Securing VPN Access
ID: 41478197-bd35-589c-b0e8-8c4cc9b04073
STIX ID: report--41478197-bd35-589c-b0e8-8c4cc9b04073
Feed Name: ReliaQuest Blog
ReliaQuest reports widespread exploitation of internet-exposed VPNs across sectors, outlining attacker pre-access reconnaissance (Shodan/Censys fingerprinting), credential acquisition (credential stuffing, password spraying, infostealers), exploitation of notable CVEs (Ivanti, FortiGate, Citrix, Cisco), and post-compromise activities (internal discovery, lateral movement, credential dumping, data exfiltration). The report emphasizes defensive measures—patch management, MFA and certificate authentication, strict access controls and segmentation, comprehensive logging, user training, and consideration of Zero Trust architectures—to reduce VPN attack surface and detect/respond to intrusions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
