September 15, 2026
- An exposed staging server mapped an intrusion operation against Thailand’s 3BB. Hunt.io found CVE-2024-21762 FortiGate tooling, multiple root-level MeshCentral agents, targeting of RADIUS subscriber credentials, a potentially valid internal OpenVPN certificate, and cleanup scripts designed to preserve MeshCentral persistence. The directory was first captured on June 3; attribution remains open. · Threat Activity
in Scope Questions Recast Anthropic’s “Rogue Agent” Incidents