Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

Imported from official source

Cybersecurity Classified by Officially

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a nation-state problem, despite two years of headlines about China-nexus actors targeting Ivanti, Fortinet, and Palo Alto Networks. The data here tells a different and much broader story. One focused on vendors vs CVEs. Two independent observation systems, Tenable exposure telemetry across thousands of customer containers and SentinelOne DFIR casework across 66 CVEs, converge 79% on the same vendor attack surfaces despite minimal CVE-level overlap. Twelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories (China, Russia, DPRK, Iran, ransomware). The exposure...

Read the original at the source: https://www.tenable.com/blog/edge-infrastructure-under-siege

Officially imported this from Tenable’s own source. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

This publication has changed since it was first published

2 versions recorded. The original is kept in full — nothing is overwritten.

  1. v2 imported change on current
  2. v1 as first published on

Provenance

Organization
Tenable — imported from official source
Official source
https://www.tenable.com/blog/feed RSS
Imported
September 18, 2026 11:35
Versions
2 recorded
Identity
https://www.tenable.com/211099

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.