CYBERSECURITYTRACKER
TRACKING6,528 stories in this site build1,321 vulnerability news stories in this site build
Permanent story citation

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5063

As cited

Copy frozen at (site build).

vulnerabilities

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

A joint Tenable-SentinelOne analysis of 93 CVE-actor pairs from two independent datasets shows that state-sponsored and criminal threat actors independently target the same edge infrastructure vendors, particularly Fortinet, Citrix, Ivanti, and Palo Alto Networks. Twelve confirmed vulnerabilities have multi-nexus attribution spanning China, Russia, DPRK, Iran, and ransomware groups, indicating a shared attack surface rather than isolated vendor problems. High-priority edge device CVEs take longer to remediate (146 days median) due to operational constraints like change management and firmware update requirements, leaving extended exploitation windows.

Why it matters: Security teams managing F5 (53.8% of environments exposed to active CVEs) and Citrix (461 days median patch time) edge devices need immediate remediation plans. Organizations running Ivanti products face predictable re-exploitation cycles every 8.5 to 13 months and must plan patching capacity accordingly. Incident responders and defenders must treat edge device vulnerabilities as a cross-functional priority incorporating threat actor convergence, CVSS severity, and exposure breadth, because patching for one adversary category leaves organizations exposed to the others targeting the same devices.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

A joint Tenable-SentinelOne analysis of 93 CVE-actor pairs from two independent datasets shows that state-sponsored and criminal threat actors independently target the same edge infrastructure vendors, particularly Fortinet, Citrix, Ivanti, and Palo Alto Networks. Twelve confirmed vulnerabilities have multi-nexus attribution spanning China, Russia, DPRK, Iran, and ransomware groups, indicating a shared attack surface rather than isolated vendor problems. High-priority edge device CVEs take longer to remediate (146 days median) due to operational constraints like change management and firmware update requirements, leaving extended exploitation windows.

Why it matters: Security teams managing F5 (53.8% of environments exposed to active CVEs) and Citrix (461 days median patch time) edge devices need immediate remediation plans. Organizations running Ivanti products face predictable re-exploitation cycles every 8.5 to 13 months and must plan patching capacity accordingly. Incident responders and defenders must treat edge device vulnerabilities as a cross-functional priority incorporating threat actor convergence, CVSS severity, and exposure breadth, because patching for one adversary category leaves organizations exposed to the others targeting the same devices.

VendorsMicrosoftCiscoFortinetPalo Alto NetworksIvantiCitrixVMwareOracleSAPSentinelOneCheck PointJuniperSonicWallF5
Actorsapt29
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary