← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 26, 2026 · 13:00via Tenable Blog

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

Brief

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication.

It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a nation-state problem, despite two years of headlines about China-nexus actors targeting Ivanti, Fortinet, and Palo Alto Networks. The data here tells a different and much broader story.

One focused on vendors vs CVEs.

Read more on Tenable Blog