Some services were accidentally exposed to the public internet because of inconsistent network bindings.
Corrected the Network Architecture to ensure predictability.
Cleanup of open ports and firewall rules.
Clear documentation of local vs. public service boundaries.
image Fig 1. Secure Network Architecture
Clear separation of public and private subnets.
Ensuring internal services listen only on localhost/private IPs.
Documentation of fixed vulnerabilities.
More secure production environment.