Get a Pentest and security assessment of your IT network.

Cyber Security

Authentication Bypass Bug Hits Top Enterprise VPNs

VPN apps improperly store authentication tokens and session cookies without encryption. Attackers with local access to user s computer can access authentication and/or session tokens. Cisco, F5 Networks, Palo Alto Networks and Pulse Secure platforms are impacted. No patches appear to be available yet for Cisco AnyConnect, which stores the cookies in log files and in memory, according to the U.S. government advisory. The warning comes after a public disclosure by CERT/CC, the vulnerability disclosure center at Carnegie Mellon University.

Source: https://threatpost.com/authentication-bypass-bug-enterprise-vpns/143781/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security