logo

New NachoVPN attack uses rogue VPN servers to install malicious updates

ID: b11f1c96-87d6-5798-a923-f18bcacb780e

STIX ID: report--b11f1c96-87d6-5798-a923-f18bcacb780e

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-11-26

Date Updated: 2026-03-27

Author: Sergiu Gatlan

...
...

AmberWolf disclosed vulnerabilities dubbed “NachoVPN” affecting SonicWall NetExtender and Palo Alto GlobalProtect that enable attacker-controlled VPN servers to steal credentials, execute arbitrary code as elevated/system users, push malicious updates, and install malicious root certificates; PoC tool and technical advisories were released and vendors have issued patches or mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.