European intelligence services are putting sharper language around a problem defenders already feel every week: internet-facing edge devices are becoming one of the most important control points in state cyber operations.

A new joint advisory from the Netherlands’ AIVD, MIVD, and NCSC warns that Chinese cyber operations against vulnerable edge devices are expected to increase. The advisory focuses on firewalls, VPN gateways, proxies, portals, routers, and similar perimeter systems that sit between an organization and the public internet. Tech Times connected that warning to the earlier COATHANGER campaign, where Dutch investigators found that a Chinese state actor had compromised at least 20,000 FortiGate systems worldwide, including devices tied to government, international, and defense-related organizations.

This is not just another patch-management reminder. Edge devices are structurally different from normal endpoints. They are exposed by design, often run proprietary operating systems, cannot usually host endpoint detection and response agents, and commonly keep the most useful logs locally on the device. If the appliance is compromised, the attacker may also control the evidence.

What changed

The Dutch advisory argues that Chinese operators are not merely opportunistically scanning for perimeter bugs. The services assess that Chinese threat actors have invested deeply in understanding Western edge-device products, including reverse engineering, vulnerability research, and in some cases access to source code or technical details obtained through espionage. That combination matters because it shortens the path from product knowledge to exploit development.

The advisory also calls out artificial intelligence as an accelerator. AI does not magically create an intrusion, but it can compress reconnaissance, code review, exploit selection, and known-vulnerability operationalization. For defenders, the practical outcome is simple: the safe patch window for perimeter systems is shrinking, and in a true zero-day scenario there may be no patch window at all.

The COATHANGER history shows why this is more than theory. In that campaign, attackers abused CVE-2022-42475 in FortiOS and deployed malware designed for FortiGate appliances. Dutch reporting later found the campaign was broader than initially understood, with at least 20,000 FortiGate systems compromised across 2022 and 2023. One of the most concerning details was persistence: systems that were patched or upgraded after compromise could still require dedicated forensic work and remediation if malware had already been installed.

Why this matters to SMBs and government contractors

Small and midsize organizations often treat the firewall or VPN appliance as a trusted boundary. Government contractors do the same, but with higher consequences: controlled unclassified information, proposal data, program communications, payroll, remote administration paths, cloud credentials, and identity infrastructure may all depend on the assumption that the perimeter device is clean.

That assumption is becoming dangerous. A compromised edge device can provide traffic visibility, credential exposure, VPN session abuse, stealthy command-and-control, and a path toward internal systems. Even if the attacker does not immediately exfiltrate sensitive files, the appliance can become a long-term observation post.

The hard part is that many organizations do not have strong telemetry from these systems. Endpoint agents may cover laptops and servers, but perimeter appliances are often monitored through vendor logs, syslog forwarding, configuration backups, and alerting rules that were never designed for nation-state persistence. When logs stay only on the compromised device, incident response becomes guesswork.

Defensive priorities

The answer is not to buy panic. It is to treat edge devices as high-value assets with their own monitoring and recovery plan.

  • Inventory every edge device. Know the model, firmware version, public exposure, management interface, support status, and owner for each firewall, VPN gateway, router, proxy, and remote-access portal.
  • Centralize logs away from the appliance. Forward authentication, admin, VPN, configuration, traffic, and system events to a protected logging platform or SOC segment. Local-only logs are not enough.
  • Shorten patch decision cycles. Edge-device patches need a different service level than routine workstation updates. Test quickly, deploy quickly, and document compensating controls when a patch must be delayed.
  • Restrict management paths. Management interfaces should not be broadly reachable from the internet. Use jump hosts, VPN restrictions, source-IP controls, strong MFA, and separate admin identities.
  • Watch configuration drift. Back up configurations and alert on new admin accounts, changed VPN settings, altered logging destinations, modified access rules, suspicious certificates, or unexpected scheduled tasks.
  • Segment behind the perimeter. If the edge device falls, the attacker should not immediately reach domain controllers, file shares, build systems, cloud admin consoles, or sensitive enclaves.
  • Practice appliance forensics. Have vendor-specific playbooks for evidence collection, clean rebuilds, credential rotation, and traffic review. A firmware upgrade alone may not be sufficient after suspected compromise.

Bulwark Black assessment

The most important lesson from the Dutch warning is that the perimeter is no longer just a wall. It is an endpoint, a sensor, an identity gateway, and sometimes a blind spot all at once. For Chinese state operators, that makes it an ideal target. For defenders, it means edge devices deserve the same seriousness normally reserved for domain controllers and identity providers.

Organizations that cannot prevent every zero-day can still reduce the blast radius. Centralized logging, segmentation, vendor diversification, forensic readiness, and disciplined patching all make a successful appliance compromise less useful to an attacker. The goal is not perfect prevention. The goal is to deny quiet, long-term access.

For SMBs and government contractors, this should become a quarterly control review: what is exposed, what is patched, what is logging centrally, what would be rebuilt from scratch, and what credentials would be rotated if the firewall or VPN gateway were declared hostile. If those answers are unclear today, the edge is carrying more risk than leadership can see.

Sources: Tech Times reporting on the Dutch advisory and COATHANGER context; AIVD/MIVD/NCSC Cyber Advisory: Edge devices systematically targeted by Chinese cyber threat actors; NCSC-NL COATHANGER campaign update.