As cited
Copy frozen at (site build).
threat intel
Coordinated Credential-Based Campaign Targets Cisco and Palo Alto Networks VPN Gateways
GreyNoise has identified a coordinated, automated campaign attempting to compromise enterprise VPN gateways through credential-based attacks targeting Cisco SSL VPN and Palo Alto Networks GlobalProtect services. The campaign appears to be systematically probing authentication infrastructure across multiple organizations.
Why it matters: Organizations using Cisco SSL VPN or Palo Alto Networks GlobalProtect should review access logs for brute force activity and enforce strong authentication controls, as successful compromise could grant attackers remote access to internal networks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Coordinated Credential-Based Campaign Targets Cisco and Palo Alto Networks VPN Gateways
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Coordinated Credential-Based Campaign Targets Cisco and Palo Alto Networks VPN Gateways
GreyNoise is tracking an automated, credential-based campaign targeting enterprise virtual private network (VPN) authentication infrastructure. The activity focuses on Cisco SSL VPN and Palo Alto Networks GlobalProtect services. The campaign appears coordinated and widespread across affected systems.
Why it matters: Organizations running Cisco SSL VPN or Palo Alto Networks GlobalProtect are under active credential attack and should review authentication logs, implement multifactor authentication (MFA) if not present, and monitor for unauthorized access attempts.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Coordinated Credential-Based Campaign Targets Cisco and Palo Alto Networks VPN Gateways
GreyNoise is tracking an automated, credential-based campaign targeting enterprise virtual private network (VPN) authentication infrastructure. The activity focuses on Cisco SSL VPN and Palo Alto Networks GlobalProtect services. The campaign appears coordinated and widespread across affected systems.
Why it matters: Organizations running Cisco SSL VPN or Palo Alto Networks GlobalProtect are under active credential attack and should review authentication logs, implement multifactor authentication (MFA) if not present, and monitor for unauthorized access attempts.
- Source published
- First seen by Cybersecurity Tracker