Cisco SSL VPNs — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
December 18, 2025
Last Seen
June 26, 2026

Cisco SSL VPNs is a technology platform tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed December 18, 2025; most recent activity June 26, 2026.

Overview

Cisco SSL VPNs (including gateways that provide SSL VPN access to remote networks) are a platform for secure remote connectivity, often featuring web-based login portals and clientless or client-based VPN options. They are a high-value attack surface in cybersecurity due to remote access credentials; recent patterns show a surge in credential-based login attempts, underscoring the importance of strong authentication, monitoring, and timely patching to mitigate unauthorized access.

Related Threat Clusters

  • Anubis Ransomware Attack Disrupts Adriatic Port Authority Operations

    The Anubis ransomware group launched a cyberattack on the Adriatic Port Authority, crippling operations and causing significant disruptions in maritime logistics. The attack, attributed to Anubis in January 2026,…

    8 articles · Updated June 15, 2026
  • Automated Credential Campaign Targets VPN Services

    GreyNoise is monitoring a coordinated credential-based attack campaign aimed at enterprise VPN authentication systems, specifically targeting Cisco SSL VPN and Palo Alto Networks GlobalProtect services. The campaign…

    5 articles · Updated December 17, 2025

Recent Intelligence Reports

  • The Anubis Ransomware Attack On The Adriatic Port Authority — www.resecurity.com · June 26, 2026
  • Surge of credential — Cybersecuritydive · December 18, 2025

CVSS v3.1 Breakdown