• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechCybersecurity

Homeland Security Says Hackers Could Crack Some Enterprise VPN Apps. Is Your Company at Risk?

By
Alyssa Newcomb
Alyssa Newcomb
Down Arrow Button Icon
By
Alyssa Newcomb
Alyssa Newcomb
Down Arrow Button Icon
April 12, 2019, 5:06 PM ET

VPN apps are supposed to help remote workers securely log onto their company’s servers, but critical vulnerabilities in apps made by at least four companies could be leaving the digital door wide open for hackers to steal corporate secrets.

The nonprofit CERT Coordination Center—which acts as the Internet’s emergency response team—and the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency issued an alert for enterprise VPN apps made by Cisco, Palo Alto Networks, Pulse Secure, and F5 Networks on Friday. The bulletin also warned that more testing will be required to determine if hundreds of other VPN apps are at risk.

These aren’t your run-of-the-mill VPN apps used by citizens to mask their private Internet surfing traffic. The services in question are enterprise solutions that are frequently deployed by corporate IT departments for people who need to work remotely, but also want access to their company’s private data, such as email and internal tools.

The apps appear to be incorrectly storing cookies on a person’s computer, according to the CERT bulletin. While the cookies are designed to help people bypass having to enter their password at every new login screen, they could be dangerous if the wrong person gains access.

A potential worst case scenario could be if a skilled hacker gained access to a person’s private computer through malware—they could then use the improperly stored cookies to log in to the enterprise VPNs, bypassing usual checkpoints where they might otherwise have to enter a password.

Palo Alto Networks has issued a patch for its GlobalProtect app, for both its Windows and Mac users, however the other companies named in the bulletin have not yet issued public responses. Hundreds of other apps could also be affected—but more testing will be required. A “generic configuration” may be the reason why the problem is being spread across companies, according to the bulletin.

Just two enterprise VPN vendors—Check Point Software Technologies and pfSense—were given an all clear in the CERT bulletin.

While it’s important to regularly check for security updates and patches, using two-factor authentication (2FA) as an extra layer of security can help companies ensure there’s no unauthorized access to their accounts, says Kathy Wang, director of security at Gitlab, an open source software development site. “A VPN is one means to an end, but not the only means,” she says.

Setting up 2FA can be as simple as adding an email address or phone number to an account. When you try to log in, the site would then send a unique, one-time code for users to enter, proving their identity.

About the Author
By Alyssa Newcomb
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

dario
AIWhite House
White House chief of staff to meet with Anthropic CEO about dangerous new Mythos model, official says
By Josh Boak, Matt O'Brien and The Associated PressApril 17, 2026
4 hours ago
Exclusive: Adam Silver on winning the Edison Achievement Award: ‘Sports remind us that some of the most important forms of innovation are human’
Arts & EntertainmentSports
Exclusive: Adam Silver on winning the Edison Achievement Award: ‘Sports remind us that some of the most important forms of innovation are human’
By Catherina GioinoApril 17, 2026
6 hours ago
chris lehane
AIOpenAI
OpenAI policy chief says AI companies ‘need to do a much better job’ talking about AI as industry leaders face personal attacks
By Jake AngeloApril 17, 2026
7 hours ago
ranch
North AmericaFood and drink
Ranch dressing’s secret history literally includes a Hidden Valley
By Holly Meyer and The Associated PressApril 17, 2026
8 hours ago
From left to right: Narendra Modi, Sam Altman, and Dario Amodei
AIOpenAI
Illinois is OpenAI and Anthropic’s latest battleground as the state tries to assess liability for catastrophes caused by AI
By Jacqueline MunisApril 17, 2026
9 hours ago
Jack Dorsey, the CEO of Block
SuccessLayoffs
Twitter cofounder Jack Dorsey breaks down his thought process when he laid off 40% of his Block staff because of AI
By Emma BurleighApril 17, 2026
9 hours ago

Most Popular

Pope Leo warned the world is in ‘big trouble’ if Elon Musk becomes the first trillionaire
Success
Pope Leo warned the world is in ‘big trouble’ if Elon Musk becomes the first trillionaire
By Preston ForeApril 17, 2026
15 hours ago
A world going broke: IMF says America's $39 trillion national debt is actually a global problem—and AI may be the only rescue
Economy
A world going broke: IMF says America's $39 trillion national debt is actually a global problem—and AI may be the only rescue
By Nick LichtenbergApril 16, 2026
1 day ago
Jeff Bezos pledged $10 billion for climate change. With the 2030 clock ticking, his wife, Lauren Sánchez Bezos, is leading the charge to spend it
Environment
Jeff Bezos pledged $10 billion for climate change. With the 2030 clock ticking, his wife, Lauren Sánchez Bezos, is leading the charge to spend it
By Sydney LakeApril 15, 2026
2 days ago
Germany already told its workers to ditch four-day weeks and work-life balance. Now the government wants to cut their pay for calling in sick, too
Success
Germany already told its workers to ditch four-day weeks and work-life balance. Now the government wants to cut their pay for calling in sick, too
By Orianna Rosa RoyleApril 16, 2026
2 days ago
MacKenzie Scott is bypassing the Ivy League and rewriting the $79 billion higher ed playbook by giving to HBCUs and community colleges
Politics
MacKenzie Scott is bypassing the Ivy League and rewriting the $79 billion higher ed playbook by giving to HBCUs and community colleges
By Sydney LakeApril 16, 2026
1 day ago
Iran has reopened the Strait of Hormuz—but experts say it now holds a card that works ‘almost like a nuclear deterrent’
Energy
Iran has reopened the Strait of Hormuz—but experts say it now holds a card that works ‘almost like a nuclear deterrent’
By Eva RoytburgApril 17, 2026
8 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.