• Services
  • Support

Your VPN Front Door – Stop Leaving It Open to Everyone.

Table of Contents

Summary

Remote-access infrastructure, including VPNs from vendors like Palo Alto Networks, Fortinet, Citrix and Check Point, remains a top ransomware entry point through both unpatched vulnerabilities and stolen credentials, especially where MFA is missing. Corero’s Zero Trust Admission Control (ZTAC) reduces this exposure by blocking traffic from known malicious sources, such as bots, Tor exit nodes and anonymising proxies, before it reaches the VPN gateway or NGFW. This source-based filtering doesn’t replace patching, MFA or segmentation, but adds a preventative layer that shields vulnerable systems and makes stolen credentials harder to exploit.

How Ransomware Operators Exploit VPN Vulnerabilities

Remote access is essential to modern business. Unfortunately, it has also become one of the most attractive entry points for ransomware operators.

A recent CSO Online article highlights the latest vulnerabilities attackers are targeting in VPN and other internet-facing security infrastructure, including equipment from Palo Alto Networks, Fortinet, Citrix and Check Point. These systems are valuable targets because they are continuously exposed to the Internet and can provide a direct route for attackers into corporate networks—often before patches are released, or organisations have had time to deploy those that are available.

Stolen Credentials Open the Front Door

But vulnerability exploitation is only part of the problem. The article reports that stolen credentials remain a major route into remote-access gateways, particularly where multi-factor authentication is absent. In other words, attackers do not always need to break the front door. Sometimes they can simply let themselves in, with a login.

Patching, strong authentication methods, and continuous monitoring remain essential. But organisations can strengthen their defences further by questioning a dangerous assumption: should every source on the internet be allowed to reach my remote-access infrastructure in the first place?

Zero Trust Admission Control Reduces VPN Attack Surface

Corero’s Zero Trust Admission Control (ZTAC) capability helps organisations reduce this exposed threat surface by controlling which traffic is permitted to reach critical services. Traffic originating from common sources of malicious activity, including; Bots, Tor exit nodes, anonymising proxies, and other untrusted infrastructure can be automatically blocked, before it reaches a VPN gateway, or NGFW.

Blocking Bots and Anonymising Proxies Early

That matters, because cybercriminals routinely use concealed or disposable infrastructure to scan for vulnerable systems, test stolen credentials, and launch attacks while obscuring their origins. Removing access from these sources can disrupt hostile activity earlier in the attack chain and reduce the volume of unwanted traffic that security teams and remote-access systems must process.

This is zero trust applied at the network edge: do not assume that an internet connection should be trusted simply because it can reach the login page.

Source-Based Filtering as Part of a Layered Defence

No single control can eliminate remote-access risk. Source-based filtering cannot replace rapid patching, phishing-resistant MFA, network segmentation, or effective credential security. But it adds an important preventative layer—one capable of shielding vulnerable infrastructure while patches are assessed and deployed, and making stolen credentials harder to exploit from high-risk locations on the Internet.

VPNs will remain a target, because they provide something attackers want: a path inside. Corero helps organisations narrow that path, deny access to known bad actors and turn an unnecessarily exposed front doors into a far more defensible point of entry.

Picture of Sean Newman

Sean Newman

Vice President, Product Management

FAQ

Why are VPN and remote-access gateways a top target for ransomware operators?

These systems are valuable targets because they are continuously exposed to the Internet and can provide a direct route for attackers into corporate networks—often before patches are released, or organisations have had time to deploy those that are available.

Do attackers only rely on unpatched vulnerabilities to get in?

No. Stolen credentials remain a major route into remote-access gateways, particularly where multi-factor authentication is absent. Attackers do not always need to break the front door; sometimes they can simply let themselves in, with a login.

What does Corero's Zero Trust Admission Control (ZTAC) do?

Corero’s Zero Trust Admission Control (ZTAC) capability helps organisations reduce this exposed threat surface by controlling which traffic is permitted to reach critical services. Traffic originating from common sources of malicious activity, including; Bots, Tor exit nodes, anonymising proxies, and other untrusted infrastructure can be automatically blocked, before it reaches a VPN gateway, or NGFW.

Why does blocking traffic from anonymising infrastructure matter?

Cybercriminals routinely use concealed or disposable infrastructure to scan for vulnerable systems, test stolen credentials, and launch attacks while obscuring their origins. Removing access from these sources can disrupt hostile activity earlier in the attack chain and reduce the volume of unwanted traffic that security teams and remote-access systems must process.

Does source-based filtering replace other security controls like patching and MFA?

No single control can eliminate remote-access risk. Source-based filtering cannot replace rapid patching, phishing-resistant MFA, network segmentation, or effective credential security. But it adds an important preventative layer—one capable of shielding vulnerable infrastructure while patches are assessed and deployed, and making stolen credentials harder to exploit from high-risk locations on the Internet.

Share the Post: