Virtual Private Networks (VPNs) are hugely popular, both with consumers looking to enhance privacy and organisations wanting to give remote employees secure access to internal applications.
Perhaps unsurprisingly, VPNs are also much loved by cybercriminals and nation-state hackers.
So loved, in fact, that the US Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark warning.
It has โfrequently identifiedโ VPNs being involved in high-profile security incidents, adding more than 22 Common Vulnerabilities and Exposures (CVEs) to the Known Exploited Vulnerabilities (KEV) list.
These have led, the CISA says, โto broad access to victim networksโ and are โprompting some to consider replacing their legacy VPN solutions with modern network access solutionsโ.
In the last few months alone we have seen:
Related: What are VPNs anyway?
How to make your business’ VPNs more secure
CISA says that โwhile some VPN solutions are inherently more secure than others โ and not always the cause of major cyber incidents โ current hybrid networks require adopting modern network access security solutions to help organisations protect corporate resources.โ
The kind of Secure Access Service Edge (SASE) and Secure Service Edge (SSE) solutions that the CISA guidance references offer, according to Adam Maruyama, Field CTO at Garrison Technology, โmore granular, context-sensitive controlsโ and so provide โadditional layers of protection to organisations in the event of a breachโ.
However, Maruyama warns that SASE and SSE software retains some residual risk.
“Just as attackers found vulnerabilities to exploit in the Internet-facing attack interfaces of VPNs,โ Maruyama says, โso too will attackers find ways to subvert the software mechanisms enforcing the SSE and SASE controls.โ
To counter these threats, Maruyama advises organisations to look toward verifiable, fixed-function security enforcement mechanisms โlike those enforced by hardware security technologiesโ for critical security functions.