Furthermore, the group seems to be exploiting CVE-2024-42057, a command injection bug in IPSec VPN that, in certain scenarios, grants unauthenticated users the ability to run OS commands.
The only way to prevent this is to use additional security mechanisms, such as IPsec or WireGuard, which provide end-to-end encryption of VPN traffic data. Only the server is then able to read the ...