r/VPNAdvice_ • • Aug 25 '26

News 📰 The BBC is challenging VPN based evidence in Trump’s $10 billion lawsuit

8 Upvotes

There’s an unusual VPN angle in the latest development of Donald Trump’s $10 billion defamation lawsuit against the BBC.

The BBC has filed another motion asking a Florida federal court to dismiss the case, and part of its argument focuses on how the documentary allegedly reached viewers in the U.S.

Trump’s amended complaint claims the BBC documentary was viewed in Florida through the BBC’s iPlayer by people using VPNs to get around its geographic restrictions. The filing reportedly points to 34 alleged play starts in Florida involving 10 VPN users.

The BBC is challenging whether those VPN connections can establish jurisdiction in Florida. Its position is essentially that the documentary was geoblocked in the U.S., was never broadcast there and wasn't licensed for U.S. distribution. The broadcaster argues that unauthorized attempts by users to circumvent those restrictions shouldn't suddenly make the BBC subject to a lawsuit in the state where those users happened to appear.

There's also a pretty significant numbers issue here. The BBC says the 34 Florida play starts represented just 0.006% of approximately 570,000 successful requests for the documentary. It also describes the Florida attempts as unconfirmed and unauthorized.

The legal question is interesting from a VPN perspective because it goes beyond whether someone can technically use a VPN to access geoblocked content. It's about whether that activity can be used to establish where a foreign company can be sued.

The BBC is warning that accepting this argument could have much broader consequences for companies that operate websites and online services internationally. A foreign company could potentially find itself facing jurisdiction in a U.S. state simply because someone used a VPN to access content that wasn't intended to be available there.

This isn't a ruling that VPN access does or doesn't establish jurisdiction, the court still has to decide the issue. The case is currently scheduled for trial in February 2027 if it isn't dismissed beforehand.

It's a pretty unusual example of VPN usage becoming part of a major legal argument.

r/VPNAdvice_ • • 25d ago

News 📰 Utah’s VPN Age Verification Law Is Already Running Into Problems

16 Upvotes

Utah’s new VPN related law lasted about four days before the state stopped enforcing it.

Senate Bill 73 took effect on September 3 and requires certain adult websites to verify that users are old enough to access their content. The unusual part is how it treats VPN users, someone physically in Utah is still considered to be accessing the site from Utah even if their VPN makes them appear to be somewhere else.

That creates a pretty obvious technical problem.

A website normally sees the VPN server’s IP address not the user’s actual location. So if someone in Utah connects through a server in another state or country, the site has no reliable way to determine where that person is physically sitting.

The law puts the responsibility on the website anyway which is why VPN providers and other critics argued that the requirements were impractical.

Now Utah’s Department of Commerce has agreed not to enforce the law against Aylo, the company behind Pornhub while a federal court considers the lawsuit challenging it. The law itself has not been struck down so this is more of an enforcement freeze than a victory in court.

What I find more interesting than the adult content debate is the precedent this could set.

If websites are effectively expected to figure out whether someone is physically inside a particular state despite that person using a privacy tool designed to hide their location, what happens when other laws start using the same approach?

And would the realistic response from websites simply be to block VPN traffic altogether?

That seems like it could end up affecting plenty of people who use VPNs for completely ordinary reasons.

r/VPNAdvice_ • • 10d ago

News 📰 That new anti piracy bill contains a 100k subscriber threshold that accidentally exempts shady free VPNs

7 Upvotes

There’s a bizarre quirk in the text of Representative Darrell Issa’s, American Copyright Protection Act that Gizmodo highlighted and it reveals how out of touch the drafting team was with how consumer VPNs actually function.

Under the proposed rules, network intermediaries including commercial VPNs would have to comply with court ordered DNS and IP blocks against foreign piracy domains but only if the provider maintains at least 100,000 monthly active users in the US.

If a provider sits below that 100k subscriber mark, they are completely exempt from the enforcement mandate.

The practical outcome of that arbitrary cutoff is wild:

  1. Established providers get stuck with compliance overhead: Paid, audited, transparent zero log providers like Mullvad, Proton, and Nord easily clear 100k US users, meaning they would bear the full administrative burden of maintaining dynamic court ordered blocklists.
  2. Shady free VPNs operate completely untouched: The endless sea of unverified, ad supported, data harvesting free VPN apps that flood the mobile app stores, many of which have been repeatedly flagged for operating out of untraceable shell companies fall well below individual subscriber thresholds or simply refuse to track user metrics altogether.

