Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Thai ISP Breach Exploited Fortinet Flaws

Thai ISP Breach Exploited Fortinet Flaws

Posted on September 15, 2026 By CWS

A cyber attack exploiting multiple vulnerabilities in Fortinet and F5 products has compromised the systems of the Thai broadband provider 3BB, according to a report by Hunt.io. This breach highlights the ongoing threat to telecommunications firms from sophisticated cyber actors.

Discovery and Tools Used

The intrusion was uncovered when the attackers’ tools were found in an open directory on a server located in Thailand. This directory contained 298 files across 30 subdirectories and included scripts for exploitation, privilege escalation, and credential harvesting, as well as a MeshCentral agent configured for persistent access.

These tools were custom-made for 3BB, a major broadband provider in Thailand, and its former owner, Jasmine. The attackers initially gained access by targeting a FortiGate SSL-VPN endpoint with eight shell scripts to identify vulnerabilities in the system’s firmware.

Exploited Vulnerabilities

Upon confirming the firmware version, the attackers exploited several known vulnerabilities, including CVE-2018-13379, CVE-2022-42475, CVE-2023-27997, and particularly CVE-2024-21762, to achieve remote code execution. They also conducted reconnaissance on the F5 BIG-IP system, targeting vulnerabilities like CVE-2021-22986 and CVE-2022-1388.

Following initial access, the attackers worked to gain root privileges on various Linux systems using known exploits like PwnKit and Dirty COW. They established persistent remote access via MeshCentral, allowing ongoing control over the compromised systems.

Post-Compromise Activities

After securing access, the threat actors used a range of scripts for host discovery and lateral movement within 3BB’s infrastructure. They harvested credentials, extracted SSH keys, and modified database privileges, enhancing their control over the network.

Efforts to maintain persistence included deploying PHP web shells and injecting SSH keys. The attackers also ran a cleanup script to erase traces of their presence, while ensuring their backdoor mechanisms remained operational.

This attack underscores the importance of vigilance and robust cybersecurity measures in defending against sophisticated threats targeting critical infrastructure.

Security Week News Tags:3BB hack, credential harvesting, cyber attack, Cybersecurity, F5 vulnerabilities, Fortinet vulnerability, MeshCentral, PHP shells, remote code execution, SSH keys, SUID backdoor

Post navigation

Previous Post: Optimize Security by Testing Attack Chains Holistically
Next Post: Google Alters Link Previews in Search Results

Related Posts

Over 73,000 WatchGuard Firebox Devices Impacted by Recent Critical Flaw Over 73,000 WatchGuard Firebox Devices Impacted by Recent Critical Flaw Security Week News
Coca-Cola Halts Fairlife Production Following Cyber Attack Coca-Cola Halts Fairlife Production Following Cyber Attack Security Week News
Hasbro Data Breach Risks Employee Information Exposure Hasbro Data Breach Risks Employee Information Exposure Security Week News
In Other News: 8,000 Ransomware Attacks, China Hacked US Gov Emails, IDHS Breach Impacts 700k In Other News: 8,000 Ransomware Attacks, China Hacked US Gov Emails, IDHS Breach Impacts 700k Security Week News
Chipmaker Patch Tuesday: Many Vulnerabilities Addressed by Intel, AMD, Nvidia Chipmaker Patch Tuesday: Many Vulnerabilities Addressed by Intel, AMD, Nvidia Security Week News
Healthcare Data Breaches Affect Millions Across the U.S. Healthcare Data Breaches Affect Millions Across the U.S. Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Trusted Email Systems Exploited in New Phishing Tactics
  • OpenAI Probes AI Agents’ Alleged Role in RubyGems Incident
  • Vite Vulnerability Exploited in Credential Harvesting Campaign
  • Google Alters Link Previews in Search Results
  • Thai ISP Breach Exploited Fortinet Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Trusted Email Systems Exploited in New Phishing Tactics
  • OpenAI Probes AI Agents’ Alleged Role in RubyGems Incident
  • Vite Vulnerability Exploited in Credential Harvesting Campaign
  • Google Alters Link Previews in Search Results
  • Thai ISP Breach Exploited Fortinet Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark