Attackers are abusing ViPNet — the encrypted communications software used across Russian government agencies — to gain access to those same agencies, according to BleepingComputer. ViPNet is a homegrown Russian cryptographic and VPN platform, built specifically to secure state communications, which makes its exploitation by outside actors a direct hit on the tooling meant to keep adversaries out in the first place.
This is the oldest trick in nation-state intrusion playbooks: don't break the wall, walk in through the gate everyone trusts. Trusted software with privileged network access — VPN clients, remote management tools, security agents — is a preferred target precisely because it's whitelisted, deeply embedded, and rarely questioned by the people running it. We've seen this pattern before with SolarWinds, with various VPN appliance compromises, and with security software itself becoming the intrusion vector rather than the defense. When the tool that's supposed to secure your network becomes the way in, every downstream user of that tool inherits the exposure, whether they know it or not.
The SAL read: any software you trust because it's "security" software is still an attack surface, and the more privileged its access, the more it deserves scrutiny rather than blind faith.