Subj : Atlas VPN security flaw leaked users' real IP address To : All From : TechnologyDaily Date : Wed Sep 06 2023 18:30:03 Atlas VPN security flaw leaked users' real IP address Date: Wed, 06 Sep 2023 17:07:33 +0000 Description: The fix is not yet available, leaving Atlas VPN users at risk of being doxxed. FULL STORY ====================================================================== Security experts have discovered a major zero-day flaw in Atlas VPNs Linux client that basically renders the entire service useless. A researcher going by the alias Educational-Map-8145 posted a new thread on Reddit, in which they explain a bug in the Atlas VPN client for Linux which allows those that abuse it to view the users real IP address. The whole purpose of a Virtual Private Network ( VPN ) is to mask peoples real IP addresses, and thus hide their identities while online. Ignored by the company As explained in the post, there is a VPN client API that doesnt perform any authentication, meaning that any website with a malicious JavaScript attached to it can disconnect the session and expose the visitors real IP address. Upon discovering the flaw, Educational-Map-8145 claims to have reached out to Atlas VPN, but was ignored. As the company didnt have any active bug bounty programs, the researcher decided to go public. Since then, the company responded, saying it takes cybersecurity very seriously and that its currently working on developing a fix. "We're aware of the security vulnerability that affects our Linux client. We take security and user privacy very seriously. Therefore, we're actively working on fixing it as soon as possible. Once resolved, our users will receive a prompt to update their Linux app to the latest version, the company said. The vulnerability affects Atlas VPN Linux client version 1.0.3, the company confirmed, adding that its working on implementing more security checks in the development process. Until Atlas VPN comes back with a fix, users are vulnerable, and should thus exercise caution when using the VPN. Via: BleepingComputer More from TechRadar Pro Check out our list of the best privacy tools right now Nord Security snaps up Atlas VPN These are the best firewalls around to keep you protected ====================================================================== Link to news story: https://www.techradar.com/pro/security/atlas-vpn-security-flaw-leaked-users-re al-ip-address --- Mystic BBS v1.12 A47 (Linux/64) * Origin: tqwNet Technology News (1337:1/100) .