Desk live·
ForensicPost
Breaches/Analysis/File 25-1107b

Two Ways an Edge Device Fails, and Only One Is Forgivable

This corpus records edge appliances compromised through zero-days and through unpatched known defects. The distinction is the difference between a shared problem and an organisational one.

Constructed geometry · not a chart of case data
TargetEdge appliance estates
ActorMultiple
D. Kennedy11 min readConfidence: medium2 sources reviewed

The edge-device incidents in this database divide cleanly, and the corpus has been treating them as one category.

Zero-Day: Nothing The Customer Could Have Done

Ivanti at 25-0109. NetScaler at 25-0624. Managed file transfer at 25-0214. Oracle E-Business Suite at 25-1007 and 25-1003.

In each, exploitation preceded any available fix. The customer’s remaining questions — why internet-facing, why data persisted, whether exfiltration would have been detected — are real, per 25-0214, and none of them is "you should have patched".

Known Defect: A Fix Existed And Was Not Applied

Marquis at 25-0814, where the identifier itself contained the year — CVE-2024-40766, exploited in August 2025. The Congressional Budget Office at 25-1106b.

This is a different failure. Not capacity, not the unpatchable backlog at 26-0405, and not the key-rotation gap at 25-0723 where patching was completed and insufficient. A perimeter device, a published fix, and an interval.

Why The Corpus Conflated Them

Because the structural argument at 25-0805 applies to both: the customer of a sealed appliance has no defence in depth available, no agent to install, no host to harden, frequently no shell.

That argument is correct and it covers only the zero-day case. Where a fix existed, the customer’s available action was precisely the one they did not take — and the corpus weakened its own analysis by folding the two together.

What Follows

For zero-days: architecture. Restrict what the appliance can reach, instrument it as a crown-jewel asset, and assume compromise, per 25-1216.

For known defects: an inventory and a clock. The edge-device population in any organisation is small, enumerable, and the highest-priority patch queue that exists. Graded medium: this is a reclassification of incidents in this database, not a new finding.

This is an analysis file

It reclassifies the edge-device incidents recorded in this database. Sources below support the underlying cases. Corrections: corrections@forensicpost.com.

Sources
  1. Lessons from 2025: zero-day exploitation shaping 2026Outpost24
  2. Congressional Budget Office Cisco ASA firewall breachRescana
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary