logo

Norway recommends replacing SSL VPN to prevent breaches

ID: 6482f2c0-47b3-5279-90f8-3eaece484bdc

STIX ID: report--6482f2c0-47b3-5279-90f8-3eaece484bdc

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-05-16

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The Norwegian NCSC warns that repeated, active exploitation of SSLVPN/WebVPN vulnerabilities (including zero-days used against Cisco ASA, FortiGate, and others) has enabled threat actors and ransomware groups to breach critical networks; it recommends migrating to IPsec with IKEv2 by 2025 (earlier for critical infrastructure), disabling SSLVPN, using certificate-based auth, and applying interim logging and geofencing mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.