An unprecedented increase in malicious scanning activity targeting Cisco ASA (Adaptive Security Appliances) occurred in late August 2025, with over 25,000 unique IP addresses participating in coordinated identification efforts.
See also: Cisco Nexus 3000 and 9000 Series: Vulnerability allows DoS attacks

GreyNoise offewer than 500 IPs per day. The peak on August 22nd included approximately 25,000 unique addresses, followed by a smaller but related campaign a few days later.
The analysis reveals that the August 26 wave was primarily driven by a single botnet cluster centered in Brazil. Of the approximately 17,000 active IPs that day, more than 14,000, representing over 80%, were associated with this coordinated botnet.
The attackers used common client signatures and spoofed Chrome-style user agents, indicating the deployment of common scanning tools across the infrastructure.
“The client signature appeared alongside a series of closely related TCP signatures, suggesting that all nodes share a common stack and tools,” the researchers noted, confirming the coordinated nature of the campaign.
Over the past 90 days, scanning activity has shown distinct geographic patterns. Brazil dominates the source countries with 64%, followed by Argentina and the United States with 8% each. However, targeting is heavily focused on US infrastructure, with 97% of attacks targeting US networks, while the UK and Germany account for 5% and 3% respectively, GreyNoise observed.
See also: Cisco: ISE RCE vulnerabilities are exploited in attacks

Both scan spikes specifically targeted the ASA web login path /+CSCOE+/logon.html, a common identifier used to identify exposed devices. Subsets of the same IP addresses also tested Cisco Telnet/SSH and ASA software personalities, indicating a deliberate campaign focused on Cisco rather than opportunistic scanning.
The timing and scale of these scanning campaigns can signal an impending vulnerability disclosure. GreyNoise’s Early Warning Signals research has shown that scanning spikes often precede the announcement of new Common Vulnerabilities and Exposures (CVEs). Historical data shows similar spikes in activity occurring shortly before previous Cisco ASA vulnerability disclosures.
Cisco ASA devices have been prime targets for sophisticated malicious actors. The ArcaneDoor previously exploited two zero-day vulnerabilities in Cisco ASA systems to infiltrate government networks. Ransomware groups including Akira and LockBit have also historically targeted these devices, while CVE-2020-3452 was deployed globally within days of its disclosure.
Organizations operating Cisco ASA infrastructure should immediately review their exposure, ensure systems are fully up-to-date, and monitor for unusual authentication attempts. Given the scale and coordination of this scanning activity, security teams should prepare for potential zero-day exploit attempts and consider implementing additional monitoring around ASA devices.
See also: Cisco patches another critical ISE vulnerability

The unprecedented scale of this reconnaissance campaign suggests that malicious actors may be preparing for a significant wave of vulnerability exploitation, making immediate defensive preparations critical for organizations relying on Cisco ASA security appliances.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
