Tag: vpn
-
Settra ransomware variant deployed in recent attacks
Security researchers warned that hackers are using VPN credentials for initial access and deploying RMM tools. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/settra-ransomware-variant-recent-attacks/830787/
-
NightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
The NightEagle advanced persistent threat group, tracked as APT-Q-95, has expanded its operations to target businesses in Russia, combining stolen VPN credentials, a stealthy Microsoft Exchange backdoor, and legitimate tunneling technologies to move through victim networks. Researchers from Kaspersky’s Global Emergency Response Team said the group has been active since at least 2023 and previously…
-
NightEagle Hackers Target Russian Companies Using GhostContainer Backdoor
The NightEagle advanced persistent threat group, tracked as APT-Q-95, has expanded its operations to target businesses in Russia, combining stolen VPN credentials, a stealthy Microsoft Exchange backdoor, and legitimate tunneling technologies to move through victim networks. Researchers from Kaspersky’s Global Emergency Response Team said the group has been active since at least 2023 and previously…
-
Fremdzugänge auf Maschinen begrenzen Ablösung im Produktionsnetz
Tags: vpnFirst seen on security-insider.de Jump to article: www.security-insider.de/vpn-abloesung-im-produktionsnetz-a-e497f7be9523904b1909be6eb2029d24/
-
NonDay VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk
Tags: access, breach, data-breach, exploit, flaw, government, network, risk, service, vpn, vulnerability, zero-dayJapan ‘s Digital Agency disclosed a VPN breach exposing 246,000 government employee records across 23 ministries. Detected June 25, publicly disclosed September 11. Japan ‘s Digital Agency disclosed that attackers exploited a vulnerability in a VPN device to access its Government Solution Service (GSS), potentially leaking personal information belonging to approximately 246,000 government employees, public…
-
Japan’s Digital Agency says VPN flaw exposed 246,000 personnel records
Japan’s Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/japans-digital-agency-says-vpn-flaw-exposed-246-000-personnel-records/
-
Japan’s Digital Agency says VPN flaw exposed 246,000 personnel records
Japan’s Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/japans-digital-agency-says-vpn-flaw-exposed-246-000-personnel-records/
-
Cyber Threat Landscape: Real Attack Alerts and Recent Incidents
The Current Threat PictureThe supplied Seceon overview presents a clear picture of a modern enterprise threat landscape. Credential attacks, suspicious cloud authentication, VPN brute force, data-loss events, and major external campaigns can occur alongside one another. The most important operational… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/cyber-threat-landscape-real-attack-alerts-and-recent-incidents/
-
Dutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk
Two critical Check Point VPN flaws score 9.8 and could enable remote code execution. Patch now and restrict VPN access before exploitation begins. The Dutch NCSC warns that two critical vulnerabilities in Check Point VPN products, both rated CVSS score of 9.8, could soon be actively exploited. If you use Check Point VPN, you should…
-
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent/
-
Androids VPN-Sperre lässt sich wieder umgehen
Der Sicherheitsforscher Armin Å upuk entdeckte eine neue Schwachstelle, mit der man die VPN-Sperre von Android aushebeln kann. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/smartphones/androids-vpn-sperre-laesst-sich-weiterhin-umgehen-333390.html
-
Androids VPN-Sperre lässt sich wieder umgehen
Der Sicherheitsforscher Armin Å upuk entdeckte eine neue Schwachstelle, mit der man die VPN-Sperre von Android aushebeln kann. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/smartphones/androids-vpn-sperre-laesst-sich-weiterhin-umgehen-333390.html
-
Critical Check Point VPN Flaws Let Unauthenticated Attackers Execute Remote Code
Check Point has announced two critical vulnerabilities in its VPN technology that could allow unauthenticated remote attackers to execute arbitrary code on affected security gateways under certain conditions. These vulnerabilities, tracked as CVE-2026-85102 and CVE-2026-85103, impact both Remote Access VPN and Site-to-Site VPN functionalities. Check Point said its internal research team discovered and resolved these…
-
Surfshark VPN says hackers breached internal testing, proxy servers
Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/surfshark-vpn-says-hackers-breached-internal-testing-proxy-servers/
-
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only “under specific conditions” that it has not described.One flaw affects Check Point’s Security Gateways, its firewall appliances. The other affects those gateways…
