HKCERT highlights internet-edge device risks as attackers target VPNs, firewalls and remote access systems

The Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT) warned that internet-edge devices such as VPN appliances,... The post HKCERT highlights internet-edge device risks as attackers target VPNs, firewalls and remote access systems appeared first on Industrial Cyber.

The Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT) warned that internet-edge devices such as VPN appliances, firewalls, routers and remote access systems can provide attackers with gateways into internal networks, potentially enabling credential theft, persistent access, lateral movement and disruption. In a Sept. 15 security blog, HKCERT said organizations should regularly inventory externally accessible network devices and management interfaces, review vulnerabilities, configurations and account status, and continuously monitor for abnormal activity. 

Relevant to industrial environments where remote access and network edge systems can form pathways into enterprise and operational networks, the HKCERT guidance said patching a vulnerability does not necessarily remove attacker access because adversaries may have already obtained credentials, created malicious accounts, installed backdoors, or established other persistence mechanisms before a fix is applied. The organization cited the FortiBleed credential leak, in which authentication data for some Fortinet network devices was suspected to have been exposed, potentially affecting more than 70,000 devices worldwide. 

The HKCERT guidance identified that Japan’s Digital Agency announced that its Government Solution Service (GSS) had been compromised through a vulnerability in VPN-related equipment. Approximately 246,000 personal data records may have been affected, involving government personnel, contractors, and partners. The incident shows that, even where a large organisation has deployed multiple security measures, attackers may still gain initial access and cause a large-scale data breach if Internet-edge devices remain vulnerable or account credentials are stolen.

“Incidents of this kind show that Internet-edge devices have become a common entry point into organisations,” the warning says. “Attacks targeting VPNs, firewalls and remote access services have continued to increase in recent years. For example, some recently disclosed high-risk vulnerabilities affecting Fortinet firewall products have been actively exploited by attackers; devices that have not yet been patched may therefore remain exposed.”

Interestingly, the HKCERT advisory noted that as an organisation patches a vulnerability promptly, the risk may not disappear. “A system update can close the vulnerability, but it does not automatically remove access paths established by an attacker before the patch was applied. The attacker may already have entered the network, obtained accounts or credentials, and continued operating through malicious accounts, backdoors or other persistence mechanisms.”

Organisations should therefore patch vulnerabilities and review account security, active sessions, credentials and system logs to determine whether any unauthorised access has occurred. Depending on the risk, they should reset credentials, revoke active sessions and conduct an incident investigation.

“If internet-edge devices are compromised, organizations may face continued misuse of accounts, passwords and other authentication information,” according to the warning. “Attackers may also remain undetected in the network for an extended period while quietly gathering information. Compromised accounts can be used to access other systems, move laterally across networks and escalate privileges. Such compromises may also lead to data breaches, ransomware attacks or business disruption.”

HKCERT recommends that organisations review rele

Source: Industrial Cyber