Краткий взгляд на UserGate SSL VPN портал

Современные требования к ИБ диктуют необходимость предоставления сотрудникам защищенного доступа к корпоративным сервисам без потери уровня контроля, удобства и производительности, при этом следуя пути импортозамещения. UserGate NGFW реализует функцию SSL VPN портала (Веб-портал) , которая позволяет осуществлять доступ ко внутренним FTP-, RDP-, SSH- и Web-серверам используя только браузер, не требуя установки специализированного ПО в операционной системе. Данный материал представляет собой небольшой обзор компонента: от его настройки до нюансов, обнаруженных в ходе его эксплуатации. Читать

https://habr.com/ru/articles/996402/

#usergate #ngfw #sslvpn #sase #ztna

Краткий взгляд на UserGate SSL VPN портал

А вот и он! Привет обитателям Хабра! Сегодня хотел бы рассмотреть вместе с вами один из модулей NGFW от UserGate для реализации удалённого доступа к ресурсам по протоколам HTTP(s), RDP, FTP и SSH...

Хабр

https://www.fortiguard.com/psirt/FG-IR-25-934

FortiGate SSLVPN vuln CVE-2025-68686

(Not) rated highly yet. However, I would promptly patch it (and quickly move away from SSL VPN, regardless of the vendor; instead use IKEv2 EAP-TLS or WireGuard). I think this one might rapidly elevate to a RCE

#infosec #fortigate #fortinet #sslvpn

PSIRT | FortiGuard Labs

None

FortiGuard Labs

SonicWall-VPN-Einbruch: Angreifer deaktivieren EDR über Kernel-Ebene mit widerrufenen Treibern

Die Angreifer verschafften sich im Februar 2026 Zugang zum Zielnetzwerk über gestohlene SonicWall-SSLVPN-Anmeldedaten.

https://www.all-about-security.de/sonicwall-vpn-einbruch-angreifer-deaktivieren-edr-ueber-kernel-ebene-mit-widerrufenen-treibern/

#vpn #edr #sslvpn #ssl

Nach SonicWall-VPN-Hack: Schutzmaßnahmen ergreifen

Nach dem SonicWall-VPN-Hack zeigen Angreifer eine raffinierte Methode zur Deaktivierung von EDR auf Kernel-Ebene.

All About Security Das Online-Magazin zu Cybersecurity (Cybersicherheit). Ransomware, Phishing, IT-Sicherheit, Netzwerksicherheit, KI, Threats, DDoS, Identity & Access, Plattformsicherheit

Fortinet confirms active exploitation of CVE-2020-12812.
A long-standing FortiOS SSL VPN flaw can bypass 2FA due to username case-sensitivity mismatches - especially in legacy deployments.

https://www.technadu.com/fortinet-warns-july-disclosed-ssl-vpn-flaw-is-being-used-to-bypass/616801/

Thoughts on mitigating MFA bypass risks?

#InfoSec #Fortinet #SSLVPN #MFA

Is your enterprise VPN stuck in the SSL era? 🦖

We unpacked the mechanics behind common issues like TCP meltdown, DTLS fallback, and mobility struggles in our new guide.

See why the transport protocol matters and what a modern, WireGuard-based alternative looks like in practice:

https://defguard.net/blog/ssl-vpn-performance-protocol-problem/

#SSLVPN #WireGuard #OpenSource #NetworkEngineering

Why is Your Fortinet VPN Slow? The SSL VPN Protocol Problem | Defguard Blog

Tired of users complaining your Fortinet VPN is slow? You're not alone. The problem is the SSL VPN protocol itself. See the facts & why even Fortinet is deprecating it.

defguard
Akira Ransomware Exploits SonicWall SSL VPN Vulnerability to Exfiltrate Data and Deploy Ransomware

This emerging threat exposes critical blind spots for enterprises acquiring smaller companies, as the inherited SonicWall devices

Cyber Security News

Nove zakrpe SonicWalla rješavaju ranjivosti visokog rizika u Email Security i SonicOS SSLVPN platformama. Stručnjaci savjetuju administratorima da bez odlaganja ažuriraju sisteme kako bi spriječili potencijalne upade i DoS napade.

#CyberSigurnost #Ranjivosti #CVE #DoS #EmailSigurnost #SonicWall #SSLVPN #SonicOS #Ažuriranje

Pročitaj više: https://cybersigurnost.ba/sonicwall-objavio-hitne-zakrpe-kriticne-ranjivosti-mogu-paralizirati-email-security-i-sonicos-sslvpn/

SonicWall objavio hitne zakrpe: Kritične ranjivosti mogu paralizirati Email Security i SonicOS SSLVPN

SonicWall je zakrpio kritične ranjivosti u Email Security i SonicOS SSLVPN sistemima koje bi napadači mogli iskoristiti za potpunu kompromitaciju i DoS napade, te poziva administratore na hitnu instalaciju nadogradnji.

Cybersigurnost.ba

Campaign #compromising #SonicWall #SSLVPN instances since October 4, 2025 (100 infections in 16 organizations known as of October 10). There is a suspicion, that the firewalls created cloud backups itself - without admin approval.

https://borncity.com/win/2025/10/12/sonicwall-sslvpn-sicherheitslucken-breit-ausgenutzt/

SonicWall SSLVPN compromised: Vulnerabilities widely exploited | Born's Tech and Windows World

🚨 New: Ukrainian network FDN3 (AS211736) linked to mass brute-force + password spraying on SSL VPN & RDP devices.
🔎 Findings:
✔️ Overlaps with/ Seychelles bulletproof ASNs
✔️ Prefixes tied to Russian & spam networks
✔️ Likely feeding RaaS crews like Black Basta
💬 Should defenders push harder for ASN-level blocking?
👉 Follow @technadu for daily cyber intel.

#FDN3 #BruteForceAttack #SSLVPN #RDP #Cybersecurity #Botnet #Ukraine #Intrinsec

Ist ja schön das #openVPNconnect versucht die #MTU selbst zu ermitteln, aber wenn von mir bewusst gesetzte Werte überschrieben werden und dadurch keine Verbinung zustqande kommt, dann ist es einfach nur Datenmüll! #openvpn #sslvpn #vpn #roadwarrior