Skip to content
Automated Credential Campaign Targets VPN Services

Automated Credential Campaign Targets VPN Services

First seen 17 Dec 2025, 20:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

GreyNoise is monitoring a coordinated credential-based attack campaign aimed at enterprise VPN authentication systems, specifically targeting Cisco SSL VPN and Palo Alto Networks GlobalProtect services. The campaign involved large-scale scripted login attempts over a two-day period in mid-December, indicating a single entity leveraging consistent infrastructure across multiple platforms.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 183d ago How this analysis works

More articles in this cluster (5)

Following this threat?

Track Cisco and CVE-2025-20393 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed