Skip to content

Topic

Network Edge Device Security

Vulnerabilities and attacker activity targeting internet-facing firewalls, VPN concentrators and other network perimeter appliances.

Current stories

security6 publishers

Fire Ant taught a Cisco IOS XR router to forward only log lines containing the word Health

Sygnia found the China-nexus group running packet captures, a tac_plus credential hook and two layers of log suppression on the gear that authenticates the rest of the estate, and it never established how the router was breached.

Perspective Coverage

6 publishers
Builder
Builder 33%
Operator
Operator 53%
Investor
Investor 14%

Reality

Evidence68
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence64
security6 publishers

Attackers are running code on BIG-IP APM boxes configured as OAuth authorization servers

F5 disclosed CVE-2026-94127 on September 22 with hotfixes and evidence of exploitation. It is a data plane heap overflow, so a locked-down management interface still leaves the system exploitable, and federal agencies had until September 25.

Perspective Coverage

6 publishers
Builder
Builder 19%
Operator
Operator 64%
Investor
Investor 17%

Reality

Evidence78
Adoption40
Hype gap+10
Incentives30
Confidence75