Cybersecurity researchers have warned that the widespread network scans that have been targeting Cisco ASA equipment may be a sign of an impending product defect.
In late August, GreyNoise saw two notable increases in scanning activity, with up to 25,000 distinct IP addresses probing Cisco IOS Telnet/SSH and ASA login gateways.
About 17,000 IPs were used in the second wave, which was logged on August 26, 2025, and was mostly (80%) powered by a Brazilian botnet.
The threat actors’ employment of overlapping user agents that resembled Chrome in both instances points to a shared origin. The United States was the primary target of the scanning activities, although Germany and the United Kingdom were also targeted.
According to a prior explanation from GreyNoise, in 80% of situations, this type of reconnaissance activity comes before new vulnerabilities on the assessed products are revealed read more about Surge in networks scans targeting Cisco ASA devices raise concerns.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