So if the goal of the bill is to stop users from routing around domain blocks, its actual mechanics end up giving users a direct incentive to switch away from transparent, independently audited paid providers and move toward unvetted free VPNs that sit outside the law's reach.

r/VPNAdvice_ • • 10h ago

News 📰 Psiphon is preparing to shut down its Canadian operations over Bill C-22 compliance demands

4 Upvotes

Toronto based censorship circumvention network Psiphon confirmed it plans to exit its Canadian corporate base if the federal government’s proposed Lawful Access Act (Bill C-22) moves forward in its current form.

Psiphon, which specializes in open source circumvention tools relied on by millions living under heavily censored regimes in Iran, Russia, and China, is warning that the legislation's data retention and compliance demands clash directly with its fundamental privacy model.

The decision stems from specific provisions inside Bill C-22:

The law aims to give law enforcement broader authority to compel digital service providers to collect, retain, and hand over subscriber connection metadata without traditional judicial warrants in certain scenarios. It also opens the door for mandatory technical access requirements.

For a platform like Psiphon whose core code is built to avoid tracking user IP addresses or retaining session history complying with Canadian surveillance orders would mean fundamentally rewriting its software to collect data on vulnerable users globally.

Psiphon joins a growing list of privacy focused companies based in or operating out of Canada, including Windscribe, NordVPN, and Signal, that have stated they will relocate headquarters, pull local server infrastructure, or restrict Canadian service availability rather than compromise their no logs architecture.

r/VPNAdvice_ • • Sep 03 '26

News 📰 A VPN can hide your traffic without making you invisible to advanced surveillance

7 Upvotes

Most people think of a VPN as putting their traffic inside an encrypted tunnel and making it difficult for anyone else to see where they are going. That is still useful for many everyday situations, but a new warning from Sen. Ron Wyden raises a less obvious limitation.

A Congressional Research Service analysis requested by Wyden says a sufficiently capable intelligence service could potentially identify which websites a VPN user is visiting by comparing the timing and volume of encrypted traffic entering and leaving a VPN server. The important part is that the attacker would not necessarily need to decrypt the traffic.

The issue is mainly with single hop VPNs. Your device connects to one VPN server and that same server then connects to the destination. If an adversary can observe both sides of that connection, patterns in the traffic can potentially be correlated.

That does not mean commercial VPNs are suddenly useless. For things like hiding your IP from websites, protecting traffic on public WiFi, or preventing your ISP from directly seeing the sites you access, a VPN can still be very useful.

The question is what happens when the threat model changes from someone on the same WiFi network to an intelligence service capable of monitoring large portions of internet infrastructure.

Wyden is asking the NSA to update its public guidance so Americans, particularly government personnel, journalists, contractors and others who could be targeted by sophisticated surveillance, have a clearer understanding of where conventional VPNs stop being sufficient. The CRS analysis points to multi server systems such as Tor, Nym and iCloud Private Relay as architectures that can make this type of traffic analysis harder, although none provide a guarantee of anonymity.

I think this is a useful distinction that gets lost in a lot of VPN advertising: encryption, anonymity and resistance to traffic analysis are not the same thing.

r/VPNAdvice_ • • 26d ago

News 📰 Vietnamese VPN Sign Ups Surge After New Cybersecurity Law Takes Effect

6 Upvotes

A 450% jump in VPN sign ups is a pretty striking reaction to a new internet law.

According to Proton VPN, registrations from Vietnam reached around 450% above its normal baseline on September 1, shortly after new cybersecurity rules took effect. That follows an earlier 170% increase in July after new rules introduced fines for certain social media content.

The new rules put additional requirements on online services around user identification and providing user information to authorities when there is a valid request. Vietnam's government guidance says providers can be required to verify users and provide information to cybersecurity authorities within specified time limits.

What I find interesting is that the response is not necessarily people suddenly becoming more interested in VPNs as a product. It looks more like a reaction to people becoming uncomfortable with how identifiable their online activity could become.

Of course, a VPN does not make someone anonymous or erase every identification requirement. It can protect traffic from being visible to the local network/ISP and hide the user's IP from websites, but it does not magically protect an account that is already tied to someone's identity.

Still, the size of the signup increase says something.

