Key Takeaways
- HKCERT says patching internet-facing equipment should be followed by credential resets, session revocation and compromise assessments.
- Japan’s Digital Agency incident and the FortiBleed leak illustrate how exposed VPN equipment can create wider data and identity risks.
- Ageing appliances, incomplete asset inventories and limited logging can leave organisations exposed even after vulnerable software is updated.
Internet-facing VPN appliances, firewalls, routers and remote-access systems remain under sustained attack, prompting HKCERT to urge organisations to treat software patching as the start of remediation rather than its final step.
Applying an update can close a vulnerability, but it cannot reverse activity that occurred beforehand. An attacker may already possess valid credentials, have created an account or established another route back into the environment.
Japan’s Digital Agency provides a recent illustration. The agency announced that its Government Solution Service (GSS) had been compromised through a vulnerability in VPN-related equipment. Approximately 246,000 personal-data records involving government personnel, contractors and partners may have been affected.
That incident is part of a much broader pattern. GreyNoise recorded nearly 3 billion malicious sessions targeting internet-facing infrastructure over 162 days in its 2026 State of the Edge research. VPNs, routers and remote-access services are attractive because they directly route traffic between outside users and internal systems.
Edge appliances are often harder to monitor than conventional servers. Security teams may have limited endpoint telemetry from a firewall or VPN concentrator, while logs can be incomplete, stored locally or overwritten quickly. Appliances may also be managed by separate networking and security teams, creating gaps in ownership.
Research from VulnCheck and Cloud Security Alliance adds another layer to the concern. VulnCheck reported that 42.5% of vulnerabilities exploited during 2025 affected end-of-life or likely end-of-life devices. Just 23.7% appeared in CISA’s Known Exploited Vulnerabilities Catalog. Cloud Security Alliance, meanwhile, found that network-edge devices were the most frequently targeted category in 2025, with vulnerability exploitation becoming the leading initial-access vector at 31%.
Those findings complicate patch-based programmes. What happens when an appliance no longer receives a fix? Organisations may need compensating controls, tighter access restrictions or accelerated replacement plans. Tracking CISA’s catalog remains useful, but relying on it as the sole prioritisation mechanism could miss vulnerabilities already being used in attacks.
Fortinet products offer a prominent example of the credential dimension. Several high-risk vulnerabilities affecting Fortinet firewall products have been actively exploited, while the FortiBleed credential leak disclosed this year was suspected of exposing login details associated with an undisclosed number of devices worldwide. Credentials harvested before patching may remain usable unless organisations rotate them and invalidate existing sessions.
Amazon Threat Intelligence also reported a 2025 campaign in which attackers compromised customer edge devices and then attempted credential replay against victim services. That sequence shows why multi-factor authentication, credential monitoring and restrictions on privileged access can reduce risk alongside patching.
HKCERT recommends that organisations maintain an inventory of externally accessible equipment and management interfaces, then review firmware, configuration, account status and support lifecycle. Unknown exposure is common, especially after acquisitions, temporary projects or hurried remote-work deployments.
After installing a security update, teams should examine historical logs for abnormal logins, unexpected privilege changes, unfamiliar administrator accounts and unusual data transfers. Potentially exposed passwords, API keys, certificates and related secrets should be changed, while active sessions and tokens should be revoked. Where evidence suggests exploitation, a broader incident investigation may be appropriate.
Verification should extend beyond the appliance itself. Attackers can use an edge foothold to reach identity systems, administrative consoles and internal applications. Segmentation and access policies based on an “Assume Breach” approach can help limit that movement rather than treating a successful VPN login as sufficient proof of trust.
The same discipline matters ahead of conferences, exhibitions, sporting events and major festivals, when public exposure and operational pressure may rise together. HKCERT advises reviewing patch status, access rights, login records, suspicious traffic, incident-response procedures and business-continuity arrangements before such events.
For business leaders, the operational message is straightforward. Edge security combines lifecycle planning, identity protection, logging, threat hunting and response readiness. Patching closes the door that defenders know about; post-patch investigation helps determine whether somebody has already walked through it.
⬇️