H-ISAC TLP White Threat Bulletin: Cisco Warns of Password Spray Attacks Against VPN Services on Cisco Secure Firewall Devices

To identify this activity in member environments, Cisco notes that a staggering amount of authentication requests in system logs are indicative of this activity. The organization has viewed instances of this campaign where hundreds of thousands of authentication requests were made. It has also been reported that this campaign is capable of making millions of requests for systems. Also, in this campaign, the username is always hidden in the logs until the no logging hide username command is configured on the Adaptive Security Appliance (ASA).  

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272