Index live· 1,284 files · 148 editions
ForensicPost

Search the index

10 results
Try
Results for “Edge devices”Newest first
26-0715
File

Salt Typhoon Campaign Reached More Than 600 Organisations Across 80 Countries

More than 600 organisations across 80 countries since 2019, including US carriers and the lawful-intercept systems they run. The metadata was always the point.

Salt TyphoonEdge & network devicesTelecomTelecom
Sev 5TargetTelecom carriers, multipleActorSalt TyphoonUSA
26-0705
File

Qilin Affiliates Linked to Exploitation of Check Point VPN Authentication Bypass

An authentication bypass on the appliance that decides who is inside. The intruder inherits every assumption built on it.

Qilin affiliatesAuthentication bypassMultipleEdge devices
Sev 4TargetCheck Point VPN appliancesActorQilin affiliates
26-0630
File

Adversary Breakout Time Falls to 72 Minutes, Research Finds

Foothold to exfiltration in about 72 minutes. Every response process that assumes a human decides in time is now mistimed.

MultipleVariousMultipleEdge devices
Sev 3TargetEnterprise networks, multipleActorMultiple
26-0602
File

Tens of Thousands of Firewalls, and the Credentials Were Already Inside

Mass credential compromise across tens of thousands of firewalls. Patching fixes the device; it does not un-disclose the credentials.

UnattributedCredential compromiseMultipleEdge devices
Sev 4TargetFortiGate firewallsActorUnattributed
26-0311
File

Edge VPN and Firewall Exploitation Becomes Dominant Initial-Access Route

Four vendors, one campaign. Largest attack surface, least visibility, highest trust — and both states and criminals use the same door.

MultipleAppliance exploitationMultipleEdge devices
Sev 5TargetEdge VPN and firewall appliancesActorMultiple
26-0206
File

European Commission Device Platform Compromised via Ivanti Flaw

Detected and remediated in about nine hours, with exposure limited to names and numbers. Fast containment is a decision, not luck.

UnattributedIvanti EPMMPublic sectorEdge devices
Sev 2TargetEuropean CommissionActorUnattributed
26-0128
File

CitrixBleed-style NetScaler Flaw CVE-2026-8451 Abused Within Hours of Disclosure

A session token read out of appliance memory bypasses the second factor entirely, because authentication already happened.

MultipleMemory disclosureMultipleEdge devices
Sev 4TargetNetScaler appliancesActorMultiple
23-1016
File

A CVSS 10.0 Flaw Let Anyone Create an Admin Account on Cisco IOS XE Devices

Management interfaces are built on the assumption that whoever reaches them is already trusted.

UnattributedUnauