• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

CISA and NSA Deliver New Security Guidance for VPNs

You are here: Home / General Cyber Security News / CISA and NSA Deliver New Security Guidance for VPNs
September 29, 2021

The US authorities have introduced new advice for companies on hardening their VPNs against compromise by cutting down the attack area.

The Cybersecurity Details Sheet comes from the NSA and Cybersecurity and Infrastructure Security Company (CISA).

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


It warned that several nation-point out actors had exploited acknowledged vulnerabilities in merchandise more than the previous yr to steal credentials, execute arbitrary code remotely on equipment, weaken and hijack encrypted communications, and browse delicate information.

“These results generally guide to further more destructive accessibility by means of the VPN, ensuing in huge-scale compromise of the corporate network or identity infrastructure and at times of different solutions as perfectly,” the companies claimed.

Their advice is to select expectations-based (IKE/IPSec) VPNs from reliable vendors with a demonstrated keep track of history for repairing vulnerabilities swiftly and mandating the use of robust authentication credentials.

At the time the product has been chosen, companies can proactively harden the machines by requiring “only powerful, accepted cryptographic protocols, algorithms, and authentication qualifications.”

The VPN attack area can be further more minimized by patching promptly, restricting exterior entry by port and protocol, and functioning only the strictly needed capabilities, the recognize continued.

At last, corporations were being urged to defend and keep track of accessibility to and from their VPNs with intrusion prevention (IPS), web software firewalls (WAFs), network segmentation, and remote and community logging for continual monitoring.

The warnings arrive immediately after a pandemic in which VPNs utilised by dwelling workers have been seriously targeted by both state-backed and financially determined cyber-criminals.

In October 2020, researchers warned that many teams were being applying the Zerologon vulnerability with VPN bugs to compromise victim networks.

In August very last calendar year, a key British higher road retailer was referred to as out for applying VPN servers with unpatched critical vulnerabilities, which set it at risk of ransomware and other threats.


Some elements of this post are sourced from:
www.infosecurity-journal.com

Previous Post: «Cyber Security News Most Third-Party Cloud Containers Have Vulnerabilities
Next Post: SolarWinds hackers are targeting Microsoft AD servers solarwinds hackers are targeting microsoft ad servers»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]
  • GoldFactory Hits Southeast Asia with Modified Banking Apps Driving 11,000+ Infections

Copyright © TheCyberSecurity.News, All Rights Reserved.