Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Habuna Heritage Villages in Najran Stand as Testaments to Architectural Ingenuity

    September 11, 2026

    F5 deepens commitment to Saudi Arabia with AI security innovation and planned expansion of F5 global network

    September 11, 2026

    Saudi Arabia shuts East-West oil pipeline after multiple attacks

    September 11, 2026
    Facebook X (Twitter) Instagram
    Riyadh Week
    • Home
    • KSA
    • Business
    • Technology
    • Sports
    • Lifestyle
    Facebook X (Twitter) Instagram YouTube
    Riyadh Week
    Home»Technology»SentinelOne and Tenable find cyber attackers routinely target edge-device vendor ecosystems
    Technology

    SentinelOne and Tenable find cyber attackers routinely target edge-device vendor ecosystems

    Editorial TeamBy Editorial TeamAugust 28, 2026
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Vlad Korsunsky, Chief Technology Officer, Tenable.

    SentinelOne®, the AI security leader, and Tenable® Holdings, Inc., the exposure management company, recently released joint research that suggests a growing disconnect between vulnerability discovery, disclosure and actual exploitation.

    The research draws on Tenable’s exposure data across thousands of organisations and remediation telemetry with SentinelOne’s endpoint and post-exploitation detection data. Together, both views produce a prioritised picture of where risk is concentrating, with lessons ripe for the Frontier AI era. The most critical takeaway: Both nation state and criminal threat actors are focusing on vendors and susceptible points in the attack surface more than specific CVEs.

    Current attacker timelines are already moving faster than standard patch cycles can address. New frontier AI models compress vulnerability discovery from months to hours, significantly expanding potential risks while speeding the time for attackers to move from disclosure to exploit code in about a week. Today, the median organisation takes five months to remediate known vulnerabilities.1 Closing that window takes more than speed, it takes knowing which product lines are more likely to carry the next wave of exploitation.

    The research finds that exposure data and runtime detection converge on the same edge-device vendor surfaces 79% of the time, while they share only 21% overlap at the individual vulnerability level. Both state-sponsored actors and ransomware operators draw from the same small set of high-severity, actively exploited vulnerabilities. The surfaces are consistent and the actors are not. That distinction matters for how defenders prioritise; a pattern Tenable has termed the “Persistently Targeted Vendor.” This is the idea that a small set of vendor product lines, not individual CVEs, is the durable unit of risk over time.

    Other key findings from the research include:

    • Twelve vulnerabilities in the dataset carry confirmed “multi-nexus” attribution — state-sponsored and ransomware operators independently exploiting the very same flaw across five distinct threat categories, including China, Russia, DPRK, Iran-nexus, and criminal (financially motivated) actors.
    • More than half (54%) of organisations running F5 products carry at least one exposed, actively exploited vulnerability, while Citrix customers post the slowest remediation of any vendor studied, at a median of 461 days — a concrete illustration of how specific product lines stay exposed long after a patch exists.
    • Remediation complexity on high-priority vulnerabilities introduces a statistically significant 24-day gap, widening the window attackers have to operationalise an exploit — underscoring why patching speed alone isn’t enough without attack surface minimisation and endpoint protection working in tandem.

    “Speed alone is not enough. By the time a vulnerability hits a remediation queue, adversaries are already iterating the exploit”, said Steve Stone, Chief Customer Officer at SentinelOne. “Static signatures run on human timelines, the threat does not. Runtime behavioural detection has to match that cadence, flagging exploitation patterns as they emerge rather than after the fact”.

    For security teams, the research reinforces the need to look beyond individual vulnerabilities and understand which technology surfaces attackers repeatedly target. Tenable’s exposure data shows where organisations are most exposed and where risk is concentrated, while SentinelOne’s runtime threat and DFIR data shows where and how attackers are operating in the wild. The convergence of these two independent perspectives gives defenders stronger evidence for prioritising remediation, strengthening detection and reducing risk across persistently targeted technology surfaces.

    “Attackers systematically target specific vendor ecosystems that could provide access. They aren’t obsessing over single vulnerabilities, and neither should defenders”, said Vlad Korsunsky, Chief Technology Officer, Tenable. “Our joint research confirms that attackers, big and small, target the same attack surfaces the majority of the time. This research underscores exposure management principles: seeing, prioritising and fixing exposures that create real business risk. As attackers weaponise AI to breach defences faster, organisations that embrace exposure management will win”.

    The research is the latest collaboration in an expanding partnership between best-in-class AI-native CTEM and AI runtime detection and response companies, building on Tenable and SentinelOne’s existing work together, including SentinelOne’s participation as a founding member of Tenable’s CyberAgents Exchange announced at Black Hat USA 2026. It’s the latest step in a partnership that continues to deepen as both companies invest further in AI security. The full research is available at sentinelone.com and tenable.com.

    1Tenable’s Key Takeaways from the Verizon DBIR (2026), May 19, 2026

    Image Credit: Tenable


    Source: Tahawul Tech

    Related Posts

    F5 deepens commitment to Saudi Arabia with AI security innovation and planned expansion of F5 global network

    September 11, 2026

    Google invests €13 billion in Finnish digital infrastructure

    September 11, 2026

    Veeam warns of EMEA ‘shadow agent’ crisis

    September 11, 2026
    Top Posts

    QBS Software Middle East embeds AI into core operations

    April 1, 2026

    Bosnia’s Barbarez cool as ice after reaching World Cup in shootout with Italy

    April 1, 2026

    Kuwaiti tanker hit by Iranian drone attack in Dubai waters

    April 1, 2026

    UAE designers turn jewellery into meaningful Eid gifts

    April 1, 2026
    Don't Miss

    Habuna Heritage Villages in Najran Stand as Testaments to Architectural Ingenuity

    By Editorial TeamSeptember 11, 2026

    The heritage villages across Habuna Governorate in Najran Region stand as enduring testaments to traditional…

    F5 deepens commitment to Saudi Arabia with AI security innovation and planned expansion of F5 global network

    September 11, 2026

    Saudi Arabia shuts East-West oil pipeline after multiple attacks

    September 11, 2026

    UAE students build AI tools to cut hospital wait times, prevent unused operating rooms

    September 11, 2026
    • KSA
    • Business
    • Technology
    • Lifestyle
    • Sports
    • Contact us
    2026. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.