-
This $50 lifetime VPN adds AI-powered protection to your connection
Get AI-powered threat protection, encrypted connections, and more with this VPN lifetime subscription today. The post This $50 lifetime VPN adds AI-powered protection to your connection appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/ghostshield-vpn-lifetime-subscription/
-
The Best 12 Business VPN Solutions, Compared and Priced
Best value overall: Tailscale. It publishes its pricing, has a genuinely usable free tier for small teams, and its per-service access model is more secure than the network-level access a traditional VPN gives you. Best free option: WireGuard, if you have the engineering capacity to run it yourself. Best enterprise picks: Palo Alto GlobalProtect and…
-
Confused about which VPN is right, US senator asks the NSA for guidance
Open source, commercial, single-hop, multi-hop, mixnet? The array of options is dizzying. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/09/us-senator-calls-on-the-nsa-to-give-guidance-for-use-of-vpns/
-
Kritische Sicherheitslücke: Sonicwall-Gateways werden attackiert
Angreifer haben es auf SSL-VPN-Gateways von Sonicwall abgesehen. Sie nutzen laut Hersteller zwei gefährliche Lücken aus. Admins sollten dringend handeln. First seen on golem.de Jump to article: www.golem.de/news/hersteller-warnt-sonicwall-firewalls-werden-attackiert-2609-212525.html
-
Wyden seeks upgraded NSA security guidance on commercial VPN use
Tags: vpnit’s the latest in a sequence of letters to feds from Sen. Ron Wyden, D-Ore., on commercial VPNs. First seen on cyberscoop.com Jump to article: cyberscoop.com/wyden-nsa-commercial-vpn-security-guidance/
-
SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs
SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild. SonicWall’s researchers William Perry and Adam Babis discovered the vulnerabilities. SonicWall confirmed that…
-
SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs
SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild. SonicWall’s researchers William Perry and Adam Babis discovered the vulnerabilities. SonicWall confirmed that…
-
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.The vulnerabilities, discovered internally by SonicWall’s William Perry and Adam Babis, are listed below – CVE-2026-83548 (CVSS score: 10.0) – A pre-authentication SSRF vulnerability in the Appliance First seen…
-
VPN-Apps mit Trackern: 85 Prozent spähen ihre Nutzer aus
Tags: vpnVPN-Apps mit Trackern: Proton hat mehr als 7.000 VPNs untersucht. 85 Prozent der US-Apps enthalten Tracker, einige erfassen den Standort. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/it-sicherheit/vpn-apps-mit-trackern-333227.html
-
Why Even the Best Edge Security Still Misses High-Risk Sessions
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisions. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/why-even-the-best-edge-security-still-misses-high-risk-sessions/
-
Passwörter geleakt: Berliner Senatsverwaltungen schränken Homeoffice ein
Nach einem Cyberangriff auf die Berliner Landes-IT werden die VPN-Zugänge der Mitarbeiter gekappt. Der Grund: Passwörter sind an die Öffentlichkeit gelangt. First seen on golem.de Jump to article: www.golem.de/news/passwoerter-geleakt-berliner-senatsverwaltungen-schraenken-homeoffice-ein-2609-212485.html
-
Russian-Speaking Hackers Used Cursor AI in Attacks on Seven Companies, Report Says
Russian-speaking hackers used Cursor AI during attacks on corporate networks, reportedly speeding reconnaissance, VPN access and exploitation attempts. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-cursor-ai-hackers-aur0ra-ransomware/
-
Fernwartung ohne Netzkopplung für kritische IT- und OT-Umgebungen Das Rendezvous-Prinzip
Fernzugriffe sind in Industrie, Verwaltung und kritischen Infrastrukturen unverzichtbar und zugleich ein bevorzugtes Einfallstor für Angreifer. Wer Steuerungen, Maschinen und Serverlandschaften aus der Ferne warten lässt, braucht mehr als ein klassisches Virtual Private Network (VPN). Gefragt ist eine Architektur, die Quell- und Zielnetz konsequent entkoppelt, jeden Zugriff von innen bestätigen lässt und lückenlos dokumentiert betrieben…
-
OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation
OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook and LinkedIn.The accounts “were being used to promote…
-
88 ID Verification Breaches Show the Cost of Collecting Identity Data
88 ID-verification breaches exposed billions of records, highlighting the growing risks of collecting sensitive identity and biometric data. A new report from Mysterium VPN compiles 88 documented incidents since 2011 where data collected specifically to verify someone’s identity or age got breached, exposed, or sold. The confirmed and researcher-verified total sits at 2.15 billion records,…