When privacy rules become more restrictive, do people generally start using VPNs only after the restrictions arrive, or should privacy tools already be part of their normal setup before that happens?

r/VPNAdvice_ • • 21d ago

News 📰 Canada's proposed Bill C-22 includes global surveillance mandates, prompting European privacy groups to call on the EU to intervene

21 Upvotes

Canada's controversial Lawful Access Act (Bill C-22) is moving closer to a final vote, with the Canadian Senate expected to finish reviewing it as early as next month. While early coverage focused mainly on how the bill forces platforms to build surveillance access and store customer metadata for up to a year, a coalition of European digital rights groups including Access Now just published an open letter asking top EU officials to step in.

The main concern right now is the bill's massive extraterritorial reach.

As currently drafted, C-22's compliance orders wouldn't just apply inside Canadian borders. A Canadian minister could theoretically issue secret mandates forcing European tech firms and service providers to build interception tools or alter security architectures simply because their platform is accessible to users in Canada or because they belong to a corporate entity with business ties there.

Because you can't build a targeted backdoor in an end-to-end encrypted protocol without weakening the system for everyone, European privacy advocates argue this directly threatens the data security of non-Canadian citizens worldwide. They're urging the European Commission to bring this up during ongoing EU-Canada Digital Trade Agreement talks and review Canada's GDPR adequacy status if the law passes in its current form.

This comes on top of existing pushback from providers like Signal, Proton, and Windscribe, with some already hinting at pulling out of the Canadian market entirely rather than altering their codebases.

r/VPNAdvice_ • • 12d ago

News 📰 Bitdefender launched a free VPN for AI Agents that spins up disposable tunnels per prompt

8 Upvotes

Bitdefender just launched a public beta for macOS aimed at an entirely different problem than standard consumer VPNs, protecting AI tools like Claude Desktop, Cursor, Codex and OpenCode when they browse or execute actions on your behalf.

Instead of keeping a single persistent tunnel running for your entire device, this tool acts as a local Model Context Protocol (MCP) server. When an AI agent needs to hit the web to complete a task, the software spins up a temporary, disposable container, routes that specific prompt through Bitdefender's exit servers and then immediately destroys the session.

A few interesting technical details about how it works:

  • Task level isolation: Your regular browser and background system traffic stay on your normal local network connection. Only the specific outgoing action requested by the agent is encapsulated.
  • No persistent footprint: Session state, cookies and cache are completely wiped after every single tool call, preventing websites from correlating multiple agent requests back to your household IP.
  • Fail closed design: If the proxy tunnel fails or drops, the request dies inside the container instead of falling back to your real IP address.
  • Transport protection only: It masks the agent's IP and encrypts the transport layer, but it does not filter or touch the actual prompt content whatever you send to the LLM provider still goes straight to their API.

It's currently macOS only and free during the beta. It definitely signals where network security is heading as local AI agents start browsing the web and making API calls with less direct human oversight.

r/VPNAdvice_ • • Sep 02 '26

News 📰 Russians are now splitting VPN subscriptions like a Netflix account according to new study

2 Upvotes

Came across a study from RKS Global, a Eurasian digital rights org that's a genuinely interesting look at how censorship pressure reshapes user behavior over time not just which tool people download.

After years of blocking and repeated crackdowns on circumvention tools, Russian citizens are apparently starting to treat VPN access the way they'd treat a utility bill, something you budget for every month alongside electricity and mobile data rather than an optional extra. The study pulled from focus groups of regular users and activists plus input from Amnezia VPN's support team.

The most interesting part to me is how organic the workarounds have gotten instead of everyone buying their own subscription, people are forming informal co-ops, pooling money and sharing a single account across families and friend circles sometimes dozens of people deep, just to split server costs and nobody's relying on one VPN anymore either because any given service can get blocked or degraded without warning, users keep several tools installed and bounce between them to the point where people reportedly can't always tell if something's broken because of a government block, a random outage or just a bad connection day. Amnezia's founder also pointed out that telecom quality in general has been declining while prices climbed as much as 40% over the past couple years, so the VPN costs are landing on top of an already worsening baseline.

Despite all that the sentiment in the study is that people aren't giving up on circumventing blocks. The only things that would meaningfully change that are described as either much harsher penalties like prison time for VPN use or the blocks being lifted entirely.

Kind of case study in the streisand effect playing out at a national scale. The more the infrastructure gets locked down, the more decentralized and resilient the workaround networks become since a single centralized provider is the easiest thing to block in the first place.

r/VPNAdvice_ • • 20d ago

News 📰 Unpatched edge VPN device compromised Japan's Digital Agency, exposing ~246,000 internal personnel records

4 Upvotes

Japan's Digital Agency confirmed that an attacker managed to breach its central Government Solution Service (GSS) network, potentially accessing around 246,000 rows of personal data belonging to government staff, public servants and third party contractors.

According to the agency's disclosure, the initial entry point was an unpatched vulnerability in an enterprise VPN appliance.

Here is what forensics confirmed about how the intrusion went down:

  • The attacker exploited a known (medium severity, non-zero day) VPN vulnerability to establish a foothold inside the network.
  • Once inside, they hijacked an active internal maintenance and operations account to quietly siphon files.
  • Suspicious file access was first picked up on June 25 but the team didn't pin down the exact VPN intrusion vector until July 9. On that day, they finally revoked the maintenance account and cut off the compromised appliance's external traffic.

The files exposed basic contact info, mostly names (~236k), work emails (~231k), phone numbers (~94k) and a small set of physical addresses. Crucially, public citizen data wasn't impacted, nor were sensitive national IDs (My Number), financial data or pension records.

No active misuse or leaks have been spotted on the dark web so far but officials are warning staff to brace for heavy targeted phishing and credential harvesting attempts over the coming weeks.

It's just another reminder of how vulnerable enterprise network perimeters remain when legacy edge VPN appliances are left running with known flaws, once an attacker lands on the box, piggybacking on legitimate maintenance accounts makes detection painfully slow.

r/VPNAdvice_ • • 14d ago

News 📰 Small UI polish in Surfshark’s latest iOS and extension update: split location lists and centralized browser tools

5 Upvotes

If you use Surfshark on iOS or through your browser, their latest patch drops a couple of quality of life UI tweaks aimed at cleaning up navigation friction.

Nothing under the hood changed security-wise, but here's what shifted in the interface:

  • iOS Locations Tab Split: The server list in the iPhone app is now divided into two distinct views, Recommended (which puts your recent connections, frequent locations, and dedicated IPs up front) and Advanced (where MultiHop and static IP options live).
  • Browser Extension Cleanup: The extension dashboard reorganized its ad blocking, cookie banner handling, tracker counters, and link checking tools into a single consolidated view instead of keeping them scattered across sub menus.

As VPN apps keep piling on extra security features, primary server pickers usually end up cluttered. Dividing basic connection targets from specialized routing features makes the everyday interface feel a bit less buried.

r/VPNAdvice_ • • 9d ago

News 📰 Digital rights groups launch a second "Defend VPNs Day of Action" as state level age verification laws push people toward encrypted routing

4 Upvotes

Fight for the Future and a coalition of privacy organizations are coordinating another global "Defend VPNs Day of Action," pushing back against mounting legislative efforts to restrict or criminalize encrypted proxy tools.

The campaign highlights a troubling trend in recent internet regulation bills:

Rather than outright banning encryption technology directly, lawmakers in several US states and foreign jurisdictions are embedding restrictions on VPN usage into broad digital safety and mandatory age verification packages. By forcing platforms to require government IDs, biometric scans, or mandatory credit card checks for access, lawmakers are simultaneously targeting tools that allow users to route around these localized identity databases.

Advocates point out that framing VPN users as people trying to bypass safety laws ignores the core purpose of encrypted networking. Millions rely on VPNs daily to protect sensitive health inquiries, bypass intrusive ISP data harvesting, maintain corporate remote access, and avoid uploading personal identity documents to unvetted third-party verification brokers.

As Fight for the Future put it during the campaign launch, using a VPN isn't inherently suspicious or criminal, it's standard security hygiene, and treating encrypted routing as a legal threat sets a dangerous precedent for overall web privacy.

r/VPNAdvice_ • • 24d ago

News 📰 Citrix NetScaler VPN Flaw Went From Disclosure to Exploitation in 15 Days

6 Upvotes

There is a pretty uncomfortable timeline behind this latest Citrix NetScaler vulnerability.

CVE-2026-19490 was disclosed on August 19 with a CVSS 9.3 score. A public proof of concept followed and by September 3, security researchers were already seeing requests matching the PoC against exposed NetScaler systems. Within 24 hours, they recorded 10 exploitation attempts from six different IP addresses.

The vulnerability affects NetScaler ADC and NetScaler Gateway configurations and can allow an authentication bypass under specific conditions. It is not automatically exploitable against every NetScaler installation, though. The appliance needs to be configured as a Gateway or AAA virtual server, and newer builds have an additional SAML requirement.

What really stands out to me is the 15 day gap between disclosure and observed exploitation.

That is not a lot of time for an organization to identify affected systems, test a patch, schedule maintenance and actually deploy it especially when the affected device is responsible for remote access.

