The Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT) warned that internet-edge devices such as VPN appliances, firewalls, routers and remote access systems can provide attackers with gateways into internal networks, potentially enabling credential theft, persistent access, lateral movement and disruption. In a Sept. 15 security blog, HKCERT said organizations should regularly inventory externally accessible network devices and management interfaces, review vulnerabilities, configurations and account status, and continuously monitor for abnormal activity.
Relevant to industrial environments where remote access and network edge systems can form pathways into enterprise and operational networks, the HKCERT guidance said patching a vulnerability does not necessarily remove attacker access because adversaries may have already obtained credentials, created malicious accounts, installed backdoors, or established other persistence mechanisms before a fix is applied. The organization cited the FortiBleed credential leak, in which authentication data for some Fortinet network devices was suspected to have been exposed, potentially affecting more than 70,000 devices worldwide.
The HKCERT guidance identified that Japan’s Digital Agency announced that its Government Solution Service (GSS) had been compromised through a vulnerability in VPN-related equipment. Approximately 246,000 personal data records may have been affected, involving government personnel, contractors, and partners. The incident shows that, even where a large organisation has deployed multiple security measures, attackers may still gain initial access and cause a large-scale data breach if Internet-edge devices remain vulnerable or account credentials are stolen.
“Incidents of this kind show that Internet-edge devices have become a common entry point into organisations,” the warning says. “Attacks targeting VPNs, firewalls and remote access services have continued to increase in recent years. For example, some recently disclosed high-risk vulnerabilities affecting Fortinet firewall products have been actively exploited by attackers; devices that have not yet been patched may therefore remain exposed.”
Interestingly, the HKCERT advisory noted that as an organisation patches a vulnerability promptly, the risk may not disappear. “A system update can close the vulnerability, but it does not automatically remove access paths established by an attacker before the patch was applied. The attacker may already have entered the network, obtained accounts or credentials, and continued operating through malicious accounts, backdoors or other persistence mechanisms.”
Organisations should therefore patch vulnerabilities and review account security, active sessions, credentials and system logs to determine whether any unauthorised access has occurred. Depending on the risk, they should reset credentials, revoke active sessions and conduct an incident investigation.
“If internet-edge devices are compromised, organizations may face continued misuse of accounts, passwords and other authentication information,” according to the warning. “Attackers may also remain undetected in the network for an extended period while quietly gathering information. Compromised accounts can be used to access other systems, move laterally across networks and escalate privileges. Such compromises may also lead to data breaches, ransomware attacks or business disruption.”
HKCERT recommends that organisations review relevant devices and systems before important events, including status of vulnerability patching and firmware updates; account and access-rights settings; abnormal login records; suspicious network traffic and data transfers; and incident response and business continuity arrangements.
To reduce attack risk on internet-edge devices and prevent compromised accounts or persistence mechanisms from continuing to be used after patching, organizations should prioritize patching high-risk vulnerabilities known to be actively exploited. They should enable multi-factor authentication (MFA) for VPNs, management interfaces and privileged accounts.
Organizations should regularly review accounts and access rights and disable accounts that are no longer used or are unrecognized. If account information is suspected to have been exposed, they should immediately change passwords and related credentials and revoke active sessions. Additionally, they should continuously monitor abnormal logins, changes to privileges and suspicious data transfers. After patching, they should also investigate whether systems have already been compromised or contain backdoors, malicious accounts or other persistence mechanisms.
VPNs, firewalls and other Internet-facing network devices are among an organisation’s most important network gateways and are frequently targeted by attackers. Vulnerability patching is an essential risk-control measure, but it should not be treated as the end of the process. A complete protection process should also include asset inventory, account and credential management, monitoring for abnormal behaviour, intrusion investigation, incident response and business continuity arrangements.
Organisations can adopt an ‘Assume Breach’ security mindset. After patching, they should proactively verify whether accounts, credentials and internal systems have been compromised, and search for backdoors, malicious accounts and other persistence mechanisms. Combining patching, verification and continuous monitoring is the only way to reduce risk of attackers maintaining a long-term presence or regaining access.
In August, the U.K. National Cyber Security Centre (NCSC) warned that it has observed increased global targeting of OT systems, including internet-exposed OT (operational technology) and edge devices. It specifically advised organizations to maintain inventories of internet-facing systems, understand edge-device functions and data flows, apply security updates, retire end-of-life equipment and monitor unexpected configuration changes or outbound connections.


