Site navigation

VPN Security Fears Pushing Firms To ‘Zero Trust Everywhere’

Tom Quinn

,

VPN risks
“Attackers will increasingly leverage AI for automated reconnaissance, intelligent password spraying, and rapid exploit development, allowing them to compromise VPNs at scale,” said Deepen Desai, CSO at Zscaler.

VPNs are becoming a liability for corporate networks, as rising security and compliance risks leave over half of enterprises fearing their current solutions are outdated and ineffective against modern cyber threats, according to a new Zscaler ThreatLabz report.

The cybersecurity firm’s 2025 VPN Risk Report found that 56% of organisations now cite cybersecurity and regulatory compliance as the main challenge in using VPNs, while a similar number (54%) highlighted growing concerns that VPNs cannot meet the standards now needed for protection.   

Almost all of the more than 600 organisations surveyed (93%) said they fear backdoor vulnerabilities from third-party VPN connections, while 92% went further, saying that ransomware risks linked to VPN vulnerabilities are keeping them up at night.

Those fears are being fuelled by the increase in cyber-criminals leveraging AI to pinpoint vulnerabilities and using GPT models to run queries focused on identifying weaknesses in VPNs, with ThreatLabz claiming that tasks which once required weeks or even months can now be accomplished by crooks in just minutes.

ThreatLabz also found a stark 82% increase in the number of VPN Common Vulnerabilities and Exposures (CVEs) between 2020-2025, with roughly 60% of vulnerabilities having a high or critical CVSS score over the last year in particular – indicating a potentially serious risk to impacted organisations.

Vulnerabilities enabling remote code execution (RCE) were the most prevalent kind, a serious liability as they can allow attackers to execute arbitrary code on the system, leading ThreatLabz to warn that, far from being innocuous, the bulk of VPN CVEs are leaving their customers open to critical exploits. 


Recommended reading


These combined risks have culminated in a dramatic shift in thinking around enterprise VPNs, with 65% of organisations planning to replace their VPNs within the next year, and 81% intending to implement a ‘zero-trust everywhere’ strategy.

According to ThreatLabz, this approach can minimise attack surfaces, prevent the later movement of attackers, and enhance data security.

“Attackers will increasingly leverage AI for automated reconnaissance, intelligent password spraying, and rapid exploit development, allowing them to compromise VPNs at scale,” said Deepen Desai, CSO at Zscaler.

“To address these risks, organizations should shift to a zero-trust everywhere approach. This approach eliminates the need for internet-exposed assets like VPNs (physical and virtual), while drastically reducing the attack surface and potential impact of breaches.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data