Vulnerabilities in business VPNs under the spotlight
ID: 3a245919-692c-524e-80c1-0f7f360bca9a
STIX ID: report--3a245919-692c-524e-80c1-0f7f360bca9a
Feed Name: WeLiveSecurity (ESET Research)
VPN software used by businesses has become a high-value target: the report summarizes how unpatched or poorly configured corporate VPNs enable credential theft, remote code execution, session hijacking, and large-scale network compromise. It cites real-world incidents (e.g., a prolonged VPN compromise at Global Affairs Canada), research like TunnelCrack affecting many VPNs, and warnings from agencies (NSA/CISA), and recommends rapid patching, hardening, multi-factor authentication, endpoint EDR, and considering zero-trust architectures to reduce risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
