# Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

DevFeed: [Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter](<https://devfeed.tech/articles/edge-infrastructure-under-siege-what-two-independent-datasets-reveal-about-who-s-exploiting-your-perimeter-8262.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/edge-infrastructure-under-siege>)

Author: Research Special Operations

Published: 2026-08-26T13:00:00Z

Content type: article

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [china](<https://devfeed.tech/tags/china.md>), [complexity](<https://devfeed.tech/tags/complexity.md>), [containers](<https://devfeed.tech/tags/containers.md>), [datasets](<https://devfeed.tech/tags/datasets.md>), [edge](<https://devfeed.tech/tags/edge.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [iran](<https://devfeed.tech/tags/iran.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

A joint Tenable-SentinelOne analysis finds state-sponsored and criminal actors converging on the same edge vulnerabilities. It compares exposure and remediation patterns across vendors and recommends faster patching, attack-surface reduction, and endpoint protection.

## Source excerpt

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge -- not the province of a single adversary category, and not exclusively a nation-state problem, despite two years of headlines about China-nexus actors targeting Ivanti, Fortinet, and Palo Alto Networks. The data here tells a different and much broader story. One focused on vendors vs CVEs. Key Takeaways Two independent observation systems, Tenable exposure telemetry across thousands of customer containers and SentinelOne DFIR casework across 66 CVEs, converge 79% on the same vendor attack surfaces despite minimal CVE-level overlap. Twelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories (China, Russia, DPRK, Iran, ransomware). The exposure picture is flatter than the headlines suggest: Fortinet, the vendor most associated with edge-device attacks in the press, sits mid-pack on container-grain exposure (25%) -- well behind F5 (54%) and in a tight 10-point band with Check Point, Ivanti, and Citrix. 54% of customer environments running F5 products have at least one exposed, actively-exploited CVE; Citrix customers show the slowest remediation patterns at 461 days median time to patch. Remediation complexity, particularly of high priority CVEs, leads to a statistically significant 24-day remediation gap, leaving large windows of opportunity for attackers. The same product lines get hit again and again: Ivanti EPMM and Ivanti Connect Secure each show a newly exploited CVE roughly every 8.5 to 13 months. Leverage multiple d