Patching isn't enough: CloudSEK researcher on what to check after leaked VPN credentials

TechNadu · x · 2026-09-19

CloudSEK researcher Santripti Bhujel explains that patching an exploited edge device doesn't mean the attacker is gone. After exposed VPN credentials, defenders should check for rogue admin accounts, configuration changes, and lateral movement into internal networks. The takeaway: patching stops the bleeding, but attackers may have established persistence during the exploitation window, requiring systematic post-incident review rather than a simple version upgrade.

Original post →

More from Safety

Safety channel →