A vulnerability in most Linux distros has been uncovered that allows a network-adjacent attacker to hijack VPN connections and inject rogue data into the secure tunnels that victims are using to communicate with remote servers. A proof-of-concept exploit works against OpenVPN, WireGuard and IKEv2/IPSec. The bug has been reported to distros and the Linux kernel security team, as well as others impacted such as Systemd, Google, Apple, OpenVPN and WireGuard.
Source: https://threatpost.com/linux-bug-vpns-hijacking/150891/

