Tag: vpn

NachoVPN Tool Exploits Flaws in Popular VPN Clients for System Compromise
News

NachoVPN Tool Exploits Flaws in Popular VPN Clients for System Compromise

Researchers studying cybersecurity have found a number of vulnerabilities in SonicWall and Palo Alto Networks virtual private network (VPN) clients that might be used to remotely execute code on Windows and macOS devices. According to a research by AmberWolf, attackers can easily obtain high levels of access, alter client behaviors, and execute arbitrary instructions by focusing on the implicit trust that VPN clients place in servers. This manifests as a rogue VPN server that can fool clients into downloading malicious updates that could have unforeseen repercussions in a hypothetical attack scenario read more about NachoVPN Tool Exploits Flaws in Popular VPN Clients for System Compromise. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity...
Apple Removes VPN Apps from Russian App Store Amid Government Pressure
News

Apple Removes VPN Apps from Russian App Store Amid Government Pressure

On July 4, 2024, Apple withdrew many virtual private network (VPN) apps from the App Store in Russia at the behest of Roskomnadzor, the Russian government's overseer over communications, according to Russian news outlets. According to MediaZona, this includes the mobile apps of 25 VPN service providers, such as ProtonVPN, Red Shield VPN, NordVPN, and Le VPN. It's important to remember that in March 2019, NordVPN closed all of its Russian servers. Apple's activities openly assist an authoritarian administration because they are driven by a desire to maintain money from the Russian market, according to a statement released by Red Shield VPN. This is a crime against civil society in addition to being careless. Le VPN stated in a similar notice that the removal of its app occurred pr...
Synology Releases Patch for Critical RCE Vulnerability Affecting VPN Plus Servers
Risk, Security

Synology Releases Patch for Critical RCE Vulnerability Affecting VPN Plus Servers

In order to fix a severe vulnerability affecting VPN Plus Server that might be used to hijack impacted devices, Synology has published security patches. The vulnerability, identified as CVE-2022-43931, has a maximum severity score of 10 on the CVSS scale and is defined as an out-of-bounds write flaw in Synology VPN Plus Server's remote desktop feature. The Taiwanese company added that successful exploitation of the flaw "allows remote attackers to execute arbitrary commands via undefined routes," adding that its Product Security Incident Response Team had detected it internally (PSIRT). Updates to versions 1.4.3-0534 and 1.4.4-0635 are recommended for users of VPN Plus Server for Synology Router Manager (SRM) 1.2 and SRM 1.3, respectively read the complete article Synology Releas...