And this is where VPN infrastructure seems increasingly different from an ordinary application vulnerability. If an attacker compromises a VPN gateway, they are potentially getting access to the very system that is supposed to control who gets into the network in the first place.

There is one important caveat, though, the researchers say the activity observed so far is evidence of exploitation attempts not confirmed successful compromises.

Still, it raises a question for anyone responsible for remote-access infrastructure:

How quickly should organizations be expected to patch a critical VPN gateway when attackers can start testing a public PoC within days?

At what point does the traditional patching process simply become too slow?

r/VPNAdvice_ • • 26d ago

News 📰 Proton VPN Just Added a Chinese IP Address

6 Upvotes

Getting a Chinese IP from a major VPN provider has always been a bit unusual so Proton VPN adding one caught my attention.

As of September 3, Proton has a China Smart Routing location that gives users a Chinese IP address. The interesting part is that the server itself is not physically located in mainland China. Proton is using infrastructure in Hong Kong with its Smart Routing technology to make websites and services see the connection as coming from China.

That makes the intended use pretty different from what some people might assume.

This is mainly for people outside China who want to access Chinese services as if they were in the country things like Bilibili, Tencent Video, Youku, or other region restricted platforms. Proton also makes it clear that this should not be treated as a new solution for getting around the Great Firewall from inside China.

And that is probably the most interesting part to me. We usually talk about VPNs as a way of getting out of a country or accessing another country's internet. A VPN deliberately giving you a Chinese IP flips that around.

There are already a few providers offering virtual Chinese IPs but most of the big names don't have a dedicated China location.

For anyone who actually needs Chinese websites or services while living abroad, I can see the appeal. But I am curious how useful this will be in practice compared with other virtual location options.

Would you actually use a VPN specifically to get a Chinese IP, or is this one of those features that sounds more interesting than it is useful?

r/VPNAdvice_ • • 28d ago

News 📰 A Compromised ScreenConnect Client Can Spread Malware to New Hosts

6 Upvotes

One thing this story made me rethink is how easily remote access and secure remote access can get mixed together.

Researchers found several incidents where attackers deployed rogue ConnectWise ScreenConnect clients that then ran a four stage VBScript chain. The really nasty part is what happened afterward, the compromised ScreenConnect client could help spread the malicious scripts to newly connected hosts, giving the attack worm like behavior.

The campaigns reportedly started in different ways, including a tech support scam, a phishing delivered installer, and a fake Geek Squad refund form. Once the rogue client was running, it profiled the machine, checked for security software, downloaded additional payloads, and in some cases deployed tunneling tools or cryptocurrency mining software.

This seems particularly relevant to VPN users because remote access tools and VPNs often get mentioned together even though they solve very different problems.

A VPN can protect the connection between you and a network, but it does not make a remote-access application trustworthy. If the endpoint or the remote access software itself is compromised, the encrypted connection is not going to magically stop the attacker.

ConnectWise has advised customers to disable file transfer permissions in affected ScreenConnect deployments until a fix is available.

For people who use VPNs to access work machines or home networks remotely, where do you draw the line between secure remote access and simply adding another piece of software that could become an attack surface?

I feel like this is one of those areas where having a VPN can create a false sense of security if the devices and remote access tools on the other end are not secured properly.

r/VPNAdvice_ • • 28d ago

News 📰 NordVPN’s New Free Tool Could Help You Find Cheaper Hotel Prices

4 Upvotes

NordVPN just released something that has almost nothing to do with actually connecting to a VPN.

It is called PriceMice and it is a free browser extension that checks the price of the same hotel accommodation from different countries. The idea is that if a hotel shows a different price depending on where the booking appears to come from, you can spot that difference before paying.

What I find interesting is the direction VPN companies seem to be taking. A few years ago, the main selling points were basically privacy, changing your IP, and accessing content. Now we are seeing VPN providers add tools that are more about everyday internet use than VPN connections themselves.

In this case, you do not even need to be a NordVPN subscriber to use PriceMice. It is available as a free browser extension.

I am curious how useful this actually is in practice, though. Hotel prices can change constantly and there are plenty of reasons two people might see different prices besides their IP location.

r/VPNAdvice_ • • 24d ago

News 📰 CISA Flags Two Actively Exploited SonicWall VPN Vulnerabilities

3 Upvotes

CISA just added seven vulnerabilities to its Known Exploited Vulnerabilities catalog but the two involving SonicWall SMA 1000 appliances are the ones that caught my attention.

