New password spraying attacks have begun targeting enterprise VPN gateways operated by Cisco and Palo Alto Networks, raising concerns about credential security across corporate remote access infrastructure. Security researchers observed a large-scale surge in automated login attempts aimed at SSL VPN and GlobalProtect portals, relying on stolen or commonly reused passwords rather than software exploits.
Large-scale credential campaign detected
Threat intelligence firm GreyNoise identified the activity in mid-December after detecting a sudden spike in authentication traffic. On December 11, attackers launched roughly 1.7 million login attempts over a 16-hour period against Palo Alto Networks GlobalProtect VPN portals.
The campaign relied on more than 10,000 unique IP addresses, allowing attackers to distribute attempts and avoid basic rate-limiting defenses. The following day, the activity shifted focus to Cisco SSL VPN gateways, where the number of attacking IPs rose sharply compared to normal background levels.
How the attacks work
Unlike vulnerability-based intrusions, these password spraying attacks attempt to authenticate using large numbers of known or commonly reused credentials across many accounts. Attackers typically test one or two passwords per account to avoid lockout protections while scanning for weak authentication practices.
GreyNoise reported that the requests followed highly structured patterns consistent with scripted automation. Most of the observed traffic originated from infrastructure tied to a German hosting provider, suggesting centralized coordination rather than random scanning.
No product vulnerabilities involved
Palo Alto Networks confirmed that the activity does not indicate a vulnerability or compromise within its products. Instead, the company emphasized that the attacks rely entirely on credential abuse and poor password hygiene.
Security analysts echoed that assessment, noting that even fully patched systems remain exposed when organizations fail to enforce strong passwords and multi-factor authentication.
Why VPN gateways remain a prime target
VPN login portals offer attackers direct access to internal corporate networks, making them a high-value entry point. Once attackers obtain valid credentials, they can bypass perimeter defenses and move laterally within enterprise environments.
Credential-based attacks also scale easily. Attackers can reuse stolen password lists across thousands of organizations while adapting their infrastructure to evade detection.
Mitigation and defensive steps
Organizations running Cisco or Palo Alto VPN gateways should treat the campaign as a reminder to strengthen authentication controls.
Recommended actions include:
- Enforcing multi-factor authentication on all VPN accounts
- Blocking or rate-limiting suspicious IP ranges
- Monitoring login logs for unusual volume or geographic patterns
- Requiring unique, complex passwords across all remote access systems
These steps significantly reduce the effectiveness of password spraying campaigns.
Conclusion
The latest password spraying attacks targeting Cisco and Palo Alto VPN gateways highlight a persistent weakness in enterprise security: credential reuse. Even without exploiting software flaws, attackers can still gain access when authentication controls remain weak. As remote access continues to play a central role in corporate environments, organizations face growing pressure to harden VPN authentication before attackers succeed.


0 responses to “Password spraying attacks target Cisco and Palo Alto VPN gateways”