top of page

Brazil leads exploitation against PaloAlto, SonicWall and Ivanti.

Brazil top1 country in attacks

ShadowServer Foundation has warned of a significant increase in brute force attacks against login interfaces of edge devices, particularly in Brazil. According to a report published on the 7th, more than 1 million Brazilian IPs were involved in the attacks, which reached peaks of 2.8 million IP addresses per day.


The main targets include devices from Palo Alto Networks, Ivanti, and SonicWall. Attackers exploit weak credentials and known vulnerabilities to gain unauthorized access. In addition to Brazil, attacks have also been attributed to IPs in Turkey, Russia, Argentina, Morocco, and Mexico. In late January, attacks focused on a critical flaw in SonicWall SMA 1000 series devices (CVE-2025-23006), allowing attackers to take control of the devices. Experts recommend adopting strong passwords and updating affected devices immediately.


Comments


Post: Blog2_Post
bottom of page