VPN devices from Palo Alto, Fortinet, Citrix and Check Point are being systematically exploited by ransomware groups because they provide direct network access and are frequently unpatched.
CVE-2026-15409 and CVE-2026-15410 in SonicWall SMA1000 enable unauthenticated and authenticated attacks with severity 10.0; immediate patches required, no workarounds available.
The U.S. Department of the Treasury sanctions a VPN provider for the first time for systematically supporting ransomware groups and other cybercriminals.
29 of 281 free Android VPN apps examined leak user data unencrypted outside the VPN tunnel – a fundamental security failure affecting over 2.4 billion installations.
More than 2.4 billion installations of free Android VPN apps with fundamental security flaws such as uncontrolled traffic leaks and missing encryption.
VPN technology protects only on the transmission path against man-in-the-middle attacks, not against malware, phishing, or modern tracking—and concentrates trust rather than eliminating it.
The critical vulnerability CVE-2026-50571 with CVSS 9.3 allows attackers to establish VPN sessions without valid passwords and has been actively exploited against organizations worldwide since May.