APT groups exploiting VPNs to carry out cyber attacks

NCSC and NSA warn that services from Palo Alto, Fortinet and Pulse Secure are vulnerable

The National Cyber Security Centre (NCSC) and the National Security Agency (NSA) have both issued warnings about vulnerabilities that exist in some versions of widely-used virtual private network (VPN) services.

Highly severe flaws across the VPN services developed by Palo Alto Networks, Fortinet and Pulse Connect Secure top the list of vulnerabilities have been exploited by attackers to gain access to vulnerable devices.

The flaws identified by the NCSC stem from vulnerabilities that allow an attacker to retrieve arbitrary files by exploiting the VPN, including documents that could contain user credentials.

These stolen credentials can then be used to connect to the VPN and change settings, as well as connect with other infrastructure. Such a connection could also give attackers access to privileges needed to run secondary exploits that target access to the root shell.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

"Users of these VPN products should investigate their logs for evidence of compromise, especially if it is possible that patches were not applied immediately after their release," the NCSC advisory said.

"Administrators should also look for evidence of compromised accounts in active use, such as anomalous IP locations or times. Snort rules are available in open source but may not pick up events for exploits over HTTPS."

The agency has also advised system administrators who suspect there may have been exploitation to revoke credentials that were at risk of theft, including both user and administrative credentials. Resetting credentials will protect against unauthorised access using credentials acquired before affected systems could have been patched.

"Pulse Secure are aware of and appreciated the reports published by NCSC," a spokesperson said.

"The more customers are made aware of severity of the vulnerabilities and the patch fix Pulse Secure had made available since April 24, 2019, the more motivated customers will be to take necessary and immediate mitigation action by upgrading their VPN system."

Related Resource

Why UEM is the key to enterprise IT security

A guide to effective endpoint security

Download now

The NSA, in its assessment, honed in on three critical Pulse Secure flaws that have been "weaponised" by nation state-sponsored cyber criminals. These vulnerabilities would allow for remote arbitrary file downloads and remote code execution on gateways.

Advertisement - Article continues below

The US agency also highlighted one critical vulnerability in Palo Alto GlobalProtect VPN that allowed for remote code execution, and another flaw in Fortinet Fortigate VPN devices.

"Our customer's security is our first priority and we urge customers to immediately implement all appropriate patch updates and signatures," Fortinet said.

"In addition to industry-leading best practices, we follow and comply with regular review processes that include multiple tiers of inspection, internal and third-party audits, and automated triggers and tools across the entire development of our source code."

The company added that it has recently improved its security practices, including the introduction of annual secure code training, a bug identification incentive programme, and automated monitoring of vulnerability landscape.

IT Pro also approached Palo Alto Networks for comment.

Featured Resources

Digitally perfecting the supply chain

How new technologies are being leveraged to transform the manufacturing supply chain

Download now

Three keys to maximise application migration and modernisation success

Harness the benefits that modernised applications can offer

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

The 3 approaches of Breach and Attack Simulation technologies

A guide to the nuances of BAS, helping you stay one step ahead of cyber criminals

Download now
Advertisement

Recommended

Visit/security/internet-security/354417/avast-and-avg-extensions-pulled-from-chrome
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them
operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020
Visit/business-strategy/public-sector/354608/uk-gov-launches-ps300000-sen-edtech-initiative
public sector

UK gov launches £300,000 SEN EdTech initiative

22 Jan 2020
Visit/hardware/354584/windows-10-and-the-tools-for-agile-working
Sponsored

Windows 10 and the tools for agile working

20 Jan 2020
Visit/web-browser/30394/what-is-http-error-503-and-how-do-you-fix-it
web browser

What is HTTP error 503 and how do you fix it?

7 Jan 2020