The observed sessions accessed a sensitive share whose configuration allowed unauthenticated access. No successful privilege escalation was found in the available records. The origin of the compromised VPN credentials remained unknown.
Viewed
Growing MSSP with Offensive Services
The exposed share and the evidence limit
Two compromised VPN accounts. One exposed file share.
Return to the full story ←