/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Hackers seen attacking enterprise networks' Webmin servers and VPN services by Pulse Secure and Fortinet, after critical flaws were recently made public

Catalin Cimpanu / ZDNet : Tweets: @gossithedog Tweets: Kevin Beaumont / @gossithedog : This is just one (super critical) vulnerability in this one SSL VPN product, which is over 4 months old. https://badpackets.net/... https://twitter.com/...

ZDNet Catalin Cimpanu

Context & Ripple Effects

This attack wave lands four months after DHS warned about VPN bugs in apps from Cisco, Palo Alto Networks, Pulse Secure, and F5 that grant remote access to enterprise networks — and researcher Kevin Beaumont notes the SSL VPN vulnerability being targeted is itself over four months old, meaning defenders have had the patch window and largely missed it.

The pattern here — disclosure followed quickly by mass scanning of exposed appliances — is the same one that later defined this product category: [[a:965466|FireEye and Pulse Secure tied a device flaw to China-linked groups hitting US defense customers]], and researchers found ~336K of ~490K Fortinet SSL VPN interfaces still unpatched months after FortiOS fixes shipped.

First-order effects

  • Enterprises running Pulse Secure and Fortinet VPN gateways or exposed Webmin servers face immediate scanning and compromise attempts the moment flaws go public, forcing emergency patching of internet-facing appliances.

Second-order effects

  • SSL VPN appliances harden into the most contested perimeter asset in enterprise security, as state-linked groups later exploit the same vendors' devices for access to government and defense networks per CISA and FireEye.

Third-order effects

  • If patch lag persists — Fortinet's 2023 numbers show most affected interfaces unpatched long after fixes — regulators and CERTs shift from advisories to mandatory remediation timelines for edge network appliances.

The trend: Enterprise SSL VPN gateways are becoming the most reliably exploited class of corporate infrastructure, with the gap between disclosure and patching setting the tempo of attack waves.

Discussion

  • @gossithedog Kevin Beaumont on x
    This is just one (super critical) vulnerability in this one SSL VPN product, which is over 4 months old. https://badpackets.net/... https://twitter.com/...