Pulling back the curtain on VPN breaches: they're supply chain attacks
Consider the “supply chain” attack. Many VPN vendors rely on a third-party data centers for compute resources which introduces risk, so VPN providers end up relying on the data center vendor to follow best practices for security resilience. While it’s understandable that the data center vendor would use a remote management system to monitor and maintain the servers they resell for use by other companies, such systems can be abused by attackers. When combined with user acco
Read more »