Exposed Staging Server Shows Perimeter Breaches Spreading Inward
The real break is not the edge appliance itself. Once attackers get in through a perimeter device, they can turn that foothold into hidden access to identity systems, SAP, Oracle, and internal data streams that patching the original box does not erase.
CloudSEK mapped Operation Escaneo from an exposed staging server and tied it to active exploitation of Fortinet FortiOS and Ivanti Connect Secure flaws, with confirmed beacons from at least five victims across Mexican government, finance, telecom, transport, and utilities. The exposed artifacts showed tunnels over HTTP, a router-based GRE path, SAP command use, Active Directory maps, private keys, and service-account secrets pulled from victim networks.
That makes the campaign more than a perimeter-bug run. It shows how one appliance compromise can become a durable internal route that slips past host-based monitoring and exposes downstream systems long after the initial device is cleaned up.
CVSS 9.1 CRITICAL: a command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure… Known ransomware campaign use. EPSS 100% (100th percentile).
CISA federal remediation date Jan 22 · date passed
CVSS 8.2 HIGH: an authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a… Known ransomware campaign use. EPSS 100% (100th percentile).
CISA federal remediation date Jan 22 · date passed
CVSS 9 CRITICAL: a stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version… Known ransomware campaign use. EPSS 100% (100th percentile).
CISA federal remediation date Jan 15 · date passed
CVSS 9.8 CRITICAL: a out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13… Known ransomware campaign use. EPSS 84% (100th percentile).
CISA federal remediation date Feb 16 · date passed