Skip to content
Threat Feed

Tag

Vpn

18 briefs RSS
high advisory

US Sanctions First VPN Service and Administrator for Aiding Ransomware Groups

The U.S. Treasury Department sanctioned First VPN Service (1VPNS) and its administrator, Dmytro Rashevskyi, for facilitating ransomware attacks by providing anonymity and evasion capabilities to cybercriminals, and also sanctioned Yegeniy Vladimirovich Silayev for selling 'cryptors' that make malware harder to detect, impacting critical infrastructure.

First VPN Service +2 sanctions vpn ransomware cybercrime defense-evasion
2t 2i
medium threat

CVE-2026-0283: Authentication Bypass in Palo Alto Networks PAN-OS Large Scale VPN (LSVPN)

An authentication bypass vulnerability, CVE-2026-0283, in Palo Alto Networks PAN-OS software allows an unauthenticated attacker with network access to establish an unauthorized site-to-site VPN connection when LSVPN functionality with configured satellites is enabled, leading to potential access to internal network resources.

exploited PAN-OS 12.1 +3 authentication-bypass vpn network-device palo-alto-networks pan-os
1t
medium threat

CVE-2026-0277 Prisma Access Agent: Improper Certificate Validation on iOS

An improper certificate validation vulnerability (CVE-2026-0277) in the Prisma Access Agent for iOS, affecting versions prior to 26.2.1, enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic, leading to potential compromise of data confidentiality and integrity.

exploited Prisma Access Agent vulnerability mitm ios vpn palo-alto-networks
1t
medium advisory

IPSEC NAT Traversal Port Activity Used for Command and Control

A detection rule identifies suspicious outbound IPSEC NAT Traversal (NAT-T) tunnels, characterized by UDP traffic where both source and destination ports are 4500, originating from an internal host to an external destination, a technique frequently abused by threat actors to establish covert command and control channels or exfiltrate data while evading network defenses.

command-and-control network vpn exfiltration protocol-tunneling
1r 3t
high advisory

WatchGuard Firebox and Mobile VPN Client Vulnerabilities

WatchGuard has released security advisories to address critical vulnerabilities, including a race condition, use-after-free, and local privilege escalation, in its Fireware OS and Mobile VPN with SSL client for Windows, which could lead to remote code execution on appliances and local privilege escalation on client systems if not patched immediately.

Fireware OS 2025.1 +4 watchguard vulnerability network-device vpn privilege-escalation remote-code-execution
2t
medium advisory

FortiGate - New VPN SSL Web Portal Added

This brief details a detection for the addition of a new VPN SSL Web Portal on FortiGate Firewalls, a configuration change that could be utilized by attackers for establishing persistence or initial access to external remote services, as indicated by observed modifications of VPN SSL settings.

FortiGate Firewall fortigate vpn configuration-change network-device persistence initial-access
1r 2t
high threat

SonicWall Gen6 SSL-VPN MFA Bypass via CVE-2024-12802

Threat actors exploited CVE-2024-12802, a vulnerability in SonicWall Gen6 SSL-VPN appliances, to bypass multi-factor authentication (MFA) after brute-forcing VPN credentials, leading to the deployment of ransomware-related tools.

Gen6 SSL-VPN appliances +2 Initial Access Broker vpn mfa-bypass cve-2024-12802 sonicwall initial access
2r 1t 1c
medium advisory

CVE-2026-0257 PAN-OS GlobalProtect Authentication Bypass Vulnerability

An authentication bypass vulnerability exists in Palo Alto Networks PAN-OS GlobalProtect portal and gateway (CVE-2026-0257) when authentication override cookies are enabled, allowing an attacker to establish an unauthorized VPN connection.

PAN-OS +1 authentication bypass vpn cve-2026-0257
1r 1t
medium advisory

CVE-2026-0249 GlobalProtect App: Certificate Validation Bypass Vulnerabilities

CVE-2026-0249 describes multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect app that could allow an attacker to intercept encrypted communications and potentially compromise the endpoint, especially on macOS, Android, and ChromeOS.

GlobalProtect App cve-2026-0249 certificate validation man-in-the-middle globalprotect vpn
2r 1t
medium advisory

CVE-2026-0248 Prisma Access Agent Improper Certificate Validation Vulnerability

CVE-2026-0248 is an improper certificate validation vulnerability in Prisma Access Agent for Android and Chrome OS, enabling a man-in-the-middle (MitM) attack to intercept VPN traffic and capture sensitive device information by presenting a certificate issued by a trusted Certificate Authority.

Prisma Access Agent cve-2026-0248 mitm vpn certificate-validation
2r 2t
critical advisory

Multiple Vulnerabilities in strongSwan Enable Denial of Service and Code Execution

A remote, anonymous attacker can exploit multiple vulnerabilities in strongSwan to conduct a denial-of-service attack or potentially achieve arbitrary code execution.

strongSwan vpn denial-of-service code-execution
2r 2t
medium advisory

AWS Discovery API Calls from VPN ASN by New Identity

This rule detects the initial use of AWS discovery APIs from VPN-associated ASNs by a previously unseen identity, indicating potential reconnaissance activity.

Amazon Web Services cloud aws discovery vpn
2r 1t
critical advisory

OpenVPN-auth-oauth2 Authentication Bypass in Plugin Mode

A critical authentication bypass vulnerability exists in openvpn-auth-oauth2 versions 1.26.3 through 1.27.2 when deployed in the experimental plugin mode; clients that do not support WebAuth/SSO are incorrectly granted VPN access without completing OIDC authentication.

openvpn-auth-oauth2 openvpn authentication-bypass vpn
2r 1t
high advisory

Synology SSL VPN Client Plaintext Password Storage Vulnerability (CVE-2021-47961)

Synology SSL VPN Client before 1.4.5-0684 stores passwords in plaintext, allowing remote attackers to potentially access or manipulate user PIN codes, leading to unauthorized VPN configuration and traffic interception.

plaintext-password vpn synology
2r 1t 1c
high advisory

Fortigate VPN CVE-2023-27997 Exploitation Attempt

IDS alerts indicate a potential exploitation attempt against a Fortigate VPN server using CVE-2023-27997, characterized by repeated GET requests to the /remote/logincheck endpoint originating from a specific IPv6 address.

fortigate vpn cve-2023-27997 exploit initial-access
2r 1t
high advisory

Fortigate VPN Exploit Attempt via CVE-2023-27997 and Suspicious User-Agent

Multiple IDS alerts indicate potential exploitation attempts against Fortigate VPN servers using CVE-2023-27997, alongside traffic from a suspicious user agent, possibly indicating reconnaissance or exploit activity.

fortigate vpn cve-2023-27997 exploit network
3r 2t
medium advisory

FortiGate SSL VPN Login Followed by SIEM Alert

Detects FortiGate SSL VPN logins followed by a SIEM detection alert for the same user within a short timeframe, potentially indicating VPN abuse, credential compromise, or initial access followed by post-compromise activity.

FortiGate SSL VPN fortinet vpn initial-access credential-access
2r 1t
medium threat

Flax Typhoon Masquerading SoftEther VPN as Legitimate Windows Binaries

The Flax Typhoon group uses SoftEther VPN, masquerading the VPN client as legitimate Windows binaries like conhost.exe and dllhost.exe, to obfuscate their network activity within compromised Taiwanese organizations.

SoftEther VPN +3 Flax Typhoon +1 flax-typhoon defense-evasion lateral-movement vpn process-masquerading
2r 2t