Exploited Edge Devices
The perimeter appliance is the most reliably weaponised class of software we track, and it is the one place in our graph where Chinese espionage groups and ransomware affiliates demonstrably reach for the same object.
Within CISA's Known Exploited Vulnerabilities catalog, the entries naming an edge or perimeter vendor carry the ransomware-association flag at more than twice the rate of KEV as a whole — 46.1% against 20.9%, measured 2026-08-29. Both figures are drawn from inside KEV, so whatever bias there is in how a vulnerability reaches that catalog applies equally to both sides of the comparison.
What no filter on this site can express is the grouping itself. "Perimeter appliance" is not a searchable string, not a vendor, and not a product; it is a judgement about where a device sits in a network. That judgement is what this page publishes, and everything beside it — severity, exploitation probability, which groups we tie to which flaw, what we have written about them — is read live from the same graph the rest of the site reads.
- Curated entries: 27
- Incidents attributed in the last 90 days: 208
- Members in the CISA KEV catalog: 19
- 60 linked briefings
What these have in common
Techniques and tooling shared by more than one of the groups below. Each row shows how many of the groups here carry it, against how many of the groups we hold that kind of data for at all. Ordered by the gap between those two shares — so what leads is what is distinctive about this set, not what is common to everyone.
ATT&CK techniques
- Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002) 3/4 here · 32/210 tracked
- Data Encrypted for Impact (T1486) 3/4 here · 39/210 tracked
- Remote Services: Remote Desktop Protocol (T1021.001) 3/4 here · 46/210 tracked
- Remote System Discovery (T1018) 3/4 here · 46/210 tracked
- Disable or Modify Tools (T1685) 3/4 here · 49/210 tracked
- Exploit Public-Facing Application (T1190) 3/4 here · 54/210 tracked
- Valid Accounts (T1078) 3/4 here · 60/210 tracked
- Disable or Modify System Firewall (T1686) 2/4 here · 13/210 tracked
- Permission Groups Discovery: Domain Groups (T1069.002) 2/4 here · 14/210 tracked
- Service Stop (T1489) 2/4 here · 14/210 tracked
Shared tooling
- Rclone 2/6 here · 31/255 tracked
- PsExec 2/6 here · 64/255 tracked
- Mimikatz 2/6 here · 73/255 tracked
Tooling counts come from the ATT&CK software catalogue, which includes dual-use administrative utilities as well as bespoke malware.
Peak weeks
The busiest single week of leak-site publication for each group here, as a share of everything it has ever posted. Read the last figure first: a peak that lands on day zero is a new leak site publishing its backlog, not a wave of fresh victims. Dates are publication dates, not dates of compromise.
- Cl0p 236 of 725 claims in the week of 2025-02-24 · 32.6% of lifetime output · 644 days after its debut
- DragonForce 37 of 630 claims in the week of 2026-05-25 · 5.9% of lifetime output · 875 days after its debut
- Akira 43 of 1,452 claims in the week of 2025-01-27 · 3% of lifetime output · 385 days after its debut
Groups
Incident counts are attributions in our own log, which is built from ransomware leak-site claims and public breach notices. Espionage actors legitimately show none.
- Salt Typhoon 4 incidents — APT · China — 2024-10-01 — China-nexus. Telecom intrusions via edge appliances.
- UNC5221 0 incidents — APT · China — China-nexus, Ivanti-focused. No incidents in our log — espionage does not reach a leak site.
- UNC4841 0 incidents — APT · China — China-nexus, Barracuda ESG. Also invisible to every incident-driven page.
- Cl0p 725 incidents — Ransomware · Russia — 2026-09-10 — Managed-file-transfer specialist; see also Mass-Victim Weeks.
- Akira 1,452 incidents — Ransomware · Unknown — 2026-09-21 — High-volume ransomware, heavy VPN-appliance exploitation.
- Medusa Ransomware 372 incidents — Ransomware · Unknown — 2026-02-14 — Linked to ScreenConnect and GoAnywhere exploitation.
- DragonForce 630 incidents — Ransomware — 2026-09-20 — Linked to CitrixBleed 2.
Vulnerabilities
KEV marks a vulnerability CISA records as exploited in the wild.
- CVE-2025-5777 KEV · ransomware — CVSS 9.3 · EPSS 100.0% · KEV added 2025-07-10 — CitrixBleed 2. The only edge flaw in our graph tying a state actor and ransomware crews to the same CVE.
- CVE-2023-4966 KEV · ransomware — CVSS 9.4 · EPSS 100.0% · KEV added 2023-10-18 — The original CitrixBleed, two years earlier on the same product line.
- CVE-2024-3400 KEV · ransomware — CVSS 10 · EPSS 100.0% · KEV added 2024-04-12 — PAN-OS GlobalProtect. The densest node here: linked actors, an implant, detection rules and our own coverage.
- CVE-2026-0300 KEV — CVSS 9.3 · EPSS 31.7% · KEV added 2026-05-06 — PAN-OS again, two years on.
- CVE-2024-55591 KEV · ransomware — CVSS 9.8 · EPSS 98.3% · KEV added 2025-01-14 — FortiOS authentication bypass.
- CVE-2022-42475 KEV · ransomware — CVSS 9.8 · EPSS 99.5% · KEV added 2022-12-13 — FortiOS heap overflow; carries two FortiOS-resident implants.
- CVE-2018-13379 KEV · ransomware — CVSS 9.1 · EPSS 100.0% · KEV added 2021-11-03 — The oldest flaw here, and still in the KEV catalog with a ransomware association.
- CVE-2025-0282 KEV · ransomware — CVSS 9 · EPSS 100.0% · KEV added 2025-01-08 — Ivanti Connect Secure.
