Virtual Private Networks (VPNs) remain one of the most common ways organizations provide secure remote access to internal systems. When configured correctly, they are an important layer of enterprise security. The problem is that attackers rarely stop at the VPN itself.
Modern corporate environments are interconnected through VPNs, cloud Direct Connect links, VPC peering, ExpressRoute connections, site-to-site tunnels, and hybrid infrastructure. Each connection expands the attack surface, and a single misconfiguration can create unexpected pathways that allow an attacker to move far beyond their initial point of access.
At Suzu Labs, we don't simply test whether a VPN is patched or uses MFA. We evaluate the entire trust relationship behind it to understand how an attacker could leverage those connections to reach critical assets.
The Hidden Risk of Trusted Connections
Organizations often spend significant effort protecting internet-facing systems while assuming that private network connections are inherently secure. In reality, trusted network paths frequently become the easiest route for an attacker once initial access has been established.
Common examples include:
- VPN users receiving unrestricted access to internal network segments
- AWS Direct Connect or Azure ExpressRoute exposing more resources than intended
- Overly permissive VPC or VNet peering relationships
- Flat internal networks with little segmentation
- Legacy site-to-site VPN tunnels that remain active long after business needs have changed
- Shared routing tables that unintentionally expose sensitive environments
Each of these issues may appear harmless on its own. Combined together, they often create attack paths that bypass perimeter security entirely.
VPN Access Is Only the Beginning
Compromising a VPN account, through phishing, credential reuse, token theft, or session hijacking, is often only the first step in a real-world intrusion.
Once authenticated, an attacker may discover:
- Internal administration portals
- Active Directory infrastructure
- Backup servers
- File shares containing sensitive data
- Jump boxes
- Development environments
- Cloud management interfaces
- Network management systems
If proper segmentation is missing, a single VPN session can quickly become access to an organization's most valuable systems.
The real question isn't whether someone can connect through the VPN, it's what they can reach after they do.
Direct Connect and Private Connectivity Don't Eliminate Risk
Dedicated connectivity solutions like AWS Direct Connect, Azure ExpressRoute, Google Cloud Interconnect, and MPLS circuits improve performance and reliability, but they should never be mistaken for security controls.
These private connections frequently inherit broad trust relationships between cloud and on-premises environments.
Misconfigurations commonly include:
- Entire cloud environments advertised across internal routing
- Excessive route propagation
- Shared management networks
- Weak network ACLs
- Missing inspection points between environments
Attackers who gain access to one side of these connections may be able to traverse directly into systems administrators assumed were isolated.
Peering Relationships Can Create Unexpected Exposure
Cloud networking makes it remarkably easy to connect environments together.
VPC peering, Transit Gateways, Azure VNet peering, shared services architectures, and hub-and-spoke designs simplify operations, but they also increase complexity.
We've seen environments where:
- Development workloads could reach production systems
- Third-party vendors had unintended network visibility
- Administrative services were reachable across multiple environments
- Security groups allowed unnecessary east-west communication
- Routing changes unintentionally exposed sensitive infrastructure
None of these issues are obvious during routine operations, but they become highly valuable to an attacker looking to move laterally.
On-Premises Pivot Paths Matter
Many organizations now operate hybrid environments where cloud resources and on-premises infrastructure are tightly integrated.
After gaining access to one environment, attackers frequently attempt to pivot into another.
Potential pivot paths include:
- Cloud workloads reaching domain controllers
- VPN-connected endpoints accessing internal management networks
- Shared authentication infrastructure
- Identity federation services
- Administrative jump hosts
- Hybrid Active Directory synchronization servers
These trusted relationships often become the bridge that allows attackers to expand a localized compromise into a much larger incident.
Testing Real Attack Paths
Traditional vulnerability scans can identify outdated VPN appliances or exposed services, but they rarely answer the more important question:
What could an attacker actually do after gaining access?
That's where manual penetration testing provides significantly more value.
Rather than validating individual components, experienced testers evaluate:
- Trust relationships between environments
- Network segmentation effectiveness
- Routing behavior
- Lateral movement opportunities
- Authentication boundaries
- Cloud-to-on-prem connectivity
- Realistic privilege escalation paths
The objective isn't simply finding vulnerabilities, it's understanding how multiple small issues combine into meaningful business risk.
Looking Beyond the Perimeter
Modern networks are no longer defined by a single firewall or VPN gateway. They consist of interconnected environments spanning cloud providers, data centers, remote offices, third-party vendors, and remote users.
Every trusted connection represents a potential attack path if it isn't properly designed, segmented, and monitored.
Understanding those pathways before an attacker does is one of the most valuable outcomes of a comprehensive penetration test.
At Suzu Labs, we evaluate VPNs, Direct Connect links, peering relationships, hybrid infrastructure, and on-premises pivot paths the same way an adversary would, identifying how trusted connections can be chained together into real compromise scenarios, so organizations can remediate the risks that matter most.