Report Reveals Rising Ransomware Risks From VPN Vulnerabilities
The latest Coalition Cyber Threat Index Report found that 60% of cyber insurance claims stemming from ransomware attacks in 2024 involved the exploitation of perimeter security devices, namely virtual private networks (VPNs). The report compiled claims data spanning between Jan. 1, 2024, and Oct. 31, 2024. Over 40,000 VPN-related vulnerabilities were identified, representing a 38% increase from the previous year’s data. Looking ahead, the report projected that these vulnerabilities will only continue to rise, potentially reaching 45,000 by the end of 2025.
Although VPNs are intended to benefit businesses by providing secure gateways to internal networks and simplifying remote access capabilities for employees, they have to be launched correctly and updated on a regular basis to remain effective. Otherwise, they can end up becoming attack avenues for cybercriminals rather than protective barriers. With this in mind, it’s imperative for businesses to uphold the following VPN security measures:
Cybersecurity Exposures Stemming From QR Codes
Quick response (QR) codes are a series of pixels arranged to form a large square that contains a long string of data. They function similarly to a barcode. They can be scanned by code readers or smartphones and often contain URLs so individuals can access websites without having to type in a specific web address. Once scanned, QR codes allow a quick and convenient way for clients to access a business’s information or leave a review. They can also be used to prompt users to take certain actions, such as making a payment or downloading an app. Although they can be a useful tool, the nature of QR codes allows them to be exploited by cybercriminals. Since legitimate QR codes appear as a random scramble of pixels within a larger square, it can be difficult for users to differentiate between the safe and malicious ones. Additionally, QR codes may be standalone images, so they may not be accompanied by telltale signs of malicious activity, as is often the case with fraudulent emails (e.g., misspellings, suspicious links). Businesses encounter risks from QR codes in a couple of ways. For instance, they could be exposed to cybersecurity threats if employees scan malicious QR codes on company devices and end up compromising their login credentials, confidential business servers and data. Alternatively, if companies utilize QR codes for business purposes, their legitimate codes can be manipulated by cybercriminals, potentially impacting their customers and causing lasting reputational damage. As cybercriminals increase their use of QR codes, it’s essential for businesses to mitigate the risks associated with them. In particular, businesses should:
Phishing Attacks: Malicious QR codes may lead users to fraudulent websites designed to steal sensitive information.
Malware Distribution: Scanning a compromised QR code can direct users to sites that automatically download malware onto their device.
Redirection to Unsafe Content: Attackers may direct users to inappropriate, harmful, or unsafe websites.
Data Collection and Privacy Risks: Some QR codes track user data without explicit consent, posing privacy concerns.
✅ Trust but Verify: Always scan codes from trusted sources and double-check the URL you're directed to.
✅ Inspect URLs: After scanning, review the link carefully before clicking or providing any information.
✅ Use a Secure QR Scanner App: Use reputable scanner apps with built-in security features rather than generic ones.
✅ Keep Devices Updated: Regularly update software and antivirus protections on your mobile device.
Benefits of Cybersecurity Awareness Programs
Cybersecurity awareness programs provide informative training sessions on cyberthreats and cybersecurity best practices. These programs aim to educate employees and organizations about the importance of maintaining a secure online environment and the potential risks associated with cyberattacks. Implementing a comprehensive cybersecurity awareness program is one of the most important strategies for recognizing and preventing cyberattacks. Establishing such a program can create a stronger cybersecurity culture and provide employees with essential training to prevent breaches. These programs can offer several benefits to businesses, such as:
Contact us today for additional cybersecurity resources!
© 2025 Zywave, Inc. All rights reserved.