WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Threat Awareness – Global Increase in Brute-Force Attacks Targeting VPNs and SSH Services
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Threat Awareness – Global Increase in Brute-Force Attacks Targeting VPNs and SSH Services

Author: Chase Snow

Created: Thursday, April 18, 2024 - 18:00

Categories: Cybersecurity, Security Preparedness

A global increase in brute-force attacks has been identified against a variety of targets which include VPN services, web application authentication interfaces, and SSH services since at least March 18, 2024. Cisco Talos is actively monitoring the increase in attacks and is providing details on affected services.

According to Talos, “depending on the target environment, successful attacks of this type may lead to unauthorized network access, account lockouts, or denial-of-service conditions. The traffic related to these attacks has increased with time and is likely to continue to rise.”

Known affected services:

  • Cisco Secure Firewall VPN
  • Checkpoint VPN 
  • Fortinet VPN 
  • SonicWall VPN 
  • RD Web Services
  • Miktrotik
  • Draytek
  • Ubiquiti

The brute-force attacks are targeting a variety of VPN services, therefore mitigations will vary depending on the affected service. Members are highly encouraged to assess your environment for potentially affected services and address accordingly, including enable logging, secure default remote access VPN profiles, and block connection attempts from malicious sources. Cisco provides additional guidance and recommendations on remote access VPN services in a recent Cisco support blog. For more information, access Cisco Talos.   

Related Resources

(TLP:CLEAR) Vulnerability Notification – Critical Vulnerability in Fortinet EMS Actively Exploited, CVE-2026-35616

May 29, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) GAO Report: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector

May 28, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

(TLP:CLEAR) FBI Releases Multiple Alerts on Credential Theft and Evolving Ransomware Intrusion Techniques

May 28, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar