Skip to content

Topic

Edge and IoT Device Security

Securing internet-facing edge and IoT devices—routers, firewalls, VPN gateways, cameras, NAS—against exploitation and unpatched flaws.

Current stories

build1 publisher

NetScaler compromise response has to unwind the controls the gateway concentrated

Citrix disclosed eight NetScaler flaws on September 27, two already exploited, with a federal fix deadline three days later. The box holds authentication, remote access, certificates and admin trust, so cleaning up a compromised one means saving evidence first and then invalidating each of them.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap−5
Incentives
Insufficient
Confidence55
build1 publisher

How Gunra actors got into a network through a default SSL VPN admin password

Gunra actors entered a victim's network through an SSL VPN admin account still on default credentials, according to a 10 August 2026 advisory. The path used no software flaw, so it tests credential changes, lockout and account reviews on edge devices.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence50
security4 publishers

Google traces most of 2026's exploitation growth to fast n-day weaponization

Google's threat intelligence group counts 18 exploited flaws a month in 2026, up from 10.5 in 2025, while zero-days rose only from eight to 11. GTIG attributes most of the added attacks to fast weaponization of disclosed n-days, so the exposure sits in the days after a patch ships.

Perspective Coverage

4 publishers
Builder
Builder 33%
Operator
Operator 61%
Investor
Investor 6%

Reality

Evidence72
Adoption
Insufficient
Hype gap+30
Incentives35
Confidence65
security21 publishers

NetScaler attackers tunnel into internal networks with a new Python proxy

Mandiant and Google traced a September 2026 campaign exploiting NetScaler bug CVE-2026-88772, CVSS 9.5, to root on appliances with no login. From there the intruders drop web shells and a Python tunneler that reaches into victims' internal networks to steal credentials.

Perspective Coverage

21 publishers
Builder
Builder 29%
Operator
Operator 56%
Investor
Investor 15%

Reality

Evidence88
Adoption82
Hype gap−8
Incentives60
Confidence86
security3 publishers

Attackers are exploiting two unpatched NetScaler RCE flaws, watchTowr says

watchTowr says attackers exploited two remote code execution flaws in Citrix NetScaler ADC and Gateway before any fix existed. The August patch for CVE-2026-19490 fixes a different bug, so every operator now has to decide whether to keep the box online and whether to assume it is breached.

Perspective Coverage

3 publishers
Builder
Builder 15%
Operator
Operator 73%
Investor
Investor 12%

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives35
Confidence60
security5 publishers

Evooo1Bot turns edge gear into rentable proxy stock, and the tell is outbound

Fortinet says the Mirai-derived botnet bolts a SOCKS5 relay onto compromised routers, cameras and Confluence hosts. Sellable proxy capacity changes what you hunt for.

Perspective Coverage

5 publishers
Builder
Builder 25%
Operator
Operator 63%
Investor
Investor 12%

Reality

Evidence60
Adoption
Insufficient
Hype gap+10
Incentives30
Confidence65
security13 publishers

CISA's seven new KEV entries put SonicWall gateways and Artifactory on one patch clock

SonicWall's CVSS 10.0 SSRF chains into command execution on remote access appliances, and JFrog Artifactory hands unauthenticated attackers admin under default configuration. Reverse shells and miners are already landing.

Perspective Coverage

13 publishers
Builder
Builder 24%
Operator
Operator 63%
Investor
Investor 13%

Reality

Evidence72
Adoption30
Hype gap+15
Incentives55
Confidence68
security4 publishers

A CVSS 10.0 Cisco FMC bypass tops the four flaws CISA moved into KEV

CISA says all four are under active exploitation, and three of them are unauthenticated flaws in edge and management appliances. Its own alert cites BOD 26-04 and prints no due date for any of them.

Perspective Coverage

4 publishers
Builder
Builder 14%
Operator
Operator 80%
Investor
Investor 6%

Reality

Evidence72
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence70