Vulnerable Private Networks: Corporate VPNs Exploited in the Wild
ID: dede5497-97f7-5d66-8380-11d6e5807b0f
STIX ID: report--dede5497-97f7-5d66-8380-11d6e5807b0f
Feed Name: Volexity Blog
**Pulse Secure SSL VPN exploitation and session hijacking:** The report warns that a vulnerability in Pulse Secure SSL VPNs has likely allowed attackers to steal cleartext credentials and session database data since August 2019, enabling session hijacking by setting a valid DSID cookie and bypassing authentication (including 2FA). It provides log examples for detecting unauthenticated web requests and remote address changes that indicate session reuse, and recommends monitoring for suspicious IPs and multi-factor authentication failures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
