• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechCybersecurity

Homeland Security Says Hackers Could Crack Some Enterprise VPN Apps. Is Your Company at Risk?

By
Alyssa Newcomb
Alyssa Newcomb
Down Arrow Button Icon
By
Alyssa Newcomb
Alyssa Newcomb
Down Arrow Button Icon
April 12, 2019, 5:06 PM ET

VPN apps are supposed to help remote workers securely log onto their company’s servers, but critical vulnerabilities in apps made by at least four companies could be leaving the digital door wide open for hackers to steal corporate secrets.

The nonprofit CERT Coordination Center—which acts as the Internet’s emergency response team—and the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency issued an alert for enterprise VPN apps made by Cisco, Palo Alto Networks, Pulse Secure, and F5 Networks on Friday. The bulletin also warned that more testing will be required to determine if hundreds of other VPN apps are at risk.

These aren’t your run-of-the-mill VPN apps used by citizens to mask their private Internet surfing traffic. The services in question are enterprise solutions that are frequently deployed by corporate IT departments for people who need to work remotely, but also want access to their company’s private data, such as email and internal tools.

The apps appear to be incorrectly storing cookies on a person’s computer, according to the CERT bulletin. While the cookies are designed to help people bypass having to enter their password at every new login screen, they could be dangerous if the wrong person gains access.

A potential worst case scenario could be if a skilled hacker gained access to a person’s private computer through malware—they could then use the improperly stored cookies to log in to the enterprise VPNs, bypassing usual checkpoints where they might otherwise have to enter a password.

Palo Alto Networks has issued a patch for its GlobalProtect app, for both its Windows and Mac users, however the other companies named in the bulletin have not yet issued public responses. Hundreds of other apps could also be affected—but more testing will be required. A “generic configuration” may be the reason why the problem is being spread across companies, according to the bulletin.

Just two enterprise VPN vendors—Check Point Software Technologies and pfSense—were given an all clear in the CERT bulletin.

While it’s important to regularly check for security updates and patches, using two-factor authentication (2FA) as an extra layer of security can help companies ensure there’s no unauthorized access to their accounts, says Kathy Wang, director of security at Gitlab, an open source software development site. “A VPN is one means to an end, but not the only means,” she says.

Setting up 2FA can be as simple as adding an email address or phone number to an account. When you try to log in, the site would then send a unique, one-time code for users to enter, proving their identity.

About the Author
By Alyssa Newcomb
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

lancaster
AIschools
Two private school boys get probation for using AI to create 350 fake nudes of their classmates
By Mark Scolforo and The Associated PressMarch 25, 2026
7 hours ago
melania
PoliticsWhite House
Enter Melania Trump, escorted by humanoid robot: ‘I’m Figure 03, a humanoid built for the United States of America’
By Darlene Superville and The Associated PressMarch 25, 2026
7 hours ago
bernie
AICongress
Bernie Sanders and AOC launch bill to ban new data-center construction
By Matthew Daly and The Associated PressMarch 25, 2026
8 hours ago
Big TechSocial Media
A court just ruled that tech addiction is real—and dangerous. It could be Meta and YouTube’s Big Tobacco moment
By Kristin StollerMarch 25, 2026
8 hours ago
Warner gestures
AIAmerican Politics
New college grad unemployment will spike to 35% in 2 years, senator warns, forcing ‘Dario, Sam’ to quit AI fear-mongering
By Jacqueline MunisMarch 25, 2026
10 hours ago
Big TechMeta
Meta and YouTube found liable in landmark child social media harm case, ordered to pay $3 million—with punitive damages still to come
By Kaitlyn Huamani, Barbara Ortutay and The Associated PressMarch 25, 2026
10 hours ago

Most Popular

Magazine
The youngest-ever female CEO of a Fortune 500 company is fighting Trump's cuts to keep Medicaid strong
By Fortune EditorsMarch 24, 2026
2 days ago
Commentary
The Treasury just declared the U.S. insolvent. The media missed it
By Fortune EditorsMarch 23, 2026
3 days ago
Success
Palantir’s billionaire CEO says only two kinds of people will succeed in the AI era: trade workers — ‘or you’re neurodivergent’
By Fortune EditorsMarch 24, 2026
2 days ago
Success
JPMorgan’s Jamie Dimon says remote work breeds ‘rope-a-dope politics’ and stunts young workers’ growth
By Fortune EditorsMarch 25, 2026
13 hours ago
Success
The job market is so bad that ‘reverse recruiters’ are charging $1,500 a month just to help people look for jobs
By Fortune EditorsMarch 25, 2026
21 hours ago
Success
JPMorgan has started monitoring the keystrokes, video calls, and meetings of its junior investment bankers—and they say it's for employee well-being
By Fortune EditorsMarch 24, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.