Skip to content
Edge Under Siege How State Sponsored Actors Exploit Your Perimeter

Edge Under Siege How State Sponsored Actors Exploit Your Perimeter

www.trendmicro.com July 23, 2026

For many years, the front door to large enterprises and government organizations for state- actors was phishing. This has now changed: Edge devices, such as VPN gateways, firewalls, and network appliances, have increasingly become a primary target as an initial access vector for state- espionage operations. This shift is not temporary and reflects a strategic recalculation by adversaries who identify and exploit the least-defended, high-value assets on enterprise networks: unmanaged edge infrastructure.

This report analyzes publicly available studies on vulnerability trends from 2024 to date, along with threat actor operations, economic drivers, and leaked operational data, to explain why edge devices are being systematically targeted and what CISOs and security leaders must know to respond.

Our key takeaways include the following:

This report is a threat landscape analysis for CISOs and security leaders rather than a vulnerability advisory. Based on publicly available data, we examine why edge devices have become the preferred entry point for espionage operations, who is exploiting them at scale, and what defenders can realistically do given the structural constraints. The appendix provides technical depth, including indicators of compromise (IoCs), exploit economics, and forensic artifacts from an active operator workstation.

Edge device exploitation rose from 3% to 22% of all vulnerability exploitation breaches in a single year, an eightfold increase documented in the Verizon 2025 DBIR. Recorded Future’s H1 2025 report showed that 53% of exploitation activity was state- , with edge appliances accounting for 17% of all actively exploited CVEs.

We do not view this as a temporary spike, but as a strategic recalculation by adversaries. As endpoint security has matured with EDR, multifactor authentication (MFA), and application allow-listing, attackers have shifted to assets on the network that have the highest value but the least defense. These assets are also the hardest to monitor efficiently.

Why edge devices? Edge devices sit at the boundary between an organization’s internal network and the internet. They serve as VPN concentrators, firewalls, web application firewalls (WAFs), and access gateways. Compromising one provides attackers with the following:

At the same time, they are uniquely difficult to defend:

The combination of high strategic value and low defensive coverage makes edge devices the optimal target for espionage operations.

Table 1. General dynamics of vulnerability exploitation and mitigation, based on publicly available sources

Between 2024 and 2026, state- actors exploited critical vulnerabilities across most major edge device vendors. The table below summarizes the key incidents.

Table 2. Edge device vulnerabilities exploited in 2024 to date Note: The information in this table is solely based on publicly disclosed information and does not account for undisclosed vulnerabilities that have been exploited in the wild.

Several patterns emerge from the data. China-aligned groups appear to dominate, accounting for at least seven of 10 major campaigns. The exploitation window is shrinking: The time to exploit averaged two to four weeks post-patch, but GreyNoise's 2026 report noted that this window “has effectively collapsed” to days. Attackers are also reverse-engineering exploits from artifacts collected in the wild, weaponizing them independently of original disclosure. Ivanti has been hit particularly hard, suffering four separate campaigns within 18 months. See Appendix A for more details Ivanti-targeting activities.

Moreover, the targeting spans all major vendors, with authentication bypass, memory corruption, and path traversal vulnerabilities exploited across the board. The impact can be seen globally. According to TeamT5 , Ivanti exploitation alone affected victims across 12 countries: Austria, Australia, France, Spain, Japan, South Korea, the Netherlands, Singapore, Taiwan, the UAE, the UK, and the US. TrendAI telemetry corroborates these findings. Telecommunications, government, defense, and technology sectors were affected significantly.

Edge device exploitation will persist because the economics overwhelmingly favor attackers. It is not just technically convenient, but also the most cost-effective path to strategic intelligence collection. Pwn2Own data from TrendAI’s Zero Day Initiative (ZDI) shows that offensive brokers pay 20 – 40 times more over coordinated disclosure prices for mobile exploits, but only two to five times more for edge device exploits. This confirms that edge vulnerabilities are structurally underpriced relative to their strategic value, making them especially attractive to cost-conscious state actors. For detailed analysis, refer to Vulnerability Broker Pricing in our appendix.