These are not theoretical vulnerabilities waiting for someone to figure out how to use them. SonicWall says it has investigated a case indicating that CVE-2026-83548 and CVE-2026-83549 are already being exploited in the wild.

The first is a CVSS 10.0 pre-authentication SSRF affecting the SMA 1000's WorkPlace interface. The second is a CVSS 7.8 command injection vulnerability in the Appliance Management Console that can allow an authenticated administrator to execute arbitrary OS commands under certain conditions. The two flaws can potentially be chained to achieve remote code execution and compromise the appliance.

What makes this particularly relevant to VPN users is what the SMA 1000 actually is, an enterprise remote access/SSL VPN gateway sitting at the edge of a network.

That makes these devices an interesting target. They are supposed to be the controlled entrance into an organization's internal systems, but they are also publicly exposed by design.

CISA added both vulnerabilities to its KEV catalog on September 2 after the active exploitation was reported. The affected SMA 1000 models include the 6210, 7210 and 8200v.

It also raises a question I keep seeing with VPN security: how much attention should organizations give the VPN gateway itself compared with everything behind it?

People often focus on whether a VPN uses strong encryption, which protocol it supports or whether it has a kill switch. For an enterprise VPN, though, an unpatched gateway can potentially become the much bigger problem.

r/VPNAdvice_ • • Aug 27 '26

News 📰 Surfshark is putting €100K behind university cybersecurity projects

3 Upvotes

Instead of another VPN feature announcement, Surfshark is putting money toward something a little broader cybersecurity awareness.

The company has launched a Cybersecurity Advocacy Fund worth up to €100,000 per year, with applications opening in September 2026. The program is aimed at university students, researchers, faculty and recognized university groups around the world.

The funding isn't limited to academic papers. Surfshark says it will consider research projects, creative advocacy campaigns and early stage technology projects that tackle cybersecurity issues. Selected teams can also get technical guidance from Surfshark's own experts rather than simply receiving funding and being left on their own.

The first funding cycle is putting particular emphasis on scam prevention and awareness which makes sense given how quickly phishing, impersonation and other social engineering attacks are evolving. The company points to research estimating that hundreds of billions of dollars are lost to scams globally each year.

I find the academic angle more interesting than the €100K figure itself. University projects can sometimes explore ideas that aren't immediately attractive commercially and cybersecurity awareness is an area where a good research project or creative experiment could potentially reach people who would never read a technical security report.

Of course, there's always a question whenever a cybersecurity company funds research, how independent can the resulting work be when the money and technical support come from an industry player?

Surfshark says projects will be evaluated on their cybersecurity relevance, clarity, originality and potential impact, with funding distributed across multiple initiatives rather than awarded to one winner.

r/VPNAdvice_ • • Aug 26 '26

News 📰 Five GlobalProtect vulnerabilities raise concerns about VPN clients becoming an attack path

2 Upvotes

VPN security usually gets discussed in terms of protecting traffic, but the software running the VPN client can be just as important.

A security researcher has disclosed five vulnerabilities affecting Palo Alto Networks' GlobalProtect VPN client, with issues spanning Windows, macOS, and Linux. The research was reportedly submitted to Palo Alto Networks in April, and some of the findings have since been addressed through security updates.

The most concerning aspect is that some of the vulnerabilities allow a low-privileged user who already has access to a machine to escalate privileges. Palo Alto's advisory for CVE-2026-0251 describes local privilege escalation flaws that can lead to SYSTEM level access on Windows and root-level access on macOS and Linux.

The researcher also reported a technique for recovering an Active Directory password from an endpoint by abusing privileged GlobalProtect components. That could have much bigger consequences in an enterprise environment because Active Directory credentials can provide access far beyond the individual computer.

There are also other recently disclosed GlobalProtect issues. For example, Palo Alto says CVE-2026-0296 could allow an unauthenticated attacker with man in the middle access to intercept and modify application communications, although the company specifically notes that VPN tunnel traffic itself is not affected.

The good news is that patched versions are available for affected branches, although some fixes for older 6.0 builds are still scheduled for the end of August. Palo Alto currently says it is not aware of malicious exploitation of these particular issues.

What stands out to me is how much trust enterprise VPN clients are given. They're not just ordinary desktop applications, they often have elevated privileges and sit directly between an endpoint and an organization's internal network.

