Executive Summary
A joint analysis by Tenable and SentinelOne of 93 CVE-actor attribution pairs revealed that state-sponsored threat actors and cybercriminals independently converge on the same edge infrastructure vulnerabilities across major vendors including F5, Fortinet, Citrix, and Ivanti. The research found that 54% of F5 customer environments have at least one exposed, actively-exploited CVE, while twelve vulnerabilities showed confirmed multi-nexus attribution spanning China, Russia, DPRK, Iran, and ransomware groups. High-priority CVEs paradoxically take 24 days longer to remediate than standard vulnerabilities, creating extended windows of opportunity for attackers targeting VPN gateways, firewalls, and remote access appliances.
This convergence highlights the urgent need for organizations to rethink their approach to edge device security as nation-state actors increasingly share attack surfaces with cybercriminals, making traditional threat-model assumptions obsolete in an era of blended adversary tactics.
Why This Matters Now
Edge infrastructure has become a shared battleground where state-sponsored actors and ransomware operators exploit identical vulnerabilities, requiring organizations to defend against all threat categories simultaneously rather than focusing on single adversary types.
Attack Path Analysis
Multi-nexus threat actors exploit edge infrastructure vulnerabilities in VPN gateways, firewalls, and remote access appliances to gain initial foothold, then escalate privileges through credential theft and configuration exports. Attackers perform lateral movement using stolen LDAP credentials and SSH keys, establish persistent command and control through rogue administrative accounts, and exfiltrate sensitive configuration data and credentials. The attack concludes with domain compromise and potential business disruption through unauthorized access to internal resources.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actors exploit publicly known CVEs in edge infrastructure including FortiGate appliances, Ivanti Cloud Services Appliances, and SonicWall devices using authentication bypass, SQL injection, and zero-day vulnerabilities
Related CVEs
CVE-2023-46805
CVSS 8.2An authentication bypass vulnerability in Ivanti Connect Secure allows an unauthenticated attacker to access restricted resources by bypassing control checks.
Affected Products:
Ivanti Connect Secure – 9.x, 22.x
Exploit Status:
exploited in the wildCVE-2024-21887
CVSS 9.1A command injection vulnerability in Ivanti Connect Secure and Policy Secure allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
Affected Products:
Ivanti Connect Secure – 9.x, 22.x
Ivanti Policy Secure – 9.x, 22.x
Exploit Status:
exploited in the wildCVE-2024-3400
CVSS 10A command injection vulnerability in Palo Alto Networks PAN-OS GlobalProtect feature enables an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.
Affected Products:
Palo Alto Networks PAN-OS – 10.2, 11.0, 11.1
Exploit Status:
exploited in the wildCVE-2024-24919
CVSS 8.6An information disclosure vulnerability in Check Point Security Gateways with IPSec VPN, Remote Access VPN, or Mobile Access software blades enabled allows a remote attacker to read certain files on the gateway.
Affected Products:
Check Point Quantum Security Gateway – R81.10, R81.20
Exploit Status:
exploited in the wildCVE-2023-42793
CVSS 9.8An authentication bypass vulnerability in JetBrains TeamCity allows an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and gain administrative control.
Affected Products:
JetBrains TeamCity – < 2023.05.4
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Exploitation for Credential Access
Exploitation of Remote Services
Unsecured Credentials: Private Keys
External Remote Services
Domain Policy Modification
Data from Local System
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security vulnerability identification and management
Control ID: 6.3.3
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.16
DORA – Identification and classification of ICT risk
Control ID: Article 8
CISA ZTMM 2.0 – Macro-Segmentation and Micro-Segmentation
Control ID: Network and Environment
NIS2 Directive – Cybersecurity risk management measures
Control ID: Article 21.2(a)
ISO 27001:2022 – Management of technical vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Critical exposure to multi-vector edge exploitation with F5/Citrix vulnerabilities threatening encrypted traffic, egress security, and zero trust segmentation across payment processing infrastructure.
Health Care / Life Sciences
HIPAA compliance violations from unencrypted traffic exploitation, lateral movement through medical device networks, and delayed remediation of edge infrastructure vulnerabilities.
Government Administration
High-priority targets for state-sponsored actors exploiting VPN gateways and firewalls, with Salt Typhoon-style campaigns compromising citizen data and critical infrastructure connections.
Telecommunications
Network perimeter devices under siege from multi-nexus threat actors exploiting edge infrastructure for encrypted traffic interception and east-west traffic manipulation capabilities.
Sources
- Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who’s Exploiting Your Perimeterhttps://www.sentinelone.com/blog/what-two-independent-datasets-reveal-about-whos-exploiting-your-perimeter/Verified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- National Vulnerability Databasehttps://nvd.nist.gov/Verified
- Ivanti Security Advisory - Multiple Vulnerabilities in Connect Securehttps://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-SecureVerified
- Palo Alto Networks Security Advisory for CVE-2024-3400https://security.paloaltonetworks.com/CVE-2024-3400Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained this multi-nexus attack by limiting lateral movement scope and reducing blast radius across compromised edge infrastructure environments.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud native security fabric may have reduced the attack surface by providing unified visibility and policy enforcement across edge infrastructure, though initial exploitation could still occur through vulnerable appliances.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely have constrained privilege escalation by limiting the scope of administrative access and reducing credential exposure through identity-aware access controls and workload isolation boundaries.
Control: East-West Traffic Security
Mitigation: East-west traffic security would likely have significantly constrained lateral movement by enforcing microsegmentation policies and reducing the attacker's ability to traverse network segments using stolen credentials.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility and control may have detected unauthorized device registrations and constrained persistent access through enhanced monitoring and policy enforcement across management platforms and VPN infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security and policy enforcement would likely have constrained data exfiltration by limiting outbound data flows and reducing the scope of configuration archive transfers through controlled egress policies.
While domain compromise may still occur, the overall impact would likely be reduced through constrained network reach and limited blast radius across segmented customer environments and critical business systems.
Impact at a Glance
Affected Business Functions
- Network Security Infrastructure
- Remote Access Management
- VPN Services
- Perimeter Defense
Estimated downtime: 18 days
Estimated loss: $2,500,000
Network configuration data, stored credentials, LDAP bind credentials, SSH keys, device management configurations, and potential access to internal network resources through compromised edge infrastructure
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement from compromised edge devices using microsegmentation and least privilege access controls
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts from compromised infrastructure through FQDN filtering and data loss prevention
- • Enable Multicloud Visibility & Control with centralized policy management to detect anomalous interactions and suspicious automation across edge infrastructure
- • Establish East-West Traffic Security monitoring to identify and block workload-to-workload communications initiated from compromised edge devices
- • Implement Threat Detection & Anomaly Response capabilities to baseline normal behavior and alert on covert tools, remote access software, and credential theft activities



