campaign appears coordinated and widespread across affected systems.

Why it matters: Organizations running Cisco SSL VPN or Palo Alto Networks GlobalProtect are under active credential attack and should review authentication logs, implement multifactor authentication (MFA) if not present, and monitor for unauthorized access attempts.

VendorsCiscoPalo Alto Networks
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary