Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Hackers Actively Attacking Cisco and Palo Alto Networks VPN Gateways to Gain Login Access

Posted on December 18, 2025December 18, 2025 By CWS

Risk actors launched a coordinated brute-force marketing campaign in opposition to enterprise VPN gateways, hammering Palo Alto Networks GlobalProtect portals and Cisco SSL VPN endpoints with hundreds of thousands of automated login makes an attempt in mid-December 2025.

GreyNoise intelligence revealed the assaults stemmed from centralized infrastructure hosted by Germany’s 3xK GmbH, utilizing scripted credential stuffing somewhat than zero-day exploits. The operation pivoted quickly between distributors, underscoring persistent dangers to distant entry infrastructure.​

Palo Alto GlobalProtect Underneath Assault

GreyNoise sensors detected an enormous surge on December 11, with over 1.7 million periods flooding emulated GlobalProtect portals in simply 16 hours.

Greater than 10,000 distinctive IPs participated, primarily geolocated to america, Pakistan, and Mexico, however originating virtually completely from 3xK’s cloud-hosted ranges.

Attackers deployed uniform request patterns, widespread username-password combos, and a Firefox consumer agent atypical for such automation, pointing to credential probing for weak or uncovered portals.​

The sharp spike suggests a brand new stock effort or marketing campaign kickoff, as GreyNoise has tracked related waves throughout peak menace durations. No proof ties this to vulnerability exploitation; as a substitute, it mimics password spraying throughout doubtlessly huge stolen credential lists.​

Cisco SSL VPN Hit Subsequent

Exercise shifted to Cisco SSL VPNs on December 12, spiking distinctive attacking IPs from beneath 200 to 1,273 in a day, a stark anomaly. Most site visitors hit GreyNoise’s facade sensors, indicating opportunistic scanning somewhat than exact focusing on.

Periods shared the identical TCP fingerprint and 3xK IP house because the Palo Alto wave, with a dominant Home windows NT 10.0 consumer agent, uncommon for this supplier’s previous conduct.​

Request our bodies adopted customary SSL VPN login flaws, together with CSRF tokens and credential fields, confirming automated stuffing over exploits. This marks the primary large-scale 3xK deployment in opposition to Cisco SSL VPNs in 12 weeks.​

Fingerprint overlaps in TCP signatures, timing, and internet hosting affirm a unified actor or toolset probing a number of VPNs. GreyNoise explicitly dominated out hyperlinks to Cisco Talos’ UAT-9686 marketing campaign in opposition to Safe E mail merchandise. Patterns echo prior surges GreyNoise flagged, usually previous CVEs, although right here brute-force dominates.​

Enterprises ought to implement MFA, sturdy distinctive passwords, and routine audits of VPN logs for anomalies. GreyNoise recommends blocking tagged IPs by way of platform lists or free Block templates for Palo Alto Login Scanner and Cisco SSL VPN Bruteforcer. Distributors like Palo Alto urge the most recent PAN-OS variations amid recurring threats.​

GreyNoise continues monitoring the assault marketing campaign. This marketing campaign highlights VPNs as prime footholds; speedy hygiene checks might thwart breaches.​

Comply with us on Google Information, LinkedIn, and X for every day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Access, Actively, Alto, Attacking, Cisco, Gain, Gateways, Hackers, Login, Networks, Palo, VPN

Post navigation

Previous Post: Microsoft 365 Services and Copilot Outage Hits Users in Japan and China
Next Post: Cisco AsyncOS 0-Day Vulnerability Exploited in the Wild to run System-level Commands

Related Posts

Lampion Banking Malware Employs ClickFix Lures To Steal Banking Information Cyber Security News
Hackers Exploiting Cisco ASA Zero-Day to Deploy RayInitiator and LINE VIPER Malware Cyber Security News
Nisos Details Earlier Signs of Insider Detection via Authentication and Access Controls Cyber Security News
RingReaper Malware Attacking Linux Servers Evading EDR Solutions Cyber Security News
List of AI Tools Promoted by Threat Actors in Underground Forums and Their Capabilities Cyber Security News
10 Best Cloud Penetration Testing Companies in 2025 Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware
  • New Udados Botnet Launches Massive HTTP Flood DDoS Attacks Targeting Tech Sector
  • UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks
  • HPE Patches Critical Flaw in IT Infrastructure Management Software
  • HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware
  • New Udados Botnet Launches Massive HTTP Flood DDoS Attacks Targeting Tech Sector
  • UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks
  • HPE Patches Critical Flaw in IT Infrastructure Management Software
  • HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark