Skip to main content
عربي
logo

NCSC-TAD-2502-001

Severity Level: Low
Threat

Reference No.: NCSC-TAD-2502-001CVSS 0

Massive Brute Force Attack Targets VPN Devices

Threat Type:
N/A
TLP:
CLEAR
CVE:
N/A

Overview

large-scale brute force attack using 2.8 million IPs is targeting VPN devices. Major vendors affected include Palo Alto Networks, Ivanti, and SonicWall. The attack focuses on weak credentials and compromised firewalls and routers infected with malware botnets.

Mitigation and Immediate Actions

  1. 01

    Changing default usernames and passwords.

  2. 02

    Enforcing strong and unique credentials.

  3. 03

    Enabling Multi-Factor Authentication (MFA).

  4. 04

    Restricting access to VPN through trusted IPs.

  5. 05

    Disabling unused services.

  6. 06

    Applying regular firmware updates and security patches

References