Get a Pentest and security assessment of your IT network.

News

Mandiant uncovered Heartbleed based attacks to Hijack VPN sessions

Security experts at Mandiant uncovered attackers exploiting the Heartbleed vulnerability to circumvent Multi-factor authentication on VPNs. The investigators have found evidences of the attack analyzing IDS signatures and VPN logs. Mandiant confirmed that an unnamed organization suffered a targeted attack which exploited the Heartbleed bug in OpenSSL running in the clients SSL VPN concentrator to remotely access its internal network. The attackers are able to obtain active session tokens for currently authenticated users sending repeatedly malformed heartbeat requests to the HTTPS web server running on the VPN device.”]

Source: https://securityaffairs.co/wordpress/24172/cyber-crime/mandiant-heartbleed-vpn.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Vulnerabilities In Alibaba threatens security of million users

News

Russian cybercriminal Roman Seleznev gets another prison sentence