Security News

DrayTek VPN routers hacked with new malware to steal data, evade detection
2023-03-06 15:03

An ongoing hacking campaign called 'Hiatus' targets DrayTek Vigor router models 2960 and 3900 to steal data from victims and build a covert proxy network. DrayTek Vigor devices are business-class VPN routers used by small to medium-size organizations for remote connectivity to corporate networks.

Microsoft Edge's built-in VPN support is around the corner
2023-02-26 16:48

Microsoft Edge's built-in VPN functionality could soon begin rolling out to all users in the stable channel, with some users already getting access to the feature.Edge's VPN 'Edge Secure Network' uses Cloudflare and aims to protect your device and sensitive data as you browse, but remember it is not a proper replacement for your VPN. Unlike traditional VPN extensions or tools, Edge uses Cloudflare's routing to encrypt your internet connection and protect your data from online threats like hackers.

Get lifetime access to this feature-rich VPN for just $60
2023-01-24 17:24

With so many options on the market, it's not easy to find the best VPN for you. Me VPN offers outstanding features, support for unlimited devices and a lifetime subscription, and it's now on sale for 86% off.

Beware: Tainted VPNs Being Used to Spread EyeSpy Surveillanceware
2023-01-13 16:39

Tainted VPN installers are being used to deliver a piece of surveillanceware dubbed EyeSpy as part of a malware campaign that started in May 2022. It uses "Components of SecondEye - a legitimate monitoring application - to spy on users of 20Speed VPN, an Iranian-based VPN service, via trojanized installers," Bitdefender said in an analysis.

Fortinet: Govt networks targeted with now-patched SSL-VPN zero-day
2023-01-12 16:05

Fortinet says unknown attackers exploited a FortiOS SSL-VPN zero-day vulnerability patched last month in attacks against government organizations and government-related targets. The security flaw abused in these incidents is a heap-based buffer overflow weakness found in the FortiOS SSLVPNd that allowed unauthenticated attackers to crash targeted devices remotely or gain remote code execution.

Things to know and do before you switch from VPN to ZTNA
2023-01-05 05:00

The reality of VPN vs. ZTNA. For a while now, VPN has been the proven, go-to solution when thinking about the best way to provide secure connectivity and ensure safety of data in transit. According to a recent poll, 81% of respondents currently utilize VPN to support remote work and 87% of the respondents who still use VPN say they have implemented at least one other solution to close the gaps.

Synology Releases Patch for Critical RCE Vulnerability Affecting VPN Plus Servers
2023-01-04 04:28

Synology has released security updates to address a critical flaw impacting VPN Plus Server that could be exploited to take over affected systems.Tracked as CVE-2022-43931, the vulnerability carries a maximum severity rating of 10 on the CVSS scale and has been described as an out-of-bounds write bug in the remote desktop functionality in Synology VPN Plus Server.

Synology fixes maximum severity vulnerability in VPN routers
2023-01-03 15:36

Taiwan-based NAS maker Synology has addressed a maximum severity vulnerability affecting routers configured to run as VPN servers. VPN Plus Server is a virtual private network server that allows administrators to set up Synology routers as a VPN server to allow remote access to resources behind the router.

Fortinet Warns of Active Exploitation of New SSL-VPN Pre-auth RCE Vulnerability
2022-12-13 03:34

Fortinet on Monday issued emergency patches for a severe security flaw affecting its FortiOS SSL-VPN product that it said is being actively exploited in the wild. Tracked as CVE-2022-42475, the critical bug relates to a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to execute arbitrary code via specially crafted requests.

Fortinet says SSL-VPN pre-auth RCE bug is exploited in attacks
2022-12-12 17:15

Fortinet urges customers to patch their appliances against an actively exploited FortiOS SSL-VPN vulnerability that could allow unauthenticated remote code execution on devices."A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests," warns Fortinet in a security advisory released today.