Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Data Breaches & Incidents
  5. Surfshark VPN says hackers breached internal testing, proxy servers

Surfshark VPN says hackers breached internal testing, proxy servers

Scheduled Pinned Locked Moved Data Breaches & Incidents
1 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Surfshark has disclosed that hackers gained access to one of its internal test servers after a configuration error left the system exposed to the internet. The VPN provider says the incident was limited to internal testing and proxy servers, not its core VPN infrastructure or customer data.

    According to the company, the misconfigured server was reachable from the public internet due to an error in its setup. Once inside, the attackers moved to a proxy server. Surfshark has not released specific details about how long the access lasted or exactly what data, if any, was viewed.

    Key points from the disclosure:

    • A configuration error exposed an internal test server to the internet.
    • Attackers accessed that test server and a proxy server.
    • The breach did not affect the core VPN service or customer accounts, per Surfshark.
    • No specific CVE ID or advisory number has been provided in the report.

    Users and administrators should watch for any follow-up guidance from Surfshark, especially if they operate their own proxy or test infrastructure that might be similarly exposed. As always, keep internal testing environments off the public internet unless absolutely necessary, and audit configurations regularly.

    Source: Unknown

    Has your organization reviewed whether any internal test or proxy servers are inadvertently exposed to the internet?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World