惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
博客园_首页
IT之家
IT之家
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Vercel News
Vercel News
美团技术团队
D
Docker
WordPress大学
WordPress大学
T
Tailwind CSS Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
The Cloudflare Blog
Y
Y Combinator Blog
F
Fortinet All Blogs
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
G
Google Developers Blog
爱范儿
爱范儿
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
月光博客
月光博客
MongoDB | Blog
MongoDB | Blog
S
SegmentFault 最新的问题
GbyAI
GbyAI
Hugging Face - Blog
Hugging Face - Blog
Microsoft Azure Blog
Microsoft Azure Blog
A
About on SuperTechFans

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
Brute-force cyberattacks originating in Middle East surge...
David Jones · 2026-04-14 · via Cybersecurity Dive - Latest News

An article from site logo

Hackers have primarily targeted SonicWall and Fortinet FortiGate devices, according to researchers.

Published April 14, 2026

Digital shield firewall with central computer processor and futuristic circuit board

Getty Images

A surge of brute force authentication attacks targeted network devices during the first quarter of 2026, with the vast majority of threat activity coming from the Middle East, according to a report released Tuesday by Barracuda

Almost 90% of the brute-force attacks originated from various Middle East locations, and the leading targets were SonicWall and Fortinet FortiGate devices, according to Barracuda researchers. These attacks accounted for more than half of all of the threat activity tracked by Barracuda between February and March. 

“These attacks were identified based on the geo-location of the IPs involved, nearly all originating from the Middle East,” Anthony Fusco, manager of cybersecurity analysts at Barracuda, told Cybersecurity Dive. 

Fusco noted that IP addresses alone are not considered a reliable indicator, but said it was “safe to assume” that a combination of state-linked and professional groups were involved. Attacks from opportunistic groups were also likely involved. 

Hackers have been aggressively scanning perimeter devices for weak or exposed credentials, according to the blog post. 

The surge in brute force activity coincided with increased targeting from Iran-nexus groups after the U.S. and Israel launched a bombing campaign in late February. U.S. authorities, including the FBI and the Cybersecurity and Infrastructure Security Agency, warned last week that Iran-linked hackers have targeted water, energy and other critical infrastructure sites in the U.S. 

Barracuda researchers could not explicitly link the surge in threat activity to the war, but the timeline overlaps with increased tension in the region. 

Security teams should enforce the use of multifactor authentication on firewalls and VPNs and use complex passwords, according to Barracuda. Also, organizations should monitor for repeated, failed login attempts. 

The focus on SonicWall and Fortinet is not unexpected, according to researchers. These devices are considered “high-value targets for initial access,” as they sit at the edge of remote access. 

SonicWall customers in late summer 2025 were hit by a wave of brute force attacks against the MySonicWall cloud backup service. Those attacks were linked to a state-sponsored threat actor. 

FortiGate appliances have been targeted in recent months by hackers using malicious single-sign-on logins, according to researchers at Arctic Wolf.