Blog | G5 Cyber Security

Mandiant uncovered Heartbleed based attacks to Hijack VPN sessions

Security experts at Mandiant uncovered attackers exploiting the Heartbleed vulnerability to circumvent Multi-factor authentication on VPNs. The investigators have found evidences of the attack analyzing IDS signatures and VPN logs. Mandiant confirmed that an unnamed organization suffered a targeted attack which exploited the Heartbleed bug in OpenSSL running in the clients SSL VPN concentrator to remotely access its internal network. The attackers are able to obtain active session tokens for currently authenticated users sending repeatedly malformed heartbeat requests to the HTTPS web server running on the VPN device.”]

Source: https://securityaffairs.co/wordpress/24172/cyber-crime/mandiant-heartbleed-vpn.html

Exit mobile version