A list of plaintext usernames and passwords for 900 Pulse Secure VPN servers, along with IP addresses, has been shared on a Russian-speaking hacker forum. ZDNet has obtained a copy of the list with the help of threat intelligence firm KELA and verified confirmed the authenticity of the data. The vulnerability could be easily exploitable by using publicly available proof-of-concept code. All the servers included in the list were vulnerable to the CVE-2019-11510 flaw.”]
Source: https://securityaffairs.co/wordpress/106807/hacking/pulse-secure-vpn-passwords-leak.html