With the increasing sophistication of cyber threats – and cyberattacks themselves becoming more ruthless and efficient – virtual private network (VPN) vulnerabilities are emerging as significant security risks that can compromise not just the security and integrity of sensitive data, but also the overall protection of the private networks where that data resides.
Among these challenges, zero-day vulnerabilities pose a significant risk, as they can expose businesses to critical cyberattacks.
A zero-day vulnerability is a security flaw in software that is unknown to the vendors. The term 'zero-day' indicates that the developers have had zero days to address and patch the vulnerability since it was first discovered.
This is exemplified by the recent exploitation of Ivanti Connect Secure and Policy Secure Gateways which impacted the businesses using their VPN service.
What happened in short
Ivanti disclosed two vulnerabilities at the beginning of January 2024, followed by two additional vulnerabilities disclosed on January 31, 2024. These affected all supported versions of the Ivanti Connect Secure and Ivanti Policy Secure Gateway products, enabling attackers to run commands on the system.
As stated by CISA (Cybersecurity & Infrastructure Security Agency of the U.S.A.), Ivanti’s vulnerabilities can be used in a “chain” of exploits, enabling hackers to bypass authentication, craft malicious requests, and execute arbitrary commands with elevated privileges.
VPNs play a crucial role in securing business networks, allowing remote workers to access corporate resources through an encrypted VPN tunnel. But because a virtual private network lives on the Internet, it also poses a significant security risk for companies, as its IP address can be found through scanning – creating major concerns for remote work security and VPN protection overall.
This blog explores the top three VPN security risks that put your business in jeopardy when a zero-day vulnerability is discovered, highlighting the importance of elevating private network security with Anapaya GATE and the SCION Internet to reduce cyberattack risks and enable more secure remote access.
Challenge 1: The massive attack surface of a virtual private network
The steep rise of hybrid workforces in recent years has resulted in most organizations using a VPN to enable access for remote workers. This shift has positioned enterprise VPN solutions as one of the most common avenues for malicious actors to secure initial access onto a target network. Why? Because VPNs – currently de facto – have a massive attack surface since they operate on the Internet and are subject to the vulnerabilities of the Internet protocol. In essence, a remote access solution built on VPN software is designed to securely extend your network to a remote endpoint, and in scenarios involving a remote workforce, it connects thousands or even tens of thousands of remote VPN clients through encrypted VPN connections across the Internet, a network that – as we are all well aware – has a massive attack surface. This puts the privacy and security of your data and network at risk, impacting the level of security of your business.
A survey led by Zscaler states that 88% of their survey’s respondents are concerned that their corporate VPN solution may expose their organization to heightened security vulnerabilities. Rightly so. In 2025-2026, all major VPN providers have been disclosing zero-day vulnerabilities, from Ivanti to Palo Alto Networks, Cisco and Fortinet, underscoring the urgent need for robust VPN security solutions.
What the Anapaya GATE solution does to help this scenario is hide your VPN server from the Internet, meaning it prevents intrusion attacks by reducing attack surface by up to 99% compared to the traditional Internet. In the Ivanti case, if your VPN had been on the SCION Internet after the zero-day vulnerability was discovered, the vast majority of cyber criminals wouldn’t have been able to see your specific VPN and thus attack it.
Challenge 2: Zero-day vulnerabilities leading to targeted attacks
We do not like to be the ones to put it out there, but YOU are a target. Because your VPN lives on the Internet, you are exposed to cybercrime from all over the world. These are bad actors who are constantly scanning your network to find holes and get in – often exploiting zero-day vulnerabilities found in widely used software just like in the Ivanti case.
Our team looked at tracking the number of attacks perpetrated against a Swiss financial institution in Switzerland for a quarter in 2023. During that time, they suffered 8M+ attacks with unspecified intent (scans) and 85K+ attacks with malicious intent on their VPN infrastructure.
The sheer size of scans makes it nearly impossible to monitor properly network traffic and prevent an intrusion attack from escalating into a malicious attack, or to block, mitigate, or circumvent one that is happening.
The same financial institution mentioned above tried out something new: they decided to put their VPN on the SCION Internet accessed via by their users via Anapaya GATE as well.
During the same quarter in 2023, they identified only 18K+ attacks with unspecified intent (scans) and 0 attacks with malicious intent. And by being in control of the attack surface, they could more easily monitor and detect scans, enabling them to react quicker to potential breaches.
Attacks with unspecified intent


Attacks with malicious intent


Challenge 3: Persistent threats once cybercriminals gain access
Once the hackers have gained access to your network via a hole in your system or in the software like in the Ivanti scenario, they are in – even if you figure it out and patch it. In the time it takes to fix such a flaw, hackers can exploit such VPN vulnerabilities to seize control of an organization’s network tools and use them to drill even deeper into that business’s IT environment. In other words, they can (and do) create the infamous backdoor – or even several of them. You don’t know when they will hit you with something else like malware, spyware or ransomware as some of the worst. Once inside, attackers can access sensitive information and compromise data in transit between remote users and critical applications, including launching man-in-the-middle attacks. For businesses everywhere, you do not want your data or money on the table.
Anapaya GATE minimizes the risk of such a breach happening by giving you fine-grained control over where your VPN infrastructure is accessible. Instead of being visible to everyone on the Internet, your VPN application is exposed only to remote users coming through the GATE infrastructure, adding another layer of security.
Enhance your business VPN security
In the case of Ivanti customers, businesses with their VPN services could have circumvented this exploited VPN vulnerability and enhanced network security if they had the VPN services on the SCION Internet and access to the VPN application on the SCION Internet and access to the it had been limited to Anapaya GATE remote users.
This would, of course, be of particular interest to businesses that have a hybrid workforce predominantly in one region or country, where the SCION Internet has been shown to reduce the attack surface by up to 99.99% compared to the traditional Internet.
Anapaya GATE is not a “once and for all protective measure” – but it is one of the simplest and most effective preventative measures against zero-day vulnerabilities (that have the potential to cripple your VPN and networks) that is available today.
Following best practices, executing regular security audits, adding encryption standards, is not enough. While strong encryption helps protect data, it cannot fully eliminate risks introduced by exposed infrastructure or compromised software.
With Anapaya GATE, you can make sure your business is not subjected to the painful loss of customer loyalty, trust or the financial losses that always accompany such zero-day exploits – whether we're talking about the lost time and resources spent fixing the issue or more serious repercussions like ransomware.
To learn how services exposed to the Internet are more vulnerable than when running on the SCION Internet, read the case study "SCION vs. the Internet."