Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who's Exploiting Your Perimeter
Tenable, Wednesday, August 26th, 2026
Tenable and SentinelOne analyze 93 CVE-actor attribution pairs showing state and criminal actors share the same edge targets.
A joint Tenable and SentinelOne analysis of 93 CVE-actor attribution pairs finds that state-sponsored actors and financially motivated criminal groups independently converge on the same edge infrastructure.
The researchers argue this shared attack surface is not the province of a single adversary category and not exclusively a nation-state problem, despite two years of headlines about China-nexus actors targeting Ivanti, Fortinet and Palo Alto Networks.
The data indicates that organizations dismissing edge exploitation as an espionage concern are misreading their own exposure. SentinelOne's Incident Readiness and Response team contributed to the publication.