This is the last part of Attacking SSL VPN series. We have found 7 vulnerabilities in total, including a stack-based overflow on the management interface. Pulse Secure has been in our research queue for a long time because it was a critical infrastructure of Google, which is one of our long-term targets. Google applies the Zero Trust security model, and therefore the VPN is removed now. An intelligence also points out that there is already a China APT group exploiting this bug. So, if you havent updated your Palo Alto, Fortinet or Pulse Secure SSL VPN, please update it ASAP!”]