WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Threat Awareness – Global Increase in Brute-Force Attacks Targeting VPNs and SSH Services
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Threat Awareness – Global Increase in Brute-Force Attacks Targeting VPNs and SSH Services

Author: Chase Snow

Created: Thursday, April 18, 2024 - 18:00

Categories: Cybersecurity, Security Preparedness

A global increase in brute-force attacks has been identified against a variety of targets which include VPN services, web application authentication interfaces, and SSH services since at least March 18, 2024. Cisco Talos is actively monitoring the increase in attacks and is providing details on affected services.

According to Talos, “depending on the target environment, successful attacks of this type may lead to unauthorized network access, account lockouts, or denial-of-service conditions. The traffic related to these attacks has increased with time and is likely to continue to rise.”

Known affected services:

  • Cisco Secure Firewall VPN
  • Checkpoint VPN 
  • Fortinet VPN 
  • SonicWall VPN 
  • RD Web Services
  • Miktrotik
  • Draytek
  • Ubiquiti

The brute-force attacks are targeting a variety of VPN services, therefore mitigations will vary depending on the affected service. Members are highly encouraged to assess your environment for potentially affected services and address accordingly, including enable logging, secure default remote access VPN profiles, and block connection attempts from malicious sources. Cisco provides additional guidance and recommendations on remote access VPN services in a recent Cisco support blog. For more information, access Cisco Talos.   

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 18, 2026)

Jun 18, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness
Members Only

(TLP:AMBER) IOC Associated with Volt Typhoon Performed Network Enumeration on Utah Infrastructure

Jun 18, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Email Impersonation Remains a Persistent Risk for Water Utilities

Jun 18, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar