Spraying credentials from thousands of IP addresses targets VPNs, Cisco warns

For a month now, hackers have been conducting a large-scale credential stuffing attack on multiple Virtual Private Network (VPN) instances around the world. At this point it’s hard to say who is behind the attack, or what the motives are, but investigators have some clues.

As reported by Ars TechnicaCisco’s Talos security team recently alerted them to an ongoing campaign where attackers continue to try more than 2,000 usernames and around 100 passwords against different VPNs. Some of the products in the attackers’ crosshairs include Cisco Secure Firewall VPN, Checkpoint VPN, Fortinet VPN, SonicWall VPN, RD Web Services, Mikrotik, Draytek, and Ubiquiti, but others could also be targeted.