Coordinated Brute-Force Attacks Target Cisco and Palo Alto VPN Gateways
First seen 18 Dec 2025, 03:51 UTC
•
•78% similarity
•42
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
In mid-December 2025, threat actors executed a brute-force campaign against Cisco SSL VPN and Palo Alto Networks GlobalProtect portals, conducting millions of automated login attempts. The attacks were traced back to infrastructure operated by Germany’s 3xK GmbH, utilizing scripted credential stuffing techniques instead of zero-day exploits.
ThreatCluster AI
How this analysis works