ZeroHour
Tenable Blogpublished ()ingested Research Special Operations

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

highThreat actor exploited in the wildimportance 62
AI summary · glm-5.3-flash

Joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs shows nation-state and criminal groups independently converge on the same edge infrastructure.

Tenable and SentinelOne jointly analyzed 93 CVE-actor attribution pairs covering exploitation of perimeter devices. The data shows state-sponsored and financially motivated actors independently target the same edge products from Ivanti, Fortinet, and Palo Alto Networks. The findings challenge the narrative that edge exploitation is exclusively a China-nexus nation-state problem, showing a broader shared attack surface.

  • 93 CVE-actor attribution pairs analyzed
  • State and criminal actors hit the same edge devices
  • Ivanti, Fortinet, Palo Alto Networks edge products targeted
  • Edge exploitation is not solely a nation-state problem
Full article

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a nation-state problem, despite two years of headlines about China-nexus actors targeting Ivanti, Fortinet, and Palo Alto Networks. The data here tells a different and much broader story. One focused on…

This source does not provide full text. Read it at tenable.com.