A Nord VPN bug, a(nother) bad Microsoft patch, Zynga data farmed out, and more

A Nord VPN bug, a(nother) bad Microsoft patch, Zynga data farmed out, and more

Plus, NSA's Ghidra found to contain faulty code


Roundup Here's the latest security news in handy digest form of stories you may have missed over the last week.


NordVPN bug causes connection confusion


Reg reader Tony writes in to tell us of an interesting security bug that arises when running NordVPN in tandem with the Cloudflare 1.1.1.1 WARP service in iOS. The end result is a connection that looks to be protected by NordVPN, but in reality it is completely exposed.


Here's how it works:


The user first connects to 1.1.1.1 with Warp, then disables the app without turning off Warp. Then, when connecting to a NordVPN server with ikev2 protocol, the iOS device will report as being connected to NordVPN and secured, without actually being connected. In other words, you're connected and protected, but you're not.


..

Support the originator by clicking the read the rest link below.