- CVE-2025-22457 KEV · ransomware — CVSS 9 · EPSS 100.0% · KEV added 2025-04-04 — Ivanti Connect Secure. Four distinct implants map to this one flaw.
- CVE-2026-10520 KEV — CVSS 10 · EPSS 99.9% · KEV added 2026-06-11 — Ivanti Sentry command injection.
- CVE-2023-2868 KEV — CVSS 9.4 · EPSS 87.7% · KEV added 2023-05-26 — Barracuda ESG. Espionage-only: no ransomware flag, one China-nexus actor.
- CVE-2026-15409 KEV · ransomware — CVSS 10 · EPSS 84.5% · KEV added 2026-07-14 — SonicWall SMA1000.
- CVE-2023-20269 KEV · ransomware — CVSS 5 · EPSS 25.5% · KEV added 2023-09-13 — Cisco ASA. The lowest-severity entry here and still ransomware-flagged.
- CVE-2024-1709 KEV · ransomware — CVSS 10 · EPSS 100.0% · KEV added 2024-02-22 — ScreenConnect. The best-covered edge flaw by detection rules.
- CVE-2024-1708 KEV · ransomware — CVSS 8.4 · EPSS 95.5% · KEV added 2026-04-28 — ScreenConnect path traversal, chained with the bypass above.
- CVE-2023-34362 KEV · ransomware — CVSS 9.8 · EPSS 99.9% · KEV added 2023-06-02 — MOVEit. Managed file transfer as an entry class of its own.
- CVE-2025-10035 KEV · ransomware — CVSS 10 · EPSS 99.8% · KEV added 2025-09-29 — GoAnywhere MFT.
- CVE-2024-50623 KEV · ransomware — CVSS 9.8 · EPSS 98.6% · KEV added 2024-12-13 — Cleo Harmony, VLTrader and LexiCom.
- CVE-2026-8452 KEV — CVSS 8.8 · EPSS 1.6% · KEV added 2026-08-26 — NetScaler ADC and Gateway, the newest strict-rule hit: added to KEV 2026-08-26 with a three-day due date. A memory-buffer flaw that denies service on appliances configured as Gateway or AAA virtual server — disruption, not code execution, and no ransomware flag yet.
Defining tradecraft
Techniques a curator named as definitional for this set — a different claim from the computed list above, which is whatever the members happen to share.
- Exploit Public-Facing Application 54 groups — initial-access — Exploit Public-Facing Application — the technique this entire class is an instance of.
Recent activity
The most recent incidents in our log attributed to the groups above, from the last twelve months.
- Prestige Management 2026-09-21 · Akira
- arsrenacer.com 2026-09-20 · DragonForce
- Anderson Industries 2026-09-18 · Akira
- Vetta 2026-09-17 · Akira
- Practice Management (maximizedrevenue.com) 2026-09-17 · Akira
- Javep Chevrolet 2026-09-17 · Akira
- Owen Leigh Optometry 2026-09-16 · DragonForce
- Manders 2026-09-16 · Akira
- Blossomland Accounting 2026-09-16 · Akira
- Community Property Management 2026-09-16 · DragonForce
- Bee Maid Honey 2026-09-16 · Akira
- Southern California Telephone Company 2026-09-15 · Akira
- Lazyboyz 2026-09-15 · Akira
- Pilot Precision 2026-09-15 · Akira
- Medical Department Store 2026-09-11 · DragonForce
- Eagle Construction 2026-09-10 · Akira
- George Cameron Nash 2026-09-10 · Akira
- HENRYPRATT.COM 2026-09-10 · Cl0p
- AK Stamping 2026-09-10 · Akira
- HARLEY-DAVIDSON.COM 2026-09-10 · Cl0p
Our coverage
The 12 most recent of 60 briefings that mention a member of this collection.
- Argentina had its busiest week yet on ransomware leak sites 2026-09-21
- Extortion crews turn on ports and fuel terminals 2026-09-21
- China-linked spies aim a new backdoor at Latin America 2026-09-18
- Bug bounty hunter planted an AI-written stealer on npm 2026-09-16
- LockBit leads a four-fold jump in Dutch leak-site listings 2026-09-05
- Settra quietly became one of the busiest extortion crews 2026-09-04
- Exploited bugs up 34% as attackers beat the patch cycle 2026-09-03
- New ransomware crew Za Woo opens with 10 German victims 2026-08-30
- CISA gives agencies three days to fix a Citrix bug 2026-08-26
- Spies and ransomware crews exploit the same edge devices 2026-08-26
- Veeam bug wrote backup credentials into plain text logs 2026-08-26
- New crew Storm goes after US clinics, banks and factories 2026-08-25
How this list was chosen. Membership is hand-picked from KEV entries whose description names one of these products, plus the groups our graph ties to those entries by an actor-to-CVE link: Ivanti, Fortinet/FortiOS, Citrix/NetScaler, MOVEit, Cleo, Palo Alto/PAN-OS, SonicWall, Pulse Secure, Barracuda, GoAnywhere and ConnectWise ScreenConnect. The 46.1% figure above is that same match run over the KEV catalog on 2026-08-29 — stated with its method because a percentage whose selection rule is not published cannot be checked, and this one is circular by construction: it finds edge CVEs because it looks for edge vendor names. Read the vendor spread as a description of this list, not as a census of the exploited perimeter. We hold NO link between a victim organisation and a CVE (there is no incident-to-CVE table), so this page names no breach vector against any company. The ransomware groups here are listed because they exploit these flaws somewhere, not because any incident in our log is attributed to one of them.
Coverage. Membership here is curated and changes only when a person changes it; every count on this page is computed live. Incident figures come from ransomware leak-site claims and public breach notices, which under-represent espionage, so a group with no incidents is not a quiet group — it is a group our incident sources do not see.