Vulnerabilities & Exploits

Hunt.io Found a Tailored 3BB Intrusion Kit

Hunt.io found an open directory tied to an intrusion against Thai broadband provider 3BB, with 298 files of exploit scripts, brute-force tools, privilege-escalation code, credential harvesters, an inventory of compromised machines, and a MeshCentral backdoor. The toolkit was organized for the victim and covered Fortinet FortiGate and F5 BIG-IP targets, not just one gateway.

The scripts first fingerprinted the appliance, checked its firmware, and then picked exploits for matching Fortinet and F5 bugs, including CVE-2024-21762 and several older flaws. After initial access, the operators used MeshCentral for remote administration and ran discovery and credential-stealing scripts, which means the exposure was a maintained foothold with lateral-movement tooling, not a one-time break-in.

For telecom networks that treat edge appliances as the front door, the important part is what survives after patching the original hole: remote-access persistence, harvested credentials, and internal reconnaissance. The reporting does not show how long the directory was exposed, but it does show the attacker had already built a reusable path back into the environment.

1 source · 3h ago

CVEs in this update

7 CVEs

Across BIG-IP; BIG-IQ, big-ip access policy manager, big-ip advanced firewall manager, and related packages.

7 critical · 0 high · 0 medium · 0 low

7 in CISA KEV · 7 with EPSS above 1%

3 with functional or packaged public exploit code

Highest severity: CVE-2022-1388 · 9.8 CRITICAL

Highest EPSS: CVE-2018-13379 · 100%

Timeline

Sources

Vendor digest: Fortinet

Vendor digest: F5

Part of the PlainSec briefing for 2026-09-15

Every edition of this story: Hunt.io Found a Tailored 3BB Intrusion Kit

More from today