In a tweet yesterday, the company Zerodium said it is trying to obtain zero-day exploits for vulnerabilities in three popular virtual private network (VPN) service providers.

See also: NSA, CISA: Guidelines for strengthening the security of VPN solutions
VPN services allow users to hide their IP address when accessing online resources byrouting the connection through the provider's servers.
This routing makes it more difficult for third parties to monitor their online activity, increasing their privacy.
Zerodium's current focus is on vulnerabilities affecting Windows for the NordVPN, ExpressVPN, and SurfShark VPN services. All of these serve millions of users, with the first two claiming at least 17 million users worldwide.
According to figures on their websites, the three companies operate more than 11,000 servers in dozens of countries.
The company's announcement today called for bugs that could reveal information about users, their IP addresses, and vulnerabilities that could be exploited to achieve remote code execution. One type of flaw that Zerodium doesn't want is local privilege escalation.
See also: Why use a VPN for Netflix

Zerodium's customer base consists of government institutions, primarily from Europe and North America, that need advanced zero-day exploits and cybersecurity capabilities.
The reason behind the operator's announcement remains unknown, but one motive could be that government customers need a way to detect cybercriminal activity hiding behind VPN services.
NordVPN and Surfshark have been used by threat actors in the past.
Last year, the Federal Bureau of Investigation (FBI) alerted to Iranian hackers using the NordVPN to run the fake Proud Boys.
A more recent example is from the National Security Agency (NSA) this year, which warned that Russian hackers were launching brute force attacks against Kubernetes servers with their origins hidden through TOR and VPN services, including Surfshark and NordVPN.
See also: Why use a VPN for Netflix
The company says its business is driven by ethics and selects customers based on strict criteria and vetting processes. And that only a small number of government customers have access to acquired zero-day research.
