Exploited Edge Devices
The perimeter appliance is the most reliably weaponised class of software we track, and it is the one place in our graph where Chinese espionage groups and ransomware affiliates demonstrably reach for the same object.
Within CISA's Known Exploited Vulnerabilities catalog, the entries naming an edge or perimeter vendor carry the ransomware-association flag at more than twice the rate of KEV as a whole — 45.7% against 20.2%, measured 2026-08-06. Both figures are drawn from inside KEV, so whatever bias there is in how a vulnerability reaches that catalog applies equally to both sides of the comparison.
What no filter on this site can express is the grouping itself. "Perimeter appliance" is not a searchable string, not a vendor, and not a product; it is a judgement about where a device sits in a network. That judgement is what this page publishes, and everything beside it — severity, exploitation probability, which groups we tie to which flaw, what we have written about them — is read live from the same graph the rest of the site reads.
- Curated entries: 26
- Incidents attributed in the last 90 days: 219
- Members in the CISA KEV catalog: 18
- 35 linked briefings
What these have in common
Techniques and tooling shared by more than one of the groups below. Each row shows how many of the groups here carry it, against how many of the groups we hold that kind of data for at all. Ordered by the gap between those two shares — so what leads is what is distinctive about this set, not what is common to everyone.
ATT&CK techniques
- Remote Access Tools (T1219) 2/3 here · 12/171 tracked
- Disable or Modify System Firewall (T1686) 2/3 here · 13/171 tracked
- Financial Theft (T1657) 2/3 here · 15/171 tracked
- Data Encrypted for Impact (T1486) 2/3 here · 19/171 tracked
- Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002) 2/3 here · 24/171 tracked
- Disable or Modify Tools (T1685) 2/3 here · 32/171 tracked
- Remote Services: Remote Desktop Protocol (T1021.001) 2/3 here · 37/171 tracked
- Remote System Discovery (T1018) 2/3 here · 40/171 tracked
- Exploit Public-Facing Application (T1190) 2/3 here · 44/171 tracked
- Valid Accounts (T1078) 2/3 here · 47/171 tracked
Shared tooling
Tooling counts come from the ATT&CK software catalogue, which includes dual-use administrative utilities as well as bespoke malware.
Peak weeks
The busiest single week of leak-site publication for each group here, as a share of everything it has ever posted. Read the last figure first: a peak that lands on day zero is a new leak site publishing its backlog, not a wave of fresh victims. Dates are publication dates, not dates of compromise.
- Cl0p 236 of 676 claims in the week of 2025-02-24 · 34.9% of lifetime output · 644 days after its debut
- DragonForce 37 of 615 claims in the week of 2026-05-25 · 6% of lifetime output · 875 days after its debut
- Akira 43 of 1,400 claims in the week of 2025-01-27 · 3.1% of lifetime output · 385 days after its debut
Groups
Incident counts are attributions in our own log, which is built from ransomware leak-site claims and public breach notices. Espionage actors legitimately show none.
- Salt Typhoon 4 incidents — APT · China — 2024-10-01 — China-nexus. Telecom intrusions via edge appliances.
- UNC5221 0 incidents — APT · China — China-nexus, Ivanti-focused. No incidents in our log — espionage does not reach a leak site.
- UNC4841 0 incidents — APT · China — China-nexus, Barracuda ESG. Also invisible to every incident-driven page.
- Cl0p 676 incidents — Ransomware · Russia — 2026-07-31 — Managed-file-transfer specialist; see also Mass-Victim Weeks.
- Akira 1,400 incidents — Ransomware · Unknown — 2026-08-06 — High-volume ransomware, heavy VPN-appliance exploitation.
- Medusa Ransomware 374 incidents — Ransomware · Unknown — 2026-02-14 — Linked to ScreenConnect and GoAnywhere exploitation.
- DragonForce 615 incidents — Ransomware · Malaysia — 2026-08-06 — Linked to CitrixBleed 2.
Vulnerabilities
KEV marks a vulnerability CISA records as exploited in the wild.
- CVE-2025-5777 KEV · ransomware — CVSS 9.3 · EPSS 100.0% · KEV added 2025-07-10 — CitrixBleed 2. The only edge flaw in our graph tying a state actor and ransomware crews to the same CVE.
- CVE-2023-4966 KEV · ransomware — CVSS 9.4 · EPSS 100.0% · KEV added 2023-10-18 — The original CitrixBleed, two years earlier on the same product line.
- CVE-2024-3400 KEV · ransomware — CVSS 10 · EPSS 100.0% · KEV added 2024-04-12 — PAN-OS GlobalProtect. The densest node here: linked actors, an implant, detection rules and our own coverage.
- CVE-2026-0300 KEV — CVSS 9.3 · EPSS 32.1% · KEV added 2026-05-06 — PAN-OS again, two years on.
- CVE-2024-55591 KEV · ransomware — CVSS 9.8 · EPSS 98.3% · KEV added 2025-01-14 — FortiOS authentication bypass.
- CVE-2022-42475 KEV · ransomware — CVSS 9.8 · EPSS 99.5% · KEV added 2022-12-13 — FortiOS heap overflow; carries two FortiOS-resident implants.
- CVE-2018-13379 KEV · ransomware — CVSS 9.1 · EPSS 100.0% · KEV added 2021-11-03 — The oldest flaw here, and still in the KEV catalog with a ransomware association.
- CVE-2025-0282 KEV · ransomware — CVSS 9 · EPSS 100.0% · KEV added 2025-01-08 — Ivanti Connect Secure.
