• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

As CEO of the $96 billion Sam’s Club, Latriece Watkins is testing her mettle at the warehouse retailer that produced CEOs for Walmart, Target, and Walgreens

2

Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year

3

The river that supplies 40 million Americans is down to 23% — and about to make a $25 million bet on one fish

1

As CEO of the $96 billion Sam’s Club, Latriece Watkins is testing her mettle at the warehouse retailer that produced CEOs for Walmart, Target, and Walgreens

2

Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year

3

The river that supplies 40 million Americans is down to 23% — and about to make a $25 million bet on one fish
TechCybersecurity

Homeland Security Says Hackers Could Crack Some Enterprise VPN Apps. Is Your Company at Risk?

By
Alyssa Newcomb
Alyssa Newcomb
Down Arrow Button Icon
By
Alyssa Newcomb
Alyssa Newcomb
Down Arrow Button Icon
April 12, 2019, 5:06 PM ET

VPN apps are supposed to help remote workers securely log onto their company’s servers, but critical vulnerabilities in apps made by at least four companies could be leaving the digital door wide open for hackers to steal corporate secrets.

The nonprofit CERT Coordination Center—which acts as the Internet’s emergency response team—and the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency issued an alert for enterprise VPN apps made by Cisco, Palo Alto Networks, Pulse Secure, and F5 Networks on Friday. The bulletin also warned that more testing will be required to determine if hundreds of other VPN apps are at risk.

These aren’t your run-of-the-mill VPN apps used by citizens to mask their private Internet surfing traffic. The services in question are enterprise solutions that are frequently deployed by corporate IT departments for people who need to work remotely, but also want access to their company’s private data, such as email and internal tools.

The apps appear to be incorrectly storing cookies on a person’s computer, according to the CERT bulletin. While the cookies are designed to help people bypass having to enter their password at every new login screen, they could be dangerous if the wrong person gains access.

A potential worst case scenario could be if a skilled hacker gained access to a person’s private computer through malware—they could then use the improperly stored cookies to log in to the enterprise VPNs, bypassing usual checkpoints where they might otherwise have to enter a password.

Palo Alto Networks has issued a patch for its GlobalProtect app, for both its Windows and Mac users, however the other companies named in the bulletin have not yet issued public responses. Hundreds of other apps could also be affected—but more testing will be required. A “generic configuration” may be the reason why the problem is being spread across companies, according to the bulletin.

Just two enterprise VPN vendors—Check Point Software Technologies and pfSense—were given an all clear in the CERT bulletin.

While it’s important to regularly check for security updates and patches, using two-factor authentication (2FA) as an extra layer of security can help companies ensure there’s no unauthorized access to their accounts, says Kathy Wang, director of security at Gitlab, an open source software development site. “A VPN is one means to an end, but not the only means,” she says.

Setting up 2FA can be as simple as adding an email address or phone number to an account. When you try to log in, the site would then send a unique, one-time code for users to enter, proving their identity.

About the Author
By Alyssa Newcomb
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Dan Rogers speaking on stage.
AIAsana
Asana was battered by the AI boom. Now it’s betting its future on humans and agents working together.
By Beatrice NolanMay 29, 2026
1 hour ago
Exclusive: Microsoft is building a super app that combines coding, chat, and other Copilot AI tools
AIMicrosoft
Exclusive: Microsoft is building a super app that combines coding, chat, and other Copilot AI tools
By Sebastian HerreraMay 29, 2026
3 hours ago
Claude Mythos shown on a smartphone screen.
AIAnthropic
Anthropic leapfrogs OpenAI with a record $965 billion valuation and says its ‘Mythos’ AI model is coming soon 
By Beatrice NolanMay 29, 2026
4 hours ago
Why Meta hired Dina Powell McCormick
NewslettersMPW Daily
Why Meta hired Dina Powell McCormick
By Ellie AustinMay 29, 2026
4 hours ago
The AI arms race in cybersecurity has started. Most companies aren’t ready
Cryptocyber
The AI arms race in cybersecurity has started. Most companies aren’t ready
By Philip MartinMay 29, 2026
5 hours ago
Kalshi adds perpetual futures for U.S. traders following thumbs-up from key regulator
CryptoBitcoin
Kalshi adds perpetual futures for U.S. traders following thumbs-up from key regulator
By Jack KubinecMay 29, 2026
5 hours ago

Most Popular

As CEO of the $96 billion Sam’s Club, Latriece Watkins is testing her mettle at the warehouse retailer that produced CEOs for Walmart, Target, and Walgreens
Magazine
As CEO of the $96 billion Sam’s Club, Latriece Watkins is testing her mettle at the warehouse retailer that produced CEOs for Walmart, Target, and Walgreens
By Emma HinchliffeMay 27, 2026
2 days ago
Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year
Success
Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year
By Preston ForeMay 21, 2026
8 days ago
The river that supplies 40 million Americans is down to 23% — and about to make a $25 million bet on one fish
Environment
The river that supplies 40 million Americans is down to 23% — and about to make a $25 million bet on one fish
By Dorany Pineda, Brittany Peterson and The Associated PressMay 27, 2026
2 days ago
As AI slashes white-collar jobs, Salesforce CEO Marc Benioff says almost no one is being hired—except in sales
Success
As AI slashes white-collar jobs, Salesforce CEO Marc Benioff says almost no one is being hired—except in sales
By Emma BurleighMay 28, 2026
1 day ago
Current price of oil as of May 28, 2026
Personal Finance
Current price of oil as of May 28, 2026
By Joseph HostetlerMay 28, 2026
1 day ago
Jamie Dimon said the American Dream was slipping away. JPMorgan just put $40 million on the table to fix it
Banking
Jamie Dimon said the American Dream was slipping away. JPMorgan just put $40 million on the table to fix it
By Nick LichtenbergMay 27, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.