Exposed Staging Server Shows Perimeter Breaches Spreading Inward
The real break is not the edge appliance itself. Once attackers get in through a perimeter device, they can turn that foothold into hidden access to identity systems, SAP, Oracle, and internal data streams that patching the original box does not erase.
CloudSEK mapped Operation Escaneo from an exposed staging server and tied it to active exploitation of Fortinet FortiOS and Ivanti Connect Secure flaws, with confirmed beacons from at least five victims across Mexican government, finance, telecom, transport, and utilities. The exposed artifacts showed tunnels over HTTP, a router-based GRE path, SAP command use, Active Directory maps, private keys, and service-account secrets pulled from victim networks.
That makes the campaign more than a perimeter-bug run. It shows how one appliance compromise can become a durable internal route that slips past host-based monitoring and exposes downstream systems long after the initial device is cleaned up.