- CVE-2025-22457 KEV · ransomware — CVSS 9 · EPSS 100.0% · KEV added 2025-04-04 — Ivanti Connect Secure. Four distinct implants map to this one flaw.
- CVE-2026-10520 KEV — CVSS 10 · EPSS 99.9% · KEV added 2026-06-11 — Ivanti Sentry command injection.
- CVE-2023-2868 KEV — CVSS 9.4 · EPSS 87.4% · KEV added 2023-05-26 — Barracuda ESG. Espionage-only: no ransomware flag, one China-nexus actor.
- CVE-2026-15409 KEV · ransomware — CVSS 10 · EPSS 78.4% · KEV added 2026-07-14 — SonicWall SMA1000.
- CVE-2023-20269 KEV · ransomware — CVSS 5 · EPSS 21.6% · KEV added 2023-09-13 — Cisco ASA. The lowest-severity entry here and still ransomware-flagged.
- CVE-2024-1709 KEV · ransomware — CVSS 10 · EPSS 100.0% · KEV added 2024-02-22 — ScreenConnect. The best-covered edge flaw by detection rules.
- CVE-2024-1708 KEV · ransomware — CVSS 8.4 · EPSS 87.6% · KEV added 2026-04-28 — ScreenConnect path traversal, chained with the bypass above.
- CVE-2023-34362 KEV · ransomware — CVSS 9.8 · EPSS 99.9% · KEV added 2023-06-02 — MOVEit. Managed file transfer as an entry class of its own.
- CVE-2025-10035 KEV · ransomware — CVSS 10 · EPSS 99.6% · KEV added 2025-09-29 — GoAnywhere MFT.
- CVE-2024-50623 KEV · ransomware — CVSS 9.8 · EPSS 98.6% · KEV added 2024-12-13 — Cleo Harmony, VLTrader and LexiCom.
Defining tradecraft
Techniques a curator named as definitional for this set — a different claim from the computed list above, which is whatever the members happen to share.
- Exploit Public-Facing Application 44 groups — initial-access — Exploit Public-Facing Application — the technique this entire class is an instance of.
Recent activity
The most recent incidents in our log attributed to the groups above, from the last twelve months.
- Basic Grain Products 2026-08-06 · Akira
- Primary Eye Care 2026-08-06 · DragonForce
- EduSpa 2026-08-06 · DragonForce
- Pharma Test Apparatebau AG 2026-08-06 · Akira
- Mike Graham Heating And Air Conditioning 2026-08-05 · DragonForce
- P. A. Inc. (Performance Alloys) 2026-08-05 · DragonForce
- University SprinklerSystems 2026-08-04 · Akira
- TUI China 2026-08-03 · DragonForce
- Albers Mechanical Contractors 2026-08-03 · Akira
- Belasco Electric 2026-08-03 · Akira
- Baicizhan 2026-08-03 · DragonForce
- MBM Law (Moore Bradley Myers) 2026-07-31 · DragonForce
- Lamont Pridmore 2026-07-31 · DragonForce
- RUS Industrial 2026-07-31 · DragonForce
- BLUEVISTALLC.COM 2026-07-31 · Cl0p
- Northwood Country Club 2026-07-29 · Akira
- Franz Krause artworksgroup 2026-07-28 · Akira
- Katathani Phuket Beach Resort 2026-07-27 · DragonForce
- Deluxe Medical Supply 2026-07-26 · DragonForce
- Syntron Bioresearch 2026-07-26 · DragonForce
Our coverage
The 12 most recent of 35 briefings that mention a member of this collection.
- Fake exploit code is stealing security researchers' secrets 2026-08-04
- Ransomware hits Brazil's schools using stolen logins 2026-08-03
- A hacker let an AI agent pick and attack its own targets 2026-07-30
- Extortion crew claims data theft at Coca-Cola's Fairlife dairy arm 2026-07-29
- Colombia warns on Gentlemen ransomware as 30 victims land in a day 2026-07-26
- Interlock ransomware claims a DC housing agency and a refugee charity 2026-07-17
- DragonForce ransomware posts more than 20 victims in three days 2026-07-17
- Hackers exploit SonicWall remote access appliances, CISA warns 2026-07-14
- Ransomware crew D1R claims Synopsys breach reaching ARM and Bosch 2026-07-14
- The Gentlemen ransomware lures affiliates with rare 90 percent payouts 2026-07-11
- Access broker exploits Citrix bug to plant DragonForce ransomware 2026-07-10
- Critical vulnerabilities surged 62% in the second quarter of 2026 2026-07-07
How this list was chosen. Membership is hand-picked from KEV entries whose description names one of these products, plus the groups our graph ties to those entries by an actor-to-CVE link: Ivanti, Fortinet/FortiOS, Citrix/NetScaler, MOVEit, Cleo, Palo Alto/PAN-OS, SonicWall, Pulse Secure, Barracuda, GoAnywhere and ConnectWise ScreenConnect. The 45.7% figure above is that same match run over the KEV catalog on 2026-08-06 — stated with its method because a percentage whose selection rule is not published cannot be checked, and this one is circular by construction: it finds edge CVEs because it looks for edge vendor names. Read the vendor spread as a description of this list, not as a census of the exploited perimeter. We hold NO link between a victim organisation and a CVE (there is no incident-to-CVE table), so this page names no breach vector against any company. The ransomware groups here are listed because they exploit these flaws somewhere, not because any incident in our log is attributed to one of them.
Coverage. Membership here is curated and changes only when a person changes it; every count on this page is computed live. Incident figures come from ransomware leak-site claims and public breach notices, which under-represent espionage, so a group with no incidents is not a quiet group — it is a group our incident sources do not see.