#VPN
17 stories taggedVPN.

Citrix Patches Critical Login-Bypass Flaw in NetScaler, Attacks Expected Soon
A security hole rated 9.3 out of 10 lets criminals walk straight past the login screen on widely used corporate network gear. Patches are out now, and researchers say exploitation is a matter of when, not if.

737 Fake VPN Extensions in Chrome Store Quietly Hijacked Browsers
The free browser add-ons promised to unblock websites for Russian speakers. Instead they routed every page a user visited through servers the operators controlled.

Cisco firewalls are being crashed through a VPN flaw, and the fix is a full software upgrade
A high-severity bug in Cisco's Secure Firewall ASA and FTD software lets attackers reboot devices remotely with a single crafted web request. Cisco says the attacks started in August.

Trojanised QuickFox VPN installer plants stealth backdoor on users' PCs
Fortinet researchers say a tampered version of the China-focused VPN app has been serving the FDMTP backdoor since at least August 2025, with tradecraft that overlaps activity tracked as Silver Fox.

Ransomware gangs are going after VPNs, and an AI just ran its own attack
Ransomware attacks rose for the fourth month in a row in June, with criminals targeting the devices companies use to connect remote workers. A new AI-driven attack completed an entire break-in with no human at the keyboard.

What is a VPN and when do you actually need one?
VPNs encrypt your internet traffic and hide your real IP address, but they are not a privacy cure-all. Here is when one genuinely helps and when it does not.

SonicWall VPN Appliances Hit by Zero-Day Attacks Weeks Before Public Warning
A newly identified group, tracked as UTA0533, broke into SonicWall SMA 1000 devices using unknown flaws from late June 2026, gaining the highest level of access.

US sanctions a VPN, a malware disguiser, and the people behind them for helping ransomware gangs
Treasury targets 1VPNS and a Belarusian 'crypter' seller who together helped ransomware crews hit hospitals, banks and local governments.

US Treasury Sanctions VPN Provider Accused of Selling Cover to Ransomware Gangs
OFAC hits 1VPNS, its Ukrainian operator, and a malware cryptor seller, accusing them of helping ransomware crews attack American victims.

Nine in Ten Top Adult Sites Now Check Ages in Australia, But VPN Workarounds Are Next on the Regulator's List
Australia's online safety watchdog says most major adult platforms have put age gates in place since March. Now it wants to know whether a simple privacy tool is letting users walk straight around them.

Free Android VPNs Are Leaking Your Traffic, Study of 281 Apps Finds
Researchers tested the most popular free VPN apps on Google Play. Many fail at the one job they promise: keeping your internet activity private.

Palo Alto Confirms In-the-Wild Abuse of GlobalProtect Auth Bypass (CVE-2026-0257)
An unknown actor is exploiting a 7.8-rated authentication bypass in PAN-OS portals and gateways to slip past GlobalProtect logins.

Check Point Issues Emergency Patches After IKEv1 Auth Bypass Draws Qilin Affiliate
Two certificate-validation flaws in Check Point's VPN stack — one already exploited, one caught during the ensuing review — have prompted hotfixes across nine Quantum software versions.

Check Point Confirms Active Exploitation of IKEv1 Cert-Bypass Flaw in Remote Access VPN
CVE-2026-50751 lets unauthenticated attackers slip past authentication on gateways still running the deprecated IKEv1 key exchange. Patch is out. Exploitation is not theoretical.

CVE-2026-0257: Palo Alto GlobalProtect Authentication Bypass Hit in the Wild Within Days of Disclosure
A credential-less VPN session forgery flaw in PAN-OS moved from 'medium severity, no known exploitation' to CISA's KEV catalog in sixteen days. Federal agencies had 72 hours to patch.