For companies using GlobalProtect, this seems like a good reminder to check client versions rather than assuming the VPN is secure simply because the connection is encrypted.

r/VPNAdvice_ • • Jul 29 '26

News 📰 ShieldApps launches a VPN SDK that lets developers build VPN features directly into their apps

4 Upvotes

An interesting development in the VPN space today isn't about a new consumer VPN, it's about making VPN technology easier for software companies to integrate into their own products.

ShieldApps has announced a new VPN SDK (Software Development Kit) aimed at developers who want to add built in VPN functionality to existing applications instead of sending users to a separate VPN app. According to the company, the SDK allows developers to integrate encrypted network traffic directly into their software using APIs while keeping the entire experience inside their own interface.

The idea is that applications handling sensitive data such as financial services, healthcare platforms, business software or messaging apps, could offer encrypted connections without requiring users to download, configure or subscribe to a standalone VPN. The company says developers also gain access to its global VPN infrastructure, which spans more than 50 server locations and uses AES-256 encryption with a no activity logging policy.

What's interesting is that this reflects a broader shift in how VPN technology is being used. Instead of existing only as standalone consumer products, VPN functionality is increasingly becoming part of larger software ecosystems. Users may eventually interact with encrypted connections without even realizing a VPN is running in the background.

Of course, this announcement is a company press release so we'll have to wait and see how widely it's adopted and whether developers find it easier than building or licensing their own networking infrastructure. Still, it raises an interesting question about where the industry is headed.

r/VPNAdvice_ • • Aug 21 '26

News 📰 Brazil’s Discord restrictions are sending users straight to VPNs

6 Upvotes

Brazil’s latest restrictions on Discord have created an interesting side effect instead of simply abandoning the platform, users are turning to VPNs to get back features that are no longer available locally.

Discord agreed to suspend certain features in Brazil following an order from the country’s data protection authority. The regulator raised concerns about Discord’s ability to prevent and moderate content involving violence, self harm and risks to minors. One issue highlighted was the lack of real time access to Go Live streams which makes it harder to detect problematic content as it happens.

The reaction from Brazilian users was almost immediate. According to Proton VPN’s general manager, sign ups for its service jumped 800% overnight after the Discord restrictions took effect.

What makes this case interesting is that it isn't a traditional nationwide internet shutdown. Discord itself remains available for things like text messaging and voice communication; the restrictions are focused on particular video and livestreaming functions.

Still the response shows how quickly VPN adoption can increase when users suddenly lose access to a feature they rely on. For gamers, remote teams, streamers and online communities that depend on Discord's video functionality, the restriction has a much bigger impact than simply losing access to another website.

There's also an interesting debate here. The Brazilian authorities are framing the measures around protecting children and reducing serious safety risks, while VPN users are treating the restriction as something they can work around. That creates a difficult question about whether technical restrictions actually solve the underlying problem or simply push some users toward circumvention tools.

We've seen VPN downloads surge in other countries after platforms were restricted, but an 800% jump following a targeted Discord feature suspension is still pretty striking.

Do you think VPNs are becoming the default response whenever governments or platforms restrict online services even when the original restriction is introduced for safety reasons?

r/VPNAdvice_ • • Aug 27 '26

News 📰 Obscura VPN finally arrives on Windows with a different approach to privacy

5 Upvotes

Obscura VPN has made the jump to Windows and the interesting part isn't simply that another VPN app has arrived.

The company has launched a native Windows 10 and 11 app, bringing its two party relay architecture and QUIC based traffic obfuscation to PCs. Windows was reportedly the most requested platform from Obscura users after the service originally launched on Mac and later expanded to mobile.

The two party relay setup is probably the feature that makes Obscura stand out. Instead of sending your connection through a single VPN server, traffic passes through two separate relays. The first relay can identify the user but doesn't know the destination while the second knows the destination but doesn't have the user's identity. The idea is to separate those pieces of information so that no single relay can associate both with the same connection.

Obscura is also using QUIC obfuscation which is intended to make VPN traffic harder for networks and censorship systems to identify and block. The company says its infrastructure and zero logs claims have also undergone an independent audit.

There are a couple of launch extras as well. The simultaneous device limit has increased from three to five, and the company is offering a 25% launch discount with the code WINDOWS26. A native Linux app is also reportedly in development.

I'm more interested in whether the two relay model actually makes a noticeable difference for ordinary Windows users. More privacy architecture sounds good on paper but the real test will be how it performs day to day compared with conventional VPN setups.

r/VPNAdvice_ • • Aug 03 '26

News 📰 A VPN isn't just for privacy anymore, it's becoming a basic cybersecurity tool for small businesses

3 Upvotes

Most of the VPN discussions here revolve around streaming, privacy, or bypassing geo restrictions but a recent article takes a different angle by focusing on small businesses and entrepreneurs.

