Norway recommends replacing SSL VPN to prevent breaches
ID: 6482f2c0-47b3-5279-90f8-3eaece484bdc
STIX ID: report--6482f2c0-47b3-5279-90f8-3eaece484bdc
Feed Name: Bleeping Computer
Threat Score
The Norwegian NCSC warns that repeated, active exploitation of SSLVPN/WebVPN vulnerabilities (including zero-days used against Cisco ASA, FortiGate, and others) has enabled threat actors and ransomware groups to breach critical networks; it recommends migrating to IPsec with IKEv2 by 2025 (earlier for critical infrastructure), disabling SSLVPN, using certificate-based auth, and applying interim logging and geofencing mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
