Massive security hole in VPNs shows their shortcomings as a defensive measure

May 14, 2024
CSO Online
Researchers at Leviathan Security Group have uncovered an unpatchable vulnerability in virtual private networks (VPNs) known as TunnelVision. This flaw allows attackers to redirect VPN traffic and snoop on data in clear text while remaining undetected, as VPNs inherently lack the ability to protect data at entry and exit points, serving only as encrypted tunnels. The experts emphasize that VPNs are often inaccurately portrayed as comprehensive security solutions when in reality, they are primarily meant for connectivity. This misconception, alongside the difficulty in patching or replacing numerous operational VPNs in enterprises, poses significant security challenges that require a more layered approach to cybersecurity, known as defense in depth.
