The Problem
All VPNs enable lateral movement, which can often lead to ransomware attacks.
Prior to its recent emergency directive on Ivanti VPN vulnerabilities, the US Cybersecurity and Infrastructure Security Agency (CISA) had called out numerous other VPN CVEs over the years. Need more proof? Here's what a list of web and ChatGPT queries revealed as the "top VPN vulnerabilities reported by CISA recently".
The challenge is that VPNs, whether hosted on-premises or delivered via virtual machines as a cloud access service, do not deliver a zero trust architecture. Rather, they provide network access, which can be exploited in a breach, enabling attackers to travel laterally and compromise high-value assets elsewhere on a network.


