Cybersecurity researchers have uncovered a large-scale coordinated attack targeting Apache Tomcat Manager interfaces, with hundreds of malicious IP addresses attempting to breach exposed servers globally.
## The Attack Campaign
GreyNoise, a threat intelligence firm, detected a significant spike in brute-force and login attempts on June 5, 2025. The campaign involved 295 unique IP addresses conducting brute-force attacks against Tomcat Manager interfaces, all classified as malicious.
In the following 24-hour period, researchers observed:
– 188 unique IPs continuing brute-force attempts
– 298 unique IPs performing login attempts
– 246 of these IPs flagged as malicious
The attacking infrastructure primarily originated from the United States, United Kingdom, Germany, Netherlands, and Singapore, with many attacks launched from DigitalOcean-hosted servers.
## Targeted Regions
The campaign specifically targeted organizations in:
– United States
– United Kingdom
– Spain
– Germany
– India
– Brazil
## Security Recommendations
While not exploiting a specific vulnerability, this campaign represents opportunistic reconnaissance that often precedes more serious attacks. Organizations should:
– Implement strong authentication mechanisms
– Apply strict access restrictions to Tomcat Manager interfaces
– Monitor systems for suspicious activity
– Consider using firewalls or VPNs to limit access
## Additional Security Concern: Exposed Cameras
In related news, Bitsight researchers discovered over 40,000 security cameras openly accessible on the internet, creating significant privacy and security risks.
The exposed cameras were found primarily in:
– United States
– Japan
– Austria
– Czechia
– South Korea
By sector, the telecommunications industry accounted for 79% of exposed devices, followed by technology (6%), media (4.1%), and utilities (2.5%).
These unsecured cameras in homes, offices, public transit systems, and factories could be exploited for espionage, stalking, or extortion. Security researcher João Cruz warned that the ease of deploying these devices without proper security configuration continues to pose an ongoing threat.
To protect camera systems, users should:
– Change default credentials immediately
– Disable remote access when unnecessary
– Use firewalls and VPNs for required remote access
– Keep firmware updated regularly
These incidents underscore the critical importance of securing internet-facing services and devices against opportunistic attacks and unauthorized access.