TrendAI’s ZDI — the world’s largest vendor-agnostic coordinated disclosure program — provides transparent pricing benchmarks through its annual Pwn2Own competitions. These figures reflect what researchers earn for reporting vulnerabilities responsibly to vendors. For comparison, nondefensive exploit acquisition markets operate in parallel, paying a structured premium to acquire the same vulnerabilities without vendor disclosure, keeping them secret and weaponizable for state- operations. Table 3 shows the pricing of exploits, based on public broker pricing and industry reporting. Our appendix contains a case study on pricing breakdown.

Coordinated disclosure market (ZDI Pwn2Own benchmark):

Table 3. ZDI's Pwn2Own historical pricing

Table 4. Offensive exploit acquisition market

Based on Tables 3 and 4, two patterns stand out:

On the open market, these prices make edge exploits attractive. In China, state-directed vulnerability programs drive costs even lower. China’s 2024 Network Data Regulations require 24- or 48-hour mandatory vulnerability reporting to state authorities, depending on the seriousness of the vulnerability. The Nvwa (女娲) Project and similar platforms, which operated in the past, offered payouts of RMB 50,000 – RMB 200,000 (USD 7,000 – USD 28,000) for edge device RCE. Note that this information uses solely historical data, as there is no up-to-date information on vulnerability supply chain pricing available in the open domain. Additionally, due to recent regulation changes in China, many of those programs are no longer publicly visible. However, we assess that these changes effectively nationalize vulnerability discovery, most likely giving state-aligned groups access to a steady supply of affordable and expendable exploits.

This explains the pattern of rapid burning of Ivanti, Palo Alto, and Fortinet zero-days throughout 2024 and early 2026. These exploits are cheap enough to use widely and then discard, rather than carefully preserving them for high-value, single-use operations.

The attacker’s economics are favorable, but the defender’s are not. Organizations face high costs when patching edge devices. VPN downtime affects remote workers, common security solutions are not present on edge devices, and even collecting forensic evidence from edge devices is not always straightforward. Testing is required to avoid breaking production, and maintenance windows must be coordinated across teams. This cost-benefit calculation routinely results in delayed patching, creating a remediation window of at least 30 days that attackers exploit through patch difference analysis and rapid weaponization.

The attacker’s economics are simple. A US$100,000 exploit targeting 33,000 Ivanti installations, with even 100 successful compromises, costs US$1,000 per victim. A phishing campaign targeting the same organizations probably costs more per success and yields far less immediate access.

Multiple China-aligned APT groups target edge devices systematically. The breadth and coordination suggest some level of coordination and are not entirely independent campaigns by different actor groups.

Together, these groups demonstrate what looks like a coordinated effort: UNC5221 provides rapid exploitation capability, Earth Estries conducts large-scale intelligence collection, and Volt Typhoon prepares for potential disruption. The shared targeting of edge devices reflects strategic prioritization that goes beyond individual group operations.

The combination of limited visibility, patching friction, and high strategic value makes edge devices uniquely challenging to defend. Organizations should focus on four areas: strategic controls, closing the patching gap, detection, and incident response.

The 30-day average remediation window is the core vulnerability defenders must address. Two approaches help:

Edge devices require dedicated monitoring strategies:

If a compromise is suspected, conduct the following:

Edge devices have become the primary initial access vector for sophisticated adversaries because the economics favor attackers, and defenders have not adapted. Organizations must stop treating these assets as networking equipment outside the security program. They require dedicated monitoring, accelerated patching, and architectural controls commensurate with their strategic value and their risk.

For more technical details please see our Appendix .

Like it? Add this infographic to your site: 1. Click on the box below. 2. Press Ctrl+A to select all. 3. Press Ctrl+C to copy. 4. Paste the code into your page (Ctrl+V).

Image will appear the same size as you see above.