As cited
Copy frozen at (site build).
threat intel
Coordinated Brute Force Activity Targeting Apache Tomcat Manager Indicates Possible Upcoming Threats
GreyNoise detected a coordinated spike in brute force attacks against Apache Tomcat Manager interfaces on June 5, 2025, with attack volumes significantly exceeding normal baselines. The activity suggests attackers are systematically probing for exposed Tomcat services to gain unauthorized access at scale.
Why it matters: Organizations running exposed Apache Tomcat Manager interfaces face immediate risk of unauthorized access and potential compromise; security teams should audit Tomcat deployments, restrict manager access, and monitor for brute force attempts.
- Source published
- First seen by Cybersecurity Tracker