An automated campaign is targeting multiple VPN platforms, with credential-based attacks being observed on Palo Alto Networks GlobalProtect and Cisco SSL VPN. On December 11, threat monitoring platform GreyNoise observed the number of login attempts aimed at GlobalProtect portals peaked at 1.7 million during a period of 16 hours. Collected data showed that the attacks originated from more than 10,000 unique IP addresses and were aimed at infrastructure located in the United States, Mexico, and Pakistan. The malicious traffic originated almost entirely from the 3xK GmbH (Germany) IP space, indicating a centralized cloud infrastructure. Based on researchers' observations, the threat actor reused common username and password combinations, and most of the requests were from a Firefox user agent that is uncommon for automated login activity through this provider. "The consistency of the user agent, request structure, and timing suggests scripted credential probing designed to identify exposed or weakly protected GlobalProtect portals, rather than interactive access attempts or vulnerability exploitation," GreyNoise explains. “This activity reflects continued pressure against enterprise VPN authentication endpoints, a pattern GreyNoise has observed repeatedly during periods of heightened attacker activity.” On December 12, activity originating from the same hosting provider using the same TCP fingerprint started to probe Cisco SSL VPN endpoints. GreyNoise monitors recorded a jump ...
New password spraying attacks target Cisco, PAN VPN gateways
BleepingComputer
·Bill Toulas
·Published Dec 18, 2025
·Updated
Affected Software
2 affected components
Palo Alto Networks GlobalProtect
Cisco SSL VPN
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses new automated password spraying attacks targeting Cisco and Palo Alto Networks VPN gateways.
2
What security implications are discussed?
The article highlights the risks of credential-based attacks on VPN platforms, which can lead to unauthorized access to networks.
3
What products or software are affected?
The affected products include Palo Alto Networks GlobalProtect and Cisco SSL VPN.
4
How are the password spraying attacks conducted?
The attacks are conducted automatedly to target multiple VPN platforms with credential-based strategies.
5
What date was the increase in attacks observed?
The increase in attacks was observed on December 11.