TL;DR: Attackers are concentrating on persistently targeted vendor ecosystems rather than isolated vulnerabilities, with exposure data and runtime detection overlapping 79% at the vendor-surface level but only 21% at the individual CVE level, according to SentinelOne and Tenable’s joint research. The shift makes patch velocity necessary but insufficient: defenders need exposure management, attack surface minimisation, and runtime detection that tracks how exploitation actually unfolds.
At a glance
What this is: This joint research argues that attackers are repeatedly targeting edge-device vendor ecosystems, not just individual CVEs, and that remediation and runtime data converge on the same vendor surfaces.
Why it matters: For IAM and security teams, that means prioritisation must move from isolated vulnerability lists to the vendor surfaces that concentrate risk across identity, access, and operational control planes.
By the numbers:
- Exposure data and runtime detection converge on the same edge-device vendor surfaces 79% of the time, while they share only 21% overlap at the individual vulnerability level.
- Citrix customers post the slowest remediation of any vendor studied, at a median of 461 days.
👉 Read SentinelOne and Tenable’s joint research on persistently targeted vendor ecosystems
Context
Edge-device security is not just a patching problem. When attackers repeatedly exploit the same vendor ecosystems, the real governance question becomes whether defenders can identify the product lines that create durable exposure, not merely the CVEs that appear in a disclosure feed. In practice, this is where identity and access control intersect with perimeter and workload defence, because compromised edge systems often become the entry point for credential abuse and lateral movement.
SentinelOne and Tenable’s joint research shows why traditional vulnerability triage often lags attacker behaviour. The finding is atypical in one important sense: rather than treating each flaw as a separate event, the research groups exploitation around persistent vendor surfaces that keep reappearing across threat actors and campaigns.
Key questions
A: Teams should prioritise by vendor surface, exploitability, and business reach, not by CVE count alone. If a product line is repeatedly targeted across the sector, exposed instances deserve immediate attention even when the individual vulnerability is not the highest scored item. This approach aligns remediation with where attackers are actually operating.
Q: Why do edge devices create disproportionate enterprise risk?
A: Edge devices sit at the boundary between external traffic and internal trust, so compromise often creates a fast path to credentials, management interfaces, and lateral movement. They also tend to have long lifecycles and uneven patch cadence, which leaves exploitable conditions open long after disclosure. That combination makes them durable attacker targets.
Q: What do defenders get wrong about patching exposed infrastructure?
A: They often treat patching as the end state when it is only one control in a broader exposure problem. Remediation delay, testing complexity, and runtime exploitation all influence whether a known flaw is still reachable. Teams need to measure exposure age, not just patch completion.
Q: How do organisations prove that exposure management is working?
A: They should measure time to owned action, reduction in high-risk exposures, closure quality for grouped findings, and whether privileged identity paths are shrinking over time. If those measures do not improve, the programme is producing noise rather than risk reduction.
Technical breakdown
Why edge-device ecosystems become durable attack surfaces
Edge devices concentrate trust. They sit at the boundary between external access and internal services, often with broad reach, long lifecycles, and delayed maintenance windows. That combination creates a persistent attack surface where the same product line can keep reappearing in exploitation even as specific CVEs change. In security terms, the unit of risk becomes the vendor ecosystem, because attackers can reuse exploit chains against common deployment patterns, misconfigurations, and operational blind spots. Exposure management and runtime detection therefore need to track the asset class, not just the vulnerability identifier.
Practical implication: build prioritisation around vendor surface exposure, not only CVE severity.
Why remediation timing now matters more than patch counts
The article highlights a gap between discovery and operational remediation. Patch queues, change windows, and testing requirements create a time lag that attackers can exploit before defenders close exposure. A vulnerability may be known, but the exploitable condition remains open for weeks or months if remediation is gated by dependency risk, application compatibility, or infrastructure constraints. That makes the detection of active exploitation patterns just as important as patch assignment. In effect, the problem is not whether a flaw exists, but how long it remains reachable to an attacker with a working path.
Practical implication: tie remediation SLAs to exploitability and reachability, not disclosure date alone.
How exposure telemetry and runtime data should be combined
Exposure data tells defenders where weaknesses exist; runtime detection shows where attackers are acting. Used together, they create a more reliable risk picture than either source alone. Exposure tooling can highlight asset classes with repeated high-severity findings, while runtime and DFIR telemetry confirm which surfaces are actually being used in the wild. That combination is especially useful for edge technologies, where patching decisions often depend on real-world exploitation pressure rather than theoretical risk. The analytical value comes from convergence across data sets, not from any single feed.
Practical implication: correlate exposure and runtime telemetry to identify the surfaces that deserve immediate containment.
Threat narrative
Attacker objective: The attacker wants a durable, repeatable access path through a widely deployed vendor surface that can be reused across victims and campaigns.
- Entry occurs through a publicly exposed or actively exploited edge-device surface that attackers know is frequently present in enterprise environments.
- Escalation follows when the device provides a foothold for credential theft, privilege gain, or access to adjacent internal systems.
- Impact comes from repeatable exploitation of the same vendor ecosystem across multiple organisations, allowing attackers to operationalise access faster than remediation can close the gap.
NHI Mgmt Group analysis
Persistently targeted vendor ecosystems are becoming the real unit of risk. Security teams still tend to triage individual CVEs as if each flaw were independent, but attackers often organise their efforts around the product lines that keep exposing the same operational weakness. That is a governance problem as much as a technical one, because it changes how risk concentration should be measured and reported. For identity programmes, the same logic applies when a platform or edge service becomes the gateway to credentials, tokens, or management interfaces.
