Tag

VPN Best Practices

Covers proven strategies for configuring, managing, and optimizing VPN connections to protect data in transit. Topics include protocol selection, split tunneling risks, kill switch configuration, and maintaining strong authentication for secure remote access.

posts

VPN Best Practices

VPN Best Practices: What Actually Protects You in 2026

In early 2024, threat actors exploited critical vulnerabilities in Ivanti Connect Secure VPN appliances so aggressively that CISA issued an emergency directive ordering federal agencies to disconnect the devices entirely. Not patch them. Disconnect them. That moment should have been a wake-up call: having a VPN isn't enough.

Carl B. Johnson Apr 12, 2026 5 min read
VPN Best Practices

VPN Best Practices: 9 Rules That Actually Stop Breaches

In May 2024, Check Point disclosed that threat actors were actively exploiting a zero-day vulnerability in its VPN products — CVE-2024-24919 — to harvest Active Directory credentials and move laterally through enterprise networks. Attackers didn't need a sophisticated exploit chain. They needed one VPN gateway running a default configuration with

Carl B. Johnson May 25, 2025 7 min read
VPN Best Practices

VPN Best Practices: What Actually Protects You in 2023

In May 2023, Barracuda Networks disclosed that a zero-day vulnerability in its VPN appliances had been actively exploited since October 2022 — giving threat actors seven months of undetected access to customer networks. CISA issued an emergency directive. The patch wasn't enough; Barracuda told customers to physically replace compromised

Carl B. Johnson Nov 26, 2023 7 min read
VPN Best Practices

VPN Best Practices: What Actually Protects You in 2022

The Pulse Secure Breach Should Have Been Your Wake-Up Call In April 2021, CISA issued an emergency directive after threat actors exploited vulnerabilities in Pulse Connect Secure VPN appliances to compromise federal agencies and defense contractors. Attackers maintained persistent access for months before anyone noticed. The tool that was supposed

Carl B. Johnson Jan 06, 2022 7 min read
VPN Best Practices

VPN Best Practices: What Actually Protects You in 2026

In early 2024, Ivanti disclosed critical vulnerabilities in its Connect Secure VPN that were already being actively exploited by threat actors — including nation-state groups. CISA issued an emergency directive ordering federal agencies to disconnect affected devices within 48 hours. It was a brutal reminder: a VPN isn't a

Carl B. Johnson Nov 08, 2020 7 min read
VPN Best Practices

VPN Best Practices: What Actually Protects You in 2026

The Ivanti Breach Changed How I Think About VPNs In early 2024, CISA issued an emergency directive after threat actors exploited vulnerabilities in Ivanti Connect Secure VPN appliances to infiltrate multiple federal agencies. The attackers didn't brute-force passwords. They didn't trick users with phishing emails. They

Carl B. Johnson Sep 28, 2019 7 min read