State-Sponsored Actors Target Network Edge Devices Amid Rising Exploits

State-Sponsored Actors Target Network Edge Devices Amid Rising Exploits

First seen 22 Jul 2026, 18:55 UTC www.sygnia.cowww.trendmicro.com 73% similarity 77.0

Article Content

Browse articles
ThreatCluster

Recent reports indicate a significant rise in the exploitation of edge devices, such as VPN gateways and firewalls, by state-sponsored actors. These devices have become the primary attack vector for espionage operations, with exploitation rates increasing from 3% to 22% in just one year. Notable vulnerabilities include CVE-2023-6548 and CVE-2023-38035, which have been actively exploited since their disclosure. The shift in tactics reflects a strategic recalibration by adversaries, moving from traditional phishing to targeting less-defended assets. Security leaders are urged to adopt a proactive defense strategy, including implementing Zero Trust principles. The ongoing threat landscape demands immediate attention to patch vulnerabilities and strengthen defenses against these persistent attacks.

Key Points: • Edge devices are now the primary target for state-sponsored cyber espionage. • Exploitation of edge devices rose from 3% to 22% of all breaches in one year. • Key vulnerabilities include CVE-2023-6548 and CVE-2023-38035, both actively exploited.

ThreatCluster AI

Timeline

2023-08-21
CVE-2023-38035 published
A critical vulnerability affecting edge devices was disclosed, leading to active exploitation.
Trend Micro
2023-08-22
CVE-2023-38035 added to CISA KEV
CISA listed CVE-2023-38035 as actively exploited, prompting immediate attention from security teams.
Trend Micro
2024-01-17
CVE-2023-6548 published
Another critical vulnerability was disclosed, marking a significant risk for edge devices.
Sygnia
2024-01-17
CVE-2023-6548 added to CISA KEV
CISA confirmed active exploitation of CVE-2023-6548, highlighting the urgency for organizations to patch.
Sygnia
Recent
Ransomware groups adopt exploit tools
Following public disclosures, ransomware groups rapidly developed and adopted tools to exploit these vulnerabilities.
Sygnia

Community

Browse all →