Upon further investigation I allowed Awesome Miner to reconfigure API access to the machines that I reinstalled firmware and changed the root password (keep in mind these 3 miners have been running flawlessly for 24 hours). As soon as I allowed the program access, the miner reconfigured to stratum+tcp://c11.mine.ahashpool.com3573
It's my opinion that the security vulnerability lies in Awesome Miner. I'm going to reach out to the company today. I will post if there are any developments.
Please keep us appraised of what you find, I am quite interested.
You have a password to your VPN?
Certificates dude. Certificates.
Thank you for your input.. very helpful. I've made sure to go back and edit my previous reply to note I made a mistake.