Patch velocity alone cannot close an exploitation window that keeps reopening. The article’s median remediation lag shows why disclosure dates do not map cleanly to safety. If change control, testing, or dependency risk stalls action, the exposure remains live long enough for exploitation to mature. The practitioner conclusion is straightforward: exposure age, exploitability, and business reach matter more than raw patch throughput.
Edge-device risk now sits at the intersection of infrastructure security and identity control. Once an attacker uses an exposed vendor surface to land, the next move is often credential theft or privilege expansion into internal systems. That means IAM, PAM, and NHI governance need to be part of the same prioritisation conversation as vulnerability management. The control question is not just whether the edge device is patched, but whether the access paths it protects can be abused before containment.
Persistently Targeted Vendor is a useful operational concept because it names the failure mode. It captures the way a small number of vendor product lines keep absorbing attacker focus even when the underlying CVEs rotate. That helps teams move from reactive ticketing to structural exposure reduction, including segmentation, tighter access boundaries, and better control of administrative paths. The practitioner takeaway is to treat repeated vendor exploitation as a category-level signal, not a one-off incident.
What this signals
Persistently targeted vendor surfaces should become a standing input to remediation planning. The practical change for programme owners is to stop treating disclosure feeds as the sole trigger for action. Exposure and telemetry now need to be joined in the same workflow so that edge devices, administrative interfaces, and adjacent identity paths are prioritised together. If compromise of a boundary device can expose credentials or management trust, then identity control boundaries become part of exposure management.
AI acceleration is shrinking the time defenders have to detect and contain exploitation. As exploit development speeds up, control teams need shorter feedback loops between detection, triage, and containment. That means aligning security operations with vulnerability management, not running them as separate conversations. Where relevant, map the response model to the MITRE ATT&CK Enterprise Matrix and the NIST Cybersecurity Framework 2.0.
Edge compromise increasingly creates an identity problem, not just a perimeter problem. Once attackers reach internal systems through a vendor surface, the next question is often which accounts, tokens, or service paths can be reused. That is where the NHI lifecycle becomes relevant, because stale machine credentials and over-broad access can turn a single exposure into repeatable access. Teams should pair exposure management with NHI lifecycle controls and periodic privilege review.
For practitioners
- Map exposure by vendor surface, not just by CVE Group edge-device findings by product line and deployment pattern so remediation focuses on the surfaces attackers repeatedly exploit, not isolated vulnerability records.
- Prioritise remediation using exploitability and reachability Assign urgent handling to exposed devices that are internet-facing, privilege-bearing, or connected to sensitive management planes, even when the vulnerability count is small.
- Correlate exposure telemetry with runtime detections Use exposure management data alongside endpoint and post-exploitation signals to confirm which vendor surfaces are active attacker targets in your environment.
- Reduce blast radius around edge access paths Segment administrative interfaces, restrict privileged sessions, and remove unnecessary trust relationships so a compromised edge surface cannot easily pivot inward.
Key takeaways
- Attackers are concentrating on vendor ecosystems that repeatedly expose the same operational weakness, which makes the product line more important than the isolated CVE.
- The 79% versus 21% overlap finding shows why exposure management and runtime detection need to be combined if teams want a realistic view of risk.
- Defenders should prioritise repeatable attack surfaces, shorten remediation lag, and reduce the blast radius of any edge-device compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0001 Initial Access; TA0006 Credential Access; TA0008 Lateral Movement | Edge-device exploitation commonly starts access and then enables credential abuse and pivoting. |
| NIST CSF 2.0 | PR.AC-4 | The article centres on access exposure and containment around boundary systems. |
| NIST SP 800-53 Rev 5 | SI-2 | The research is about remediation lag and active exploitation of known weaknesses. |
| CIS Controls v8 | CIS-7 , Continuous Vulnerability Management | The study directly addresses vulnerability discovery, prioritisation, and remediation timing. |
| NIST AI RMF | MANAGE | AI-driven discovery is compressing exploit cycles, which affects risk management decisions. |
Map exposed vendor surfaces to ATT&CK and prioritise controls that reduce initial access and lateral movement.
Key terms
- Persistently targeted vendor surface: A product line or technology family that attackers repeatedly exploit across organisations, even as the specific CVEs change. The concept shifts attention from single flaws to the durable exposure created by common deployment patterns, shared management interfaces, and long remediation cycles.
- Exposure management: Exposure management is the practice of identifying which assets are reachable by attackers and reducing that reach before exploitation occurs. For collaboration systems like SharePoint, it is not enough to know that a patch exists, because public accessibility changes the speed and likelihood of attack.
- Runtime Detection: Runtime detection is the practice of monitoring behaviour while a system is operating so suspicious actions can be flagged or contained. It is useful for visibility, but it does not replace preventive identity controls because it reacts after the access path has already been used.
- Blast Radius: The potential scope of damage if a specific credential or identity is compromised. Identities with broad permissions have a larger blast radius and represent a higher priority for least-privilege enforcement and security controls.
What's in the full report
SentinelOne's full article covers the operational detail this post intentionally leaves for the source:
- The underlying exposure and remediation telemetry across thousands of organisations, including how the vendor-surface pattern was derived.
- The joint comparison of endpoint, post-exploitation, and exposure data that supports the 79% convergence finding.
- The specific vendor ecosystems and remediation timing patterns discussed in the study, including the slower-moving product families.
- The research context around AI acceleration and how it affects exploit development timelines.
Deepen your knowledge
NHI Mgmt Group covers identity security, NHI governance, and agentic AI through independent research, practitioner guides, and the NHI Foundation Level course, the industry's only accredited NHI security programme. It helps security teams connect machine identity governance to broader access control and operational resilience.
Published by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org