Cyb3rius
@cyb3rius
· 6d
How are hackers breaking into VPN gateways in 2025?A massive brute-force campaign is hammering edge devices by replaying stolen credentials from infostealer malware, not by exploiting brand-new vulnerabilities.What happened: Since early March 2025, Lumen's Black Lotus Labs has tracked a distributed credential-stuffing offensive hitting Fortinet, SonicWall, Cisco, and Ivanti VPNs and firewalls. The attackers use botnets of compromised devices to slowly test stolen username/password pairs against admin portals, deliberately throttling attempts to stay below lockout thresholds and evade detection.Key numbers: 2.8 million source IP addresses involved in the attacking botnet.1.5 million+ login attempts per day observed at peak activity.5+ major VPN and firewall vendors targeted in the same campaign.Why it matters: Traditional brute force rarely worked, but credential stuffing turns one reused password into a full network foothold—especially when MFA is not enforced on admin accounts.Bottom line: Patching alone won't stop this; kill password reuse, enforce MFA everywhere, and stop exposing management interfaces to the internet.
0