State-Sponsored Actors Target Network Edge Devices Amid Rising Exploits

State-Sponsored Actors Target Network Edge Devices Amid Rising Exploits

First seen 22 Jul 2026, 18:55 UTC www.sygnia.cowww.trendmicro.comNews.Sophoswww.ncsc.gov.uk 77.0

Article Content

Browse articles
ThreatCluster

Recent reports indicate a significant rise in the exploitation of edge devices, such as VPN gateways and firewalls, by state-sponsored actors. These devices have become the primary attack vector for espionage operations, with exploitation rates increasing from 3% to 22% in just one year. Notable vulnerabilities include CVE-2023-6548 and CVE-2023-38035, which have been actively exploited since their disclosure. The shift in tactics reflects a strategic recalibration by adversaries, moving from traditional phishing to targeting less-defended assets. Security leaders are urged to adopt a proactive defense strategy, including implementing Zero Trust principles. The ongoing threat landscape demands immediate attention to patch vulnerabilities and strengthen defenses against these persistent attacks.

Key Points: • Edge devices are now the primary target for state-sponsored cyber espionage. • Exploitation of edge devices rose from 3% to 22% of all breaches in one year. • Key vulnerabilities include CVE-2023-6548 and CVE-2023-38035, both actively exploited.

Ask AI about this cluster

Timeline

2023-08-21
CVE-2023-38035 published
A critical vulnerability affecting edge devices was disclosed, leading to active exploitation.
Trend Micro
2023-08-22
CVE-2023-38035 added to CISA KEV
CISA listed CVE-2023-38035 as actively exploited, prompting immediate attention from security teams.
Trend Micro
2024-01-17
CVE-2023-6548 published
Another critical vulnerability was disclosed, marking a significant risk for edge devices.
Sygnia
2024-01-17
CVE-2023-6548 added to CISA KEV
CISA confirmed active exploitation of CVE-2023-6548, highlighting the urgency for organizations to patch.
Sygnia
Recent
Ransomware groups adopt exploit tools
Following public disclosures, ransomware groups rapidly developed and adopted tools to exploit these vulnerabilities.
Sygnia