Greynoise Automated Credential Campaign Targets VPN Services
Article Content
Browse articles
GreyNoise is monitoring a coordinated credential-based attack campaign aimed at enterprise VPN authentication systems, specifically targeting Cisco SSL VPN and Palo Alto Networks GlobalProtect services. The campaign involved large-scale scripted login attempts over a two-day period in mid-December, indicating a single entity leveraging consistent infrastructure across multiple platforms.
Ask AI about this cluster
Answers cite the sources they use
Updated 183d ago How this analysis works
More articles in this cluster (5)
Following this threat?
Track Cisco and CVE-2025-20393 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical OVERPASS Vulnerability in SAP Kernel Requires Immediate Action On September 8, 2026, SAP released security updates addressing 20 vulnerabilities, including a critical memory corruption flaw tracked as CVE-2026-44756, named OVERPASS. This vulnerability allows unauthenticated attackers to execute arbitrary commands on vulnerable SAP systems, leading to full compromise of business…
Critical GitLab Vulnerability Allows Unauthenticated Data Deletion GitLab released an emergency patch on August 17, 2026, for a critical vulnerability tracked as CVE-2026-19478. This flaw allows unauthenticated attackers to remotely modify or delete public projects and user data through a GraphQL directive, with a CVSS score of 9.4. Affected versions include GitLab Community Edition…