HomeSecurityCisco ASA: Hackers exploit vulnerabilities in 25,000 IPs

Cisco ASA: Hackers exploit vulnerabilities on 25,000 IPs

An unprecedented increase in malicious scanning activity targeting Cisco ASA (Adaptive Security Appliances) occurred in late August 2025, with over 25,000 unique IP addresses participating in coordinated identification efforts.

See also: Cisco Nexus 3000 and 9000 Series: Vulnerability allows DoS attacks

Cisco ASA

GreyNoise offewer than 500 IPs per day. The peak on August 22nd included approximately 25,000 unique addresses, followed by a smaller but related campaign a few days later.

The analysis reveals that the August 26 wave was primarily driven by a single botnet cluster centered in Brazil. Of the approximately 17,000 active IPs that day, more than 14,000, representing over 80%, were associated with this coordinated botnet.

The attackers used common client signatures and spoofed Chrome-style user agents, indicating the deployment of common scanning tools across the infrastructure.

“The client signature appeared alongside a series of closely related TCP signatures, suggesting that all nodes share a common stack and tools,” the researchers noted, confirming the coordinated nature of the campaign.

Over the past 90 days, scanning activity has shown distinct geographic patterns. Brazil dominates the source countries with 64%, followed by Argentina and the United States with 8% each. However, targeting is heavily focused on US infrastructure, with 97% of attacks targeting US networks, while the UK and Germany account for 5% and 3% respectively, GreyNoise observed.

See also: Cisco: ISE RCE vulnerabilities are exploited in attacks

Cisco ASA: Hackers exploit vulnerabilities on 25,000 IPs

Both scan spikes specifically targeted the ASA web login path /+CSCOE+/logon.html, a common identifier used to identify exposed devices. Subsets of the same IP addresses also tested Cisco Telnet/SSH and ASA software personalities, indicating a deliberate campaign focused on Cisco rather than opportunistic scanning.

The timing and scale of these scanning campaigns can signal an impending vulnerability disclosure. GreyNoise’s Early Warning Signals research has shown that scanning spikes often precede the announcement of new Common Vulnerabilities and Exposures (CVEs). Historical data shows similar spikes in activity occurring shortly before previous Cisco ASA vulnerability disclosures.

Cisco ASA devices have been prime targets for sophisticated malicious actors. The ArcaneDoor previously exploited two zero-day vulnerabilities in Cisco ASA systems to infiltrate government networks. Ransomware groups including Akira and LockBit have also historically targeted these devices, while CVE-2020-3452 was deployed globally within days of its disclosure.

Organizations operating Cisco ASA infrastructure should immediately review their exposure, ensure systems are fully up-to-date, and monitor for unusual authentication attempts. Given the scale and coordination of this scanning activity, security teams should prepare for potential zero-day exploit attempts and consider implementing additional monitoring around ASA devices.

See also: Cisco patches another critical ISE vulnerability

Cisco ASA: Hackers exploit vulnerabilities on 25,000 IPs

The unprecedented scale of this reconnaissance campaign suggests that malicious actors may be preparing for a significant wave of vulnerability exploitation, making immediate defensive preparations critical for organizations relying on Cisco ASA security appliances.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS