The Canadian Centre for Cyber Security (Cyber Centre), Australian Signals Directorate’s Australian Cyber Security Centre, and The UK’s National Cyber Security Centre (NCSC) have issued a joint warning about concerning threats to VPN services, in particular CISCO ASA55xx VPNs which are running firmware ASA versions 9.12 and 9.14.
The agencies say that since early 2024 they have been evaluating ongoing malicious cyber activity targeting virtual private network (VPN ) services. The ‘capabilities are indicative of espionage conducted by a well-resourced and sophisticated state-sponsored actor’ say the agencies. There ‘are no indicators suggesting that this threat activity is currently being used to preposition for disruptive or destructive computer network attack’.
Unauthorized access was gained to impacted devices through WebVPN sessions, commonly associated with Clientless SSLVPN services.
The joint warning states that:
The sophistication demonstrated by the threat actors’ use of multiple layers of novel techniques and the concurrent operations against multiple targets around the world is cause for concern to the authoring agencies. Since VPN services are essential components of computer network security, vulnerabilities in such services are particularly consequential and a public disclosure of critical vulnerabilities can enable their use by a wide variety of threat actors. We emphasize the need to patch devices quickly and to have a comprehensive defense in depth strategy.






