Windows VPN services could face serious security worries soon

A laptop screen displaying a VPN logo
(Image credit: Shutterstock)

Popular exploit broker platform Zerodium has tweeted its desire to acquire zero-day exploits that capitalize on vulnerabilities in three widely-used virtual private network (VPN) service providers.

By its own admission Zerodium is currently interested in bugs that affect Windows clients for NordVPN, ExpressVPN, and SurfShark VPN services. 

Reporting on the development, BleepingComputer says that the three companies manage more than 11000 servers spread over tens of countries, and collectively serve at least 17 millions users around the world.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

Zerodium is an above-board platform whose customer base is composed of government institutions, primarily from Europe and North America, that are willing to shell huge amounts of money to get their hands on advanced zero-day exploits and cybersecurity research.

What’s cooking?

In its tweet, the popular premium vulnerability broker said it was looking for vulnerabilities that can be used to develop “information disclosure, IP address leak, or remote code execution” exploits.

Interestingly, it also clarified that it wasn’t in the market for a local privilege escalation vulnerability.

While the platform hasn’t clarified its intentions behind seeking zero-days in the three VPN services, BleepingComputer fathoms that it could be at the behest of one of its government customers that needs a way to identify cybercriminal activity hiding behind VPN services.

Threat actors are known to hide behind the safeguards provided by VPN, and both NordVPN and SurfShark have reportedly been used by threat actors in the past.

None of the three VPN providers have yet issued a statement on Zerodium’s post.

Via BleepingComputer

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
vpn
Ivanti warns another critical security flaw is being attacked
A VPN runs on a mobile phone placed on a laptop keyboard
Major new online tunneling vulnerability could put millions of devices at risk
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
China-linked cyberespionage group PlushDaemon used South Korean VPN service to inject malware
vpn
Nominet says it was hit by cyberattack following recent Ivanti VPN security issue
An illustration of a hand holding a set of keys in front of a laptop, accompanied by a padlock symbol, fingerprint, and key.
Thousands of SonicWall VPN devices are facing worrying security threats
Representational image depecting cybersecurity protection
Hackers are breaking SonicWall products to target business networks
Latest in VPN Privacy & Security
Homepage of CloudFlare website on the display of PC, url - CloudFlare.com.
"Network blocking is never going to be the solution" – Cloudflare slams anti-piracy tactics
Panels at RightsCon 2025 during a press briefing about the latest Access Now report of internet shutdowns
2024 was the worst year on record for internet freedoms – again
Vector illustration of the word Censored in a glitch distorted style
Google, Apple, and internet restriction – how Big Tech is making censorship "much worse" according to experts
Google TV onscreen interface showing streaming apps
Why do streaming services geo-restrict content?
Pirate key on computer keyboard
Italy to require VPN and DNS providers to block pirated content
piracy
Canal+ wants to block VPN usage – and VPN providers are fuming
Latest in News
An Nvidia GeForce RTX 5080 resting on an RTX 5090 on a gray crafting mat.
Corsair tells us only one of its prebuilt PCs with an RTX 5000 GPU has suffered from chip-level fault, suggesting it’s as rare as Nvidia claimed
ChatGPT WhatsApp
New survey suggests the vast majority of iPhone and Samsung Galaxy users find AI useless – and to be honest, I’m not surprised
A hunter holds up a Grav Bowfin and smiles
How to catch a Gravid Bowfin in Monster Hunter Wilds
Fujfilm GFX 50R
First Fujifilm GFX100RF images leaked in build-up to expected reveal – here’s what they tell us about the unique premium compact camera
Samsung Galaxy Z Flip 6 in blue
The Samsung Galaxy Z Flip 7 could have a Motorola Razr-style full-sized cover screen – and I think it’s about time
Spotify logo on a mobile device
Had Spotify problems recently? It's clamped down on Premium APK 'modded' apps – here's what's happening