Malwarebytes Privacy VPN receives full third-party audit
ID: bd85d935-3039-55e0-8656-9191c80ba5e4
STIX ID: report--bd85d935-3039-55e0-8656-9191c80ba5e4
Feed Name: Malwarebytes Blog
Malwarebytes published results of a third-party audit of the infrastructure used by Malwarebytes Privacy VPN and AzireVPN, which identified two critical vulnerabilities — an absent signature validation of downloaded Debian images (CVSS 9.4) and unsigned PXE network boot files (CVSS 9.3) — plus additional issues (replay attacks, port relay misuse, observable traffic, padding oracle). The company reports several fixes already implemented, is addressing remaining items, and notes there is no evidence of user logging or active exploitation while acknowledging that exploitation would likely require significant physical or supply-chain access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
