A set of flaws called “NachoVPN” allow attacks via compromised VPN servers that install malicious updates when unpatched Palo Alto and SonicWall SSL-VPN.
See also: NymVPN – The new era of digital anonymity and privacy

AmberWolf security researchers have found that malicious actors can trick potential targets into connecting SonicWall NetExtender and Palo Alto Networks GlobalProtect VPN clients to VPN servers controlled by attackers using malicious websites or documents in social engineering or phishing attacks.
Hackers can use VPN endpoints to steal victims' login credentials, execute arbitrary code with elevated privileges, install malware through updates, and perform code signature forgery or man-in-the-middle attacks by installing malicious root certificates.
SonicWall released patches to address the CVE-2024-29014 NetExtender in July, two months after it was initially reported in May, and Palo Alto Networks released security updates today for the CVE-2024-5921 GlobalProtect, seven months after it was notified of the flaw in April and nearly a month after AmberWolf published vulnerability details at SANS HackFest Hollywood.
See also: D-Link: Recommends replacing old VPN routers due to vulnerability
While SonicWall says customers should install NetExtender Windows 10.2.341 or later to patch the security flaw, Palo Alto Networks says running the VPN client in FIPS-CC mode can also reduce potential attacks in addition to installing GlobalProtect 6.2.6 or later (which fixes the vulnerability).

On Tuesday, AmberWolf revealed additional details about the two flaws and released an open-source tool called NachoVPN, which simulates compromised VPN servers that can exploit these vulnerabilities in attacks.
AmberWolf also released advisories with more technical information about the SonicWall NetExtender and Palo Alto Networks GlobalProtect vulnerabilities, as well as details and recommendations for attack vectors, to help defenders protect their networks from potential attacks.
See also: Google's VPN may finally come to the Pixel Tablet
Virtual Private Network (VPN) servers are essential for maintaining privacy and security online. These servers act as intermediaries between your device and the internet, encrypting your data and masking your real IP address with an anonymous one. This process not only protects sensitive information from cyber threats, but also allows users to bypass geo-restrictions and access content from different parts of the world. VPN servers are located worldwide, allowing users to select a server in the country of their choice to optimize speed and accessibility. As cybersecurity threats continue to evolve, using VPN servers has become an increasingly popular method of safeguarding one’s digital presence.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
