Check Point releases emergency fix after hackers target VPNs
The Hindu
Check Point issues emergency fix for zero-day vulnerability targeting Remote Access VPN devices, shares protection recommendations for admins.
Check Point released an emergency fix for a zero-day vulnerability being exploited to target its Remote Access VPN devices.
Remote Access VPNs are integrated into all Check Point networks via VPN clients and were targeted to try to breach corporate networks.
The company on Monday issued a warning about a spike in attacks targeting VPN devices, sharing recommendations on how admins can protect their devices. Later the problem was found to be a zero-day flaw that was being exploited by hackers.
At the time the company said it had witnessed multiple attempts that when analysed were found to have the same pattern.
(For top technology news of the day, subscribe to our tech newsletter Today’s Cache)
“The vulnerability potentially allows an attacker to read certain information on Internet-connected Gateways with remote access VPN or mobile access enabled”, the company said in a blog post.
The company created an FAQ page with additional information about the vulnerability and created a remote access validation script that can be used to review results and take appropriate actions.
“Writing, in general, is a very solitary process,” says Yauvanika Chopra, Associate Director at The New India Foundation (NIF), which, earlier this year, announced the 12th edition of its NIF Book Fellowships for research and scholarship about Indian history after Independence. While authors, in general, are built for it, it can still get very lonely, says Chopra, pointing out that the fellowship’s community support is as valuable as the monetary benefits it offers. “There is a solid community of NIF fellows, trustees, language experts, jury members, all of whom are incredibly competent,” she says. “They really help make authors feel supported from manuscript to publication, so you never feel like you’re struggling through isolation.”
Several principals of government and private schools in Delhi on Tuesday said the Directorate of Education (DoE) circular from a day earlier, directing schools to conduct classes in ‘hybrid’ mode, had caused confusion regarding day-to-day operations as they did not know how many students would return to school from Wednesday and how would teachers instruct in two modes — online and in person — at once. The DoE circular on Monday had also stated that the option to “exercise online mode of education, wherever available, shall vest with the students and their guardians”. Several schoolteachers also expressed confusion regarding the DoE order. A government schoolteacher said he was unsure of how to cope with the resumption of physical classes, given that the order directing government offices to ensure that 50% of the employees work from home is still in place. On Monday, the Commission for Air Quality Management in the National Capital Region and Adjoining Areas (CAQM) had, on the orders of the Supreme Court, directed schools in Delhi-NCR to shift classes to the hybrid mode, following which the DoE had issued the circular. The court had urged the Centre’s pollution watchdog to consider restarting physical classes due to many students missing out on the mid-day meals and lacking the necessary means to attend classes online. The CAQM had, on November 20, asked schools in Delhi-NCR to shift to the online mode of teaching.