Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter (opens in a new tab)
Why readTwo independent datasets, Tenable exposure telemetry and SentinelOne DFIR casework across 66 CVEs, converge 79% on the same edge vendors, and 12 CVEs show both state and criminal actors exploiting them.
A joint Tenable-SentinelOne analysis of 93 CVE-to-actor attribution pairs finds that state-sponsored and financially motivated groups independently converge on the same edge infrastructure vendors, with 79% agreement at the vendor level despite minimal overlap at the CVE level. Twelve CVEs in the combined set have confirmed multi-nexus attribution, meaning both categories exploited them separately. The practical argument is that edge exposure should be prioritised by vendor attack surface rather than by which adversary category the headlines attach to a given CVE.