CVE-2024-6387 is a critical vulnerability in OpenSSH that was exploited by APT36 in their campaign targeting Afghan telecom and Indian critical infrastructure. The exploit was found on an exposed staging server, indicating the threat actor's capability to leverage known vulnerabilities for initial access or lateral movement.