vpn news
6 stories
Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
The FBI and Secret Service have issued a joint alert regarding "FortiBleed," a credential compromise campaign targeting Fortinet firewalls and VPN gateways. The agencies confirm that the campaign remains active and poses a significant threat, potentially leading to user lockouts and serving as an initial entry point for ransomware attacks.

ZDI-26-577: Trend Micro VPN OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Trend Micro's TrendLife VPN product has been found to contain a local privilege escalation vulnerability, tracked as CVE-2026-67212, which could allow an attacker to execute arbitrary code with SYSTEM privileges. The flaw, identified as ZDI-26-577 (ZDI-CAN-29830), stems from an uncontrolled search path element in the OpenSSL configuration used by the VPN client.

737 Chrome Extensions Caught Routing User Traffic Through Proxies
A recent report indicates that 737 Google Chrome extensions have been identified as surreptitiously routing user browser traffic through proxy servers. These extensions, which collectively amassed over 75,000 installations, were primarily observed targeting Russian-speaking users. The core functionality of these extensions appears to be the circumvention of geo-restrictions or service blocks,…

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
Reports indicate that a sophisticated threat actor, identified as UTA0533, has been actively exploiting two zero-day vulnerabilities within SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. These exploits were reportedly chained together to achieve arbitrary command execution and subsequently gain root access on affected systems. The exploitation occurred prior to the public…

FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices
The cybersecurity landscape is grappling with the fallout from "FortiBleed," a widespread credential abuse campaign targeting internet-exposed FortiGate devices. Public reports emerged in June 2026 detailing extensive datasets containing Fortinet-related URLs, device records, usernames, and credentials. This activity is not attributed to a single new vulnerability but rather the reuse of…

Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways
Organizations utilizing Fortinet firewalls and VPN gateways are being alerted to a global campaign that has targeted these devices. The National Cyber Security Centre (NCSC) in the UK has issued guidance for affected entities, urging them to investigate potential compromises and implement mitigation strategies.