
- Home
- Threat Advisories
- NCSC-TAD-2502-001
NCSC-TAD-2502-001
Severity Level: Low
Threat
Reference No.: NCSC-TAD-2502-001CVSS 0
Massive Brute Force Attack Targets VPN Devices
- Threat Type:
- N/A
- TLP:
- CLEAR
- CVE:
- N/A
Overview
large-scale brute force attack using 2.8 million IPs is targeting VPN devices. Major vendors affected include Palo Alto Networks, Ivanti, and SonicWall. The attack focuses on weak credentials and compromised firewalls and routers infected with malware botnets.
Mitigation and Immediate Actions
- 01
Changing default usernames and passwords.
- 02
Enforcing strong and unique credentials.
- 03
Enabling Multi-Factor Authentication (MFA).
- 04
Restricting access to VPN through trusted IPs.
- 05
Disabling unused services.
- 06
Applying regular firmware updates and security patches

