Edge infrastructure is becoming the shared front door for both nation-state operators and financially motivated crews. VPN gateways, firewalls, application delivery controllers, and remote-access appliances sit in the one place every attacker wants to reach first: the boundary between the internet and the internal network.

A joint analysis from SentinelOne and Tenable compared exposure telemetry with incident-response observations and found that different adversary groups are repeatedly converging on the same perimeter product lines. The point is not that one vendor or one actor is uniquely bad. The point is that edge devices have become a durable attack surface.

What was reported

The research compared Tenable exposure data against SentinelOne DFIR casework and found strong convergence at the vendor layer. Even when the exact CVEs differed, both datasets pointed back to many of the same perimeter vendors and product families. That matters because defenders often prioritize vulnerability response one CVE at a time, while attackers appear to be prioritizing access paths.

The analysis also highlighted confirmed multi-nexus exploitation: multiple categories of actors, including state-sponsored groups and ransomware operators, exploiting the same vulnerabilities or the same product lines. In practical terms, a firewall or VPN flaw is not only an espionage concern and not only a ransomware concern. It is both.

Why this matters for SMBs and government contractors

Small and mid-sized organizations often treat perimeter appliances as infrastructure rather than endpoints. That creates a dangerous blind spot. These devices may not run normal EDR agents, may have limited logging, may require scheduled downtime to patch, and may store credentials or configuration data that helps an attacker move deeper into the network.

Government contractors have an extra problem: edge compromise can become a supply-chain and compliance issue fast. A stolen VPN configuration, LDAP bind credential, admin account, or managed-service console token can expose controlled environments, customer data, subcontractor access, and evidence needed for incident reporting.

The defensive lesson: patching is necessary, but not sufficient

The obvious answer is “patch faster,” but edge appliances are often the hardest systems to patch quickly. They sit in production traffic paths. They support remote work. They may need firmware validation, maintenance windows, vendor support, or HA failover testing. That operational friction is exactly why attackers keep coming back to them.

Instead of folding perimeter devices into a generic vulnerability queue, treat them as a separate risk class with their own operating model.

Practical controls to implement now

  • Create edge-device patch SLAs. Internet-facing VPN, firewall, remote-access, SSO, load-balancer, and management appliances should have shorter timelines than ordinary internal servers, especially when exploitation is public or CISA KEV-listed.
  • Inventory exposed management planes. Confirm which appliance admin interfaces, APIs, portals, and vendor cloud integrations are reachable from the internet. Remove exposure where possible.
  • Minimize enabled features. Turn off unused VPN portals, legacy auth methods, SSO integrations, management protocols, and file-transfer features. Smaller feature sets reduce exploit paths.
  • Log what the appliance cannot protect. Forward authentication, admin, configuration-export, firmware, VPN pool, and account-creation events to the SIEM. Do not rely only on endpoint telemetry behind the device.
  • Hunt after every serious edge CVE. Look for rogue local admins, new VPN users, configuration exports, unfamiliar device registrations, unusual LDAP/service-account use, and internal logins from VPN address pools.
  • Prepare credential rotation playbooks. If an edge device is compromised, assume stored credentials, SAML material, API tokens, VPN secrets, and directory bind accounts may need rotation.

Bulwark Black assessment

The most important shift is mental: perimeter devices are not passive network boxes. They are privileged control points. When compromised, they can hand an attacker authentication paths, internal reachability, configuration intelligence, and trusted network position before an EDR ever sees a payload.

For SMBs and government contractors, the right goal is not perfect patching. The goal is fast prioritization, reduced exposure, usable logs, and rehearsed containment. Treat every internet-facing edge appliance like a Tier 0-adjacent system: fewer features, stronger monitoring, faster emergency windows, and post-patch compromise checks.

Source: SentinelOne / Tenable — Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who’s Exploiting Your Perimeter