Tag Archives: vpns

China state hackers infected 20,000 Fortinet VPNs, Dutch spy service says

reader comments 21 Hackers working for the Chinese government gained access to more than 20,000 VPN appliances sold by Fortinet using a critical vulnerability that the company failed to disclose for two weeks after fixing it, Netherlands government officials said. The vulnerability, tracked as CVE-2022-42475, is a heap-based buffer overflow that allows hackers to remotely… Read More »

Novel attack against virtually all VPN apps neuters their entire purpose

Getty Images reader comments 123 Researchers have devised an attack against nearly all virtual private network applications that forces them to send and receive some or all traffic outside of the encrypted tunnel designed to protect it from snooping or tampering. TunnelVision, as the researchers have named their attack, largely negates the entire purpose and… Read More »

Nation-state hackers exploit Cisco firewall 0-days to backdoor government networks

reader comments 16 Hackers backed by a powerful nation-state have been exploiting two zero-day vulnerabilities in Cisco firewalls in a five-month-long campaign that breaks into government networks around the world, researchers reported Wednesday. The attacks against Cisco’s Adaptive Security Appliances firewalls are the latest in a rash of network compromises that target firewalls, VPNs, and… Read More »

Attackers are pummeling networks around the world with millions of login attempts

Matejmo | Getty Images reader comments 14 Cisco’s Talos security team is warning of a large-scale credential compromise campaign that’s indiscriminately assailing networks with login attempts aimed at gaining unauthorized access to VPN, SSH, and web application accounts. The login attempts use both generic usernames and valid usernames targeted at specific organizations. Cisco included a… Read More »

Ivanti CEO pledges to “fundamentally transform” its hard-hit security model

Getty Images reader comments 36 Ivanti, the remote-access company whose remote-access products have been battered by severe exploits in recent months, has pledged a “new era,” one that “fundamentally transforms the Ivanti security operating model” backed by “a significant investment” and full board support. CEO Jeff Abbott’s open letter promises to revamp “core engineering, security,… Read More »

As if two Ivanti vulnerabilities under exploit weren’t bad enough, now there are 3

reader comments 12 Mass exploitation began over the weekend for yet another critical vulnerability in widely used VPN software sold by Ivanti, as hackers already targeting two previous vulnerabilities diversified, researchers said Monday. The new vulnerability, tracked as CVE-2024-21893, is what’s known as a server-side request forgery. Ivanti disclosed it on January 22, along with… Read More »

Mass exploitation of Ivanti VPNs is infecting networks around the globe

Enlarge / Cybercriminals or anonymous hackers use malware on mobile phones to hack personal and business passwords online. Getty Images reader comments 8 Hackers suspected of working for the Chinese government are mass exploiting a pair of critical vulnerabilities that give them complete control of virtual private network appliances sold by Ivanti, researchers said. As… Read More »

Zyxel patches critical vulnerability that can allow Firewall and VPN hijacks

reader comments 5 with 5 posters participating Share this story Hardware manufacturer Zyxel has issued patches for a highly critical security flaw that gives malicious hackers the ability to take control of a wide range of firewalls and VPN products the company sells to businesses. The flaw is an authentication bypass vulnerability that stems from… Read More »

VPN servers seized by Ukrainian authorities weren’t encrypted

reader comments 62 with 41 posters participating Share this story Privacy tools-seller Windscribe said it failed to encrypt company VPN servers that were recently confiscated by authorities in Ukraine, a lapse that made it possible for the authorities to impersonate Windscribe servers and capture and decrypt traffic passing through them. The Ontario, Canada-based company said… Read More »

More US agencies potentially hacked, this time with Pulse Secure exploits

Getty Images reader comments 23 with 19 posters participating Share this story At least five US federal agencies may have experienced cyberattacks that targeted recently discovered security flaws that give hackers free rein over vulnerable networks, the US Cybersecurity and Infrastructure Security Agency said on Friday. The vulnerabilities in Pulse Connect Secure, a VPN that… Read More »