Summary

HKISG telemetry and member reports continue to show exposed firewall / VPN management interfaces on public Hong Kong IPs. Attackers chain these with known CVEs for initial access, then move laterally into identity and backup systems.

Risk label: high. Treat internet-reachable management planes as active attack surface until proven otherwise.

Who is affected

  • Organisations running edge firewalls, SSL VPNs, or SD-WAN controllers with management UI on 0.0.0.0/0
  • MSPs managing customer appliances without jump-host or allowlist controls
  • Teams that “temporarily” opened admin ports for a vendor and never closed them

Why this matters now

Exposed management planes compress attacker timelines. Credential stuffing, default passwords, and unpatched CVEs convert a scanning hit into ransomware staging within hours. Trust Reviews and buyer diligence increasingly ask whether admin paths are internet-reachable.

  1. Confirm management planes are not reachable from the open internet — prefer private management networks or ZTNA
  2. Enforce MFA and IP allowlists for any remaining admin paths
  3. Patch to vendor-fixed builds within 72 hours of a relevant advisory
  4. Review auth logs for anomalous admin sessions, new local users, and config exports
  5. Rotate credentials and certificates if exposure window is uncertain
  6. Validate backup integrity and offline copies after any suspected admin compromise

Evidence to retain

  • Screenshots of ACL / security-group rules before and after change
  • Ticket IDs for patch jobs
  • Log extracts covering the exposure window

These artefacts matter if you later enter an Trust Review.

Status

Active. Members should report recurring exposure clusters via Contact so Programme Council can update aggregate outlook notes without naming victims.