SentinelOne and Tenable Find Attackers Target Edge-Device Ecosystems, Not Vulnerabilities

SentinelOne and Tenable Find Cyber Attackers Routinely Target Edge-Device Vendor Ecosystems Rather Than Individual Vulnerabilities
🕧 8 min

New joint research from SentinelOne and Tenable finds that exposure data and runtime detection converge on the same vendor surfaces even as the specific vulnerabilities change

SentinelOne®,(opens in new tab) the AI security leader, and Tenable Holdings, Inc(opens in new tab)., the exposure management company, released joint research that suggests a growing disconnect between vulnerability discovery, disclosure and actual exploitation. The research draws on Tenable’s exposure data across thousands of organizations and remediation telemetry with SentinelOne’s endpoint and post-exploitation detection data. Together, both views produce a prioritized picture of where risk is concentrating, with lessons ripe for the Frontier AI era. The most critical takeaway: Both nation state and criminal threat actors are focusing on vendors and susceptible points in the attack surface more than specific CVEs.

Also Read: IT Tech Pulse Exclusive Interview with Syed Ali Founder and Chief Executive Officer of EZO

Current attacker timelines are already moving faster than standard patch cycles can address. New frontier AI models compress vulnerability discovery from months to hours, significantly expanding potential risks while speeding the time for attackers to move from disclosure to exploit code in about a week. Today, the median organization takes five months to remediate known vulnerabilities.1 Closing that window takes more than speed, it takes knowing which product lines are more likely to carry the next wave of exploitation.

The research finds that exposure data and runtime detection converge on the same edge-device vendor surfaces 79% of the time, while they share only 21% overlap at the individual vulnerability level. Both state-sponsored actors and ransomware operators draw from the same small set of high-severity, actively exploited vulnerabilities. The surfaces are consistent and the actors are not. That distinction matters for how defenders prioritize; a pattern Tenable has termed the “Persistently Targeted Vendor.” This is the idea that a small set of vendor product lines, not individual CVEs, is the durable unit of risk over time.

Other key findings from the research include:

  • Twelve vulnerabilities in the dataset carry confirmed “multi-nexus” attribution — state-sponsored and ransomware operators independently exploiting the very same flaw across five distinct threat categories, including China, Russia, DPRK, Iran-nexus and criminal (financially motivated) actors.
  • More than half (54%) of organizations running F5 products carry at least one exposed, actively exploited vulnerability, while Citrix customers post the slowest remediation of any vendor studied, at a median of 461 days — a concrete illustration of how specific product lines stay exposed long after a patch exists.
  • Remediation complexity on high-priority vulnerabilities introduces a statistically significant 24-day gap, widening the window attackers have to operationalize an exploit — underscoring why patching speed alone isn’t enough without attack surface minimization and endpoint protection working in tandem.

Speed alone is not enough. By the time a vulnerability hits a remediation queue, adversaries are already iterating the exploit,” said Steve Stone(opens in new tab), Chief Customer Officer at SentinelOne. “Static signatures run on human timelines, the threat does not. Runtime behavioral detection has to match that cadence, flagging exploitation patterns as they emerge rather than after the fact.”

For security teams, the research reinforces the need to look beyond individual vulnerabilities and understand which technology surfaces attackers repeatedly target. Tenable’s exposure data shows where organizations are most exposed and where risk is concentrated, while SentinelOne’s runtime threat and DFIR data shows where and how attackers are operating in the wild. The convergence of these two independent perspectives gives defenders stronger evidence for prioritizing remediation, strengthening detection and reducing risk across persistently targeted technology surfaces.

“Attackers systematically target specific vendor ecosystems that could provide access. They aren’t obsessing over single vulnerabilities, and neither should defenders,” said Vlad Korsunsky,(opens in new tab) Chief Technology Officer, Tenable. “Our joint research confirms that attackers, big and small, target the same attack surfaces the majority of the time. This research underscores exposure management principles: seeing, prioritizing and fixing exposures that create real business risk. As attackers weaponize AI to breach defenses faster, organizations that embrace exposure management will win.”

Also Read: IT Tech Pulse Exclusive Interview with Ken Claffey Chief Executive Officer and President of VDURA

The research is the latest collaboration in an expanding partnership between best-in-class AI-native CTEM and AI runtime detection and response companies, building on Tenable and SentinelOne’s existing work together, including SentinelOne’s participation as a founding member of Tenable’s CyberAgents Exchange announced at Black Hat USA 2026. It’s the latest step in a partnership that continues to deepen as both companies invest further in AI security.

Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.

  • Business Wire has been synonymous with well-known press release distribution for more than half a century. Owned by Berkshire Hathaway, it combines regulatory compliance expertise with a powerful media network, helping enterprises large and small share news that influences markets and decision-makers alike.

Recommended Reads :