A widespread brute force attack is underway, exploiting nearly 2.8 million IP addresses, aimed at stealing credentials from a wide range of VPN devices. The affected devices include solutions from companies such as Palo Alto Networks, Ivanti , and SonicWall.
See also: Hackers use FastHTTP in new Microsoft 365 attacks

Brute force attacks are one of the simplest yet most persistent methods of cyberattacks. In such an attack, an attacker attempts to gain access to a system or account by continuously trying different combinations of usernames and passwords until they succeed. Although this method requires high computing power and time, it can be effective, especially in cases where weak or predictable passwords are used. To protect against such attacks, it is important to use strong passwords, enable multi-factor authentication, and use tools to limit failed login attempts.
According to threat monitoring platform The Shadowserver Foundation, a large-scale brute force attack on VPN devices has been ongoing since last month. Every day, nearly 2.8 million IP addresses are used as sources to carry out these attacks, indicating the severity and scale of the problem.
The majority of these, around 1.1 million, come from Brazil, followed by Turkey, Russia, Argentina, Morocco and Mexico. However, overall, people from a strikingly large number of countries of origin participate in the activity.
See also: Brute-force attacks target Citrix NetScaler devices
The attack targets advanced security devices, such as firewalls, VPNs, gateways, and other related technologies, which are often exposed online to facilitate remote access.

The devices carrying out these attacks are mostly MikroTik, Huawei, Cisco, Boa and ZTE and IoT, which are usually exploited by large botnets . ShadowServer also said that the attacking IP addresses are spread across multiple networks and Autonomous Systems and are likely a botnet or some operation related to home proxy networks.
Protection measures against brute force attacks
Steps to protect edge devices from brute force attacks, such as the latest one affecting VPN devices, include changing the default admin password to a strong and unique one, enforcing multi-factor authentication (MFA), using a trusted IP whitelist, and disabling web admin interfaces if they are not needed.
See also: Cisco patches vulnerability that allows Brute-Force
Finally, applying the latest firmware and security updates to these devices is crucial to eliminating vulnerabilities that threat actors can exploit to gain initial access.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
