Security researchers disclosed active exploitation of a critical zero-day vulnerability in a widely deployed enterprise VPN appliance, attributing the campaign to a state-linked espionage group.
The flaw allows unauthenticated remote code execution on the device's management interface. Attackers have been observed installing a custom backdoor that survives firmware updates and harvests credentials passing through the appliance.
The vendor released an emergency patch and mitigation guidance, but scanning data suggests thousands of internet-facing devices remain vulnerable, including systems at government agencies and critical infrastructure operators.
Incident responders recommend organizations assume compromise if devices were exposed prior to patching, rotate all credentials and inspect appliances for unauthorized configuration changes.
