Table of Contents
Summary
Remote-access infrastructure, including VPNs from vendors like Palo Alto Networks, Fortinet, Citrix and Check Point, remains a top ransomware entry point through both unpatched vulnerabilities and stolen credentials, especially where MFA is missing. Corero’s Zero Trust Admission Control (ZTAC) reduces this exposure by blocking traffic from known malicious sources, such as bots, Tor exit nodes and anonymising proxies, before it reaches the VPN gateway or NGFW. This source-based filtering doesn’t replace patching, MFA or segmentation, but adds a preventative layer that shields vulnerable systems and makes stolen credentials harder to exploit.
How Ransomware Operators Exploit VPN Vulnerabilities
Remote access is essential to modern business. Unfortunately, it has also become one of the most attractive entry points for ransomware operators.
A recent CSO Online article highlights the latest vulnerabilities attackers are targeting in VPN and other internet-facing security infrastructure, including equipment from Palo Alto Networks, Fortinet, Citrix and Check Point. These systems are valuable targets because they are continuously exposed to the Internet and can provide a direct route for attackers into corporate networks—often before patches are released, or organisations have had time to deploy those that are available.
Stolen Credentials Open the Front Door
But vulnerability exploitation is only part of the problem. The article reports that stolen credentials remain a major route into remote-access gateways, particularly where multi-factor authentication is absent. In other words, attackers do not always need to break the front door. Sometimes they can simply let themselves in, with a login.
Patching, strong authentication methods, and continuous monitoring remain essential. But organisations can strengthen their defences further by questioning a dangerous assumption: should every source on the internet be allowed to reach my remote-access infrastructure in the first place?
Zero Trust Admission Control Reduces VPN Attack Surface
Corero’s Zero Trust Admission Control (ZTAC) capability helps organisations reduce this exposed threat surface by controlling which traffic is permitted to reach critical services. Traffic originating from common sources of malicious activity, including; Bots, Tor exit nodes, anonymising proxies, and other untrusted infrastructure can be automatically blocked, before it reaches a VPN gateway, or NGFW.
Blocking Bots and Anonymising Proxies Early
That matters, because cybercriminals routinely use concealed or disposable infrastructure to scan for vulnerable systems, test stolen credentials, and launch attacks while obscuring their origins. Removing access from these sources can disrupt hostile activity earlier in the attack chain and reduce the volume of unwanted traffic that security teams and remote-access systems must process.
This is zero trust applied at the network edge: do not assume that an internet connection should be trusted simply because it can reach the login page.
Source-Based Filtering as Part of a Layered Defence
No single control can eliminate remote-access risk. Source-based filtering cannot replace rapid patching, phishing-resistant MFA, network segmentation, or effective credential security. But it adds an important preventative layer—one capable of shielding vulnerable infrastructure while patches are assessed and deployed, and making stolen credentials harder to exploit from high-risk locations on the Internet.
VPNs will remain a target, because they provide something attackers want: a path inside. Corero helps organisations narrow that path, deny access to known bad actors and turn an unnecessarily exposed front doors into a far more defensible point of entry.
FAQ
These systems are valuable targets because they are continuously exposed to the Internet and can provide a direct route for attackers into corporate networks—often before patches are released, or organisations have had time to deploy those that are available.
No. Stolen credentials remain a major route into remote-access gateways, particularly where multi-factor authentication is absent. Attackers do not always need to break the front door; sometimes they can simply let themselves in, with a login.
Corero’s Zero Trust Admission Control (ZTAC) capability helps organisations reduce this exposed threat surface by controlling which traffic is permitted to reach critical services. Traffic originating from common sources of malicious activity, including; Bots, Tor exit nodes, anonymising proxies, and other untrusted infrastructure can be automatically blocked, before it reaches a VPN gateway, or NGFW.
Cybercriminals routinely use concealed or disposable infrastructure to scan for vulnerable systems, test stolen credentials, and launch attacks while obscuring their origins. Removing access from these sources can disrupt hostile activity earlier in the attack chain and reduce the volume of unwanted traffic that security teams and remote-access systems must process.
No single control can eliminate remote-access risk. Source-based filtering cannot replace rapid patching, phishing-resistant MFA, network segmentation, or effective credential security. But it adds an important preventative layer—one capable of shielding vulnerable infrastructure while patches are assessed and deployed, and making stolen credentials harder to exploit from high-risk locations on the Internet.

