HomeSecurityCoordinated attack on Cisco, Fortinet and Palo Alto Networks devices

Coordinated attack on Cisco, Fortinet and Palo Alto Networks devices

Three exploit campaigns targeting Cisco and Palo Alto Networks firewalls and Fortinet VPNs originate from IPs in the same subnets, GreyNoise.

See also: 500% increase in scanning for Palo Alto Networks portals

Cisco

The threat intelligence firm initially warned of scanning attempts targeting Cisco ASA appliances in early September, about three weeks before Cisco disclosed two zero-day vulnerabilities affecting its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software .

The vulnerabilities, tracked as CVE-2025-20333 (CVSS score 9.9) and CVE-2025-20362 (CVSS score 6.5), were exploited in attacks linked to the ArcaneDoor, which is attributed to hackers based in China.

Last week, GreyNoise warned of a huge increase in scanning activity related to Palo Alto Networks GlobalProtect, as well as an increase in the number of unique ASNs involved.

The cybersecurity firm observed a 500% increase in scanning activity over two days, originating from approximately 1,300 IPs. Within a few days, the number of unique IPs involved increased to 2,200, as more threat actors were likely involved in the activity.

See also: 48+ Cisco Firewalls vulnerable to active zero-day vulnerability

Coordinated attack on Cisco, Fortinet and Palo Alto Networks devices

Last week, GreyNoise observed over 1.3 million unique login attempts targeting Palo Alto Networks firewalls and published a list of the credentials used in the campaign.

On Thursday, the company warned that scanning campaigns targeting Cisco and Palo Alto Networks firewalls are coming from IPs located on the same subnets and that they can also be linked to brute forcing attacks targeting Fortinet VPNs.

In fact, the threat intelligence firm says that about 80% of the increases in activity targeting firewall and VPN products from well-known vendors are an early warning that new vulnerabilities in these products are likely to be revealed within the next six weeks.

The three campaigns targeting Cisco, Fortinet, and Palo Alto Networks devices share TCP fingerprints, use the same subnets, and exhibit increased activity at similar times.

See also: CISA: Requires Cisco to patch zero-day vulnerabilities

ransomware-2020-average ransom payment

The company has also published a list of the credentials used in the Fortinet campaign.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS