Researchers have identified an exposed attacker-controlled staging server, containing evidence of a widespread intrusion targeting 3BB, the consumer brand operated by Thailand’s Triple T Broadband This article explores vpn vulnerability followed. . The investigation links the operation to the exploitation of a critical SSL-VPN vulnerability, followed by privilege escalation, credential theft, internal reconnaissance, lateral movement, and persistent remote access.
FortiGate SSL-VPN Vulnerability Hunt.io first recorded the open directory at 92.63.180[. ]133:8888 on June 3, 2026. It included FortiGate exploitation scripts, Linux privilege-escalation tools, SSH brute-force utilities, database credential harvesters, VPN configuration files, captured session cookies, cleanup scripts, and a live MeshCentral agent configuration. Attack server directory (Image Source: Hunt.io) Multiple artifacts referenced 3BB infrastructure directly, including internal 10.11.x.x addresses, systems under the triplet.co.th domain, and organization-specific credentials.
A critical out-of-bounds write vulnerability exists within the FortiOS and FortiProxy SSL-VPN component, allowing an unauthenticated remote attacker to execute arbitrary code or commands through specially crafted HTTP requests. The operation extended beyond the FortiGate appliance, targeting eleven reconnaissance scripts that targeted agent.3bb.co[. ]th, a CodeIgniter-based sales portal behind an F5 BIG-IP appliance, testing authentication, session forgery, file uploads, SQL injection, path traversal, server-side request forgery, and HTTP request smuggling.
Potential organizations should scrutinize unexpected MeshCentral agents, connections to www.ayuthayatech[. ]com, reverse-shell traffic involving 92.63.180[. ]133, hidden SUID files, web shells, modified SSH authorization files, and unexplained security gaps in logs.












