Watch out for rogue DHCP servers decloaking your VPN connections
ID: f2debabb-9a43-5bad-be3c-ce39c3c9e8a0
STIX ID: report--f2debabb-9a43-5bad-be3c-ce39c3c9e8a0
Feed Name: The Register (Security)
Threat Score
Researchers disclosed 'TunnelVision' (CVE-2024-3661), a DHCP option 121 abuse that allows an attacker controlling a DHCP server on the same LAN to inject routes that divert VPN traffic outside encrypted tunnels; most VPNs and kill-switches do not detect the reroute, Android is not affected, and mitigations (network namespaces, DHCP filtering, dedicated hotspots) are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
