VPN devices from Palo Alto, Fortinet, Citrix and Check Point are being systematically exploited by ransomware groups because they provide direct network access and are frequently unpatched.
Authentication flaw in Palo Alto GlobalProtect is being actively exploited; attackers can bypass VPN protection and infiltrate corporate networks, making immediate security patching essential.