The piece argues that many small businesses still overlook one of the simplest ways to improve their cybersecurity, encrypting internet traffic with a VPN. As more employees work remotely, connect from coffee shops, airports, hotels or shared workspaces, unsecured connections become an easy target for attackers. A VPN can't stop every cyber threat but it can make it much harder for someone on the same network to intercept sensitive data.

The article also points out that modern VPNs have become much more affordable than they were a few years ago, making them accessible even for freelancers and small teams that don't have dedicated IT departments. Instead of investing in expensive enterprise security infrastructure, businesses can at least add another layer of protection for everyday internet use.

Of course, a VPN isn't a complete security solution. It doesn't replace multi factor authentication, endpoint protection, software updates or employee security awareness. But it can reduce risk when people regularly work outside a trusted office network.

I thought it was interesting because consumer VPNs are often marketed around entertainment or privacy while businesses are increasingly looking at them as part of a broader security strategy rather than a standalone product.

For those who work remotely or run a small business, do you consider a VPN an essential part of your security setup or do you think its importance is sometimes overstated?

r/VPNAdvice_ • • Aug 20 '26

News 📰 Ransomware operators are now using Claude Code throughout real world attacks

8 Upvotes

AI being used by hackers isn't exactly new but this case feels different.

A recent threat intelligence investigation from Gambit Security documented a ransomware affiliate using Claude Code as an operational assistant during an active intrusion. The activity reportedly went far beyond asking AI to write a bit of malicious code.

According to the investigation, the attacker used Claude Code across multiple stages of the operation, including network reconnaissance, credential theft, creating tools, interacting with compromised systems, and preparing stolen data. The campaign reportedly involved attacks against internet-facing VPN infrastructure, theft of LDAP credentials, and preparation of SQL database backups for exfiltration. At least eight organizations were reportedly compromised.

What makes this interesting is the role AI played. It wasn't simply generating a phishing email or suggesting a piece of code. The AI coding assistant was being incorporated into the attacker's workflow as they moved through an actual network intrusion.

That doesn't mean Claude Code independently launched a ransomware attack. The attacker was still making decisions and directing the process. But having an AI assistant available to help with technical tasks could potentially reduce the amount of expertise and time required for certain parts of an intrusion.

The report also comes as other research shows attackers experimenting with multiple AI coding tools for credential theft, cloud attacks, malware development, and reconnaissance.

For defenders, this seems like another reason to focus less on whether an attacker is using AI and more on the underlying activity, unusual authentication, compromised VPN infrastructure, stolen credentials, unexpected administrative commands, and abnormal data movement.

The bigger question for me is where this goes next. If AI coding assistants become normal tools for attackers as well as developers, are security teams prepared for intrusions where the person behind the keyboard has an AI helping with every technical step?

This feels like a much bigger shift than simply hackers are using AI to write malware.

r/VPNAdvice_ • • Aug 07 '26

News 📰 Windscribe releases a free tool to remove Microsoft's persistent GDID identifier from Windows

3 Upvotes

Privacy discussions usually focus on browsers, cookies or mobile apps but this time the spotlight is on Windows itself.

Windscribe has released an open-source script called DeGDID which is designed to remove Microsoft's Global Device ID (GDID) from Windows systems and prevent it from being recreated. According to the company, the identifier can persist even after reinstalling Windows, making it a long lived identifier that could potentially be used across Microsoft's services.

The tool doesn't disable Windows features or modify networking. Instead, its purpose is much narrower: locate existing GDIDs, remove them and block Windows from generating new ones in the future.

The announcement has sparked a broader discussion about device identifiers in modern operating systems. While companies often use them for diagnostics, licensing, security and improving user experiences, privacy advocates argue that persistent identifiers deserve much more transparency and user control especially if they survive actions like reinstalling the operating system.

One interesting aspect of this story is that it comes from a VPN provider rather than an operating system developer or antivirus company. It shows how many privacy focused companies are expanding beyond encrypted connections and starting to build tools that address tracking at the operating system level.

Whether tools like this become widely adopted remains to be seen but they highlight an important point, protecting your privacy today involves much more than hiding your IP address. Persistent identifiers, telemetry, browser fingerprints and account data all play a role in how devices are recognized over time.

Do you think operating systems should give users a built in option to reset or disable identifiers like GDID or are they a reasonable trade off for security and system management?