216.73.216.226

Coordinated Brute Force Campaign Targets Fortinet SSL VPN

· Published 13/08/2025 16:59 · Modified 13/08/2025 17:18

Export JSON

Essential information

Published
13/08/2025 16:59
Modified
13/08/2025 17:18
Tags
2025-08-13 brute-force fgfm fortimanager fortinet fortios ip blocking ssl vpn vulnerability
Related entities
3 observables, 6 techniques (mitre), 2 others

Description

A significant spike in traffic targeting SSL VPNs was observed on August 3, with over 780 unique IPs triggering the Bruteforcer tag. The activity was deliberate and precise, focusing on . Two distinct waves of attacks were identified: a long-running set of activity and a sudden burst beginning August 5. The second wave shifted from targeting to - profile. Historical data revealed a potential residential origin or proxy use. The analysis suggests evolving attack patterns and potential reuse of tooling. Research indicates that such spikes often precede new disclosures within six weeks. Defenders are advised to use GreyNoise to search for and block malicious IPs associated with this campaign.

External references