LIVE · cybersecurity feed
Live wire
CVE-2026-15409 · Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeterAnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodesCVE-2026-60004 · Hackers now exploit critical Gitea flaw in code injection attacksEmployee benefits platform Paylogix says hackers stole financial and health dataU.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure BreachesCVE-2026-61979 · Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as VulnerableCVE-2024-28224 · A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClawAustralia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attack
CVE-2026-15409critical

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. It is the shared attack surface where state-sponsored threat actors and financially motivated criminal grou

zeroday.news ·

A joint analysis by Tenable and SentinelOne reveals that edge infrastructure is a shared attack surface, with both state-sponsored actors and cybercriminals independently targeting the same vulnerabilities and vendors. This convergence challenges the perception that edge device exploitation is primarily a nation-state problem, demonstrating a broader threat landscape.

The study, which combined Tenable's exposure telemetry from thousands of customer environments with SentinelOne's digital forensics and incident response (DFIR) casework across 66 CVEs, found a 79% overlap in the vendor attack surfaces observed by both systems, despite minimal CVE-level overlap. This indicates a consistent focus on specific vendors by a diverse range of threat actors.

Twelve CVEs in the combined dataset were confirmed to have multi-nexus attribution, meaning both state-sponsored and criminal actors independently exploited the same vulnerability. These cases spanned five nexus categories: China, Russia, DPRK, Iran, and ransomware. Examples include CVE-2026-15409 in SonicWall SMA1000, exploited by an unattributed actor and ransomware groups; CVE-2023-42793 in JetBrains TeamCity, targeted by Russia's APT29 and DPRK's Lazarus; CVE-2024-3400 in PAN-OS GlobalProtect, exploited by a China-nexus actor and ransomware operators; and CVE-2024-24919 in Check Point Quantum, targeted independently by China's PurpleHaze and Iran's Fox Kitten. The remaining eight multi-nexus CVEs affected products from Fortinet, Citrix, Cisco, and Ivanti.

The analysis highlighted that certain product lines are repeatedly exploited. Ivanti EPMM and Ivanti Connect Secure, for instance, show a new exploited CVE emerging roughly every 8.5 to 13 months, indicating a structural rather than episodic vulnerability-to-exploitation pipeline.

Regarding vendor exposure, F5 products were found to have at least one exposed, actively exploited CVE in 54% of customer environments. Fortinet, often associated with edge device attacks in media, was mid-pack with 25% container-grain exposure, similar to Check Point, Ivanti, and Citrix. Citrix customers exhibited the slowest remediation patterns, with a median time to patch of 461 days.

A significant finding was that high-priority CVEs take longer to remediate, not less. Across Tenable's list of 238 high-priority CVEs, the median remediation time was 146 days, a 24-day gap compared to the 122 days for all other CVEs. This delay creates extended windows of opportunity for attackers. External data, including the 2026 Verizon Data Breach Investigations Report (DBIR), corroborates this trend, noting an increase in median patch time and that only 54% of edge device KEVs were fully remediated.

The difficulty in patching edge devices is attributed to several factors: they are network boundaries, meaning updates can cause downtime; they often don't run standard endpoint agents; they may require firmware-level updates with manual validation; and they frequently lack active support contracts. These operational challenges mean that the devices most critical to patch are often the hardest to update.

The study concludes that defending against one category of threat actor on edge devices necessitates defending against all, as the attack surface is shared. Organizations are advised to implement multiple defense-in-depth strategies, including rapid patching, minimizing the attack surface through feature-set minimization, and running endpoints in protect mode to mitigate lateral movement from initial access compromises.

ransomwarebreachvulnerabilityzero-daypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Four in Five AI Tools Run with No IT Oversight, New Research Finds

Reco report reveals growing shadow AI problem and surge in vulnerability disclosures

phishingcritical

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes

A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. “By leveraging a critical flaw – the use of bare relative paths – the investigation unraveled a reseller supply chain of 506 domains and 168 storefront brands active since early 2024. Despite leveraging advanced AI to mim

breach

CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks

The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks. The post CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks appeared first on SecurityWeek.

CVE-2026-60004critical

Hackers now exploit critical Gitea flaw in code injection attacks

Attackers are actively exploiting a critical code injection vulnerability (CVE-2026-60004) in the self-hosted Gitea Git service. The flaw allows authenticated users with write access to execute arbitrary shell commands, and with default open registration, unauthenticated attackers can exploit it by creating an account. Gitea has released version 1.27.1 to address the issue, and CISA has ordered U.S. federal agencies to patch within three days due to active exploitation, with reports indicating cryptocurrency mining malware deployment.

mfa

The MFA Identity Trap: When Authentication Creates a False Sense of Security

Organizations are falling into an 'MFA Identity Trap' by conflating identity verification, authentication, and threat detection. This confusion can lead to a false sense of security, where systems successfully authenticate attackers instead of blocking them. A clear distinction between these processes is crucial for effective security.

security

RightCrowd Pass unifies mobile, physical, and biometric credentials

RightCrowd announced RightCrowd Pass, a credentialing solution that issues and manages mobile, physical and biometric access credentials from a single platform. Many large enterprises and universities rely on badge programs-built years ago. As organizations add mobile and biometric credentials, what began as a single access program can fragment into three separate systems, each with its own issuan