Japan breach shows patching a VPN is not enough

Published

Japan's Digital Agency has told staff, contractors and partners that roughly 246,000 records of personal data may have been exposed after attackers reached its Government Solution Service through a vulnerability in VPN-related equipment. The agency posted its notice on 11 September. The uncomfortable part is what comes after the patch.

That is the argument Hong Kong's computer emergency response team built a security blog post around on Monday. An update closes the hole. It does nothing about the way in that the intruder already built.

A patch closes the door, not the tunnel

An internet-edge device (a VPN appliance, a firewall, a router, a remote access gateway) sits between the public internet and everything an organisation runs internally. HKCERT's point is that installing the fix removes the vulnerability but not the access paths an attacker established before it was applied. Accounts already taken, credentials already copied, backdoors and rogue accounts already planted all survive the reboot.

The Japanese case is the illustration HKCERT chose, and it works because the Digital Agency is not a soft target. A large organisation with layered defences still lost a large volume of data because one internet-facing device was reachable and account credentials were available.

Credentials outlive the vulnerability

The second example in the post is FortiBleed, a credential exposure disclosed earlier this year. Login credentials for some Fortinet network devices were suspected to have been exposed, HKCERT writes, potentially affecting more than 70,000 devices worldwide. The risk in a leak of that shape is that authentication data taken before a patch keeps working after it, so the attacker walks back in through the front door and nothing looks anomalous. HKCERT also notes that some recently disclosed high-risk flaws in Fortinet firewall products have been actively exploited, leaving unpatched devices exposed on both counts.

Edge appliances have been the busiest ground in intrusion work for a while. State crews and ransomware affiliates keep turning up on the same boxes, and Japan itself absorbed a month of hacktivist traffic and real breaches in August.

Check the edge before the big week

HKCERT adds a timing note worth borrowing. Major conferences, exhibitions, sporting events and festivals raise an organisation's public profile and its risk at the same time, and attackers prioritise internet-facing VPNs, firewalls and management interfaces around them. Pre-event checks should cover patch and firmware status, account and access-rights settings, abnormal login records, suspicious traffic and data transfers, and whether the incident response and business continuity plans are actually ready to run.

Assume somebody is already inside

The recommendations themselves are ordinary, and that is rather the point, because the failure is in the follow-through rather than the list. Prioritise patching high-risk flaws known to be actively exploited. Turn on multi-factor authentication for VPNs, management interfaces and privileged accounts. Review accounts and access rights on a schedule and disable the ones nobody recognises. Where credentials may have been exposed, change them and revoke live sessions rather than waiting for evidence of misuse. Monitor for odd logins, privilege changes and unexpected data transfers. Then, after patching, go looking: for backdoors, for accounts that should not exist, for anything else that would let somebody back in.

The compromise of an edge device, as HKCERT puts it, is usually the beginning of an attack chain rather than the end. Treating the patch as the end of the incident is how a closed vulnerability turns into a year of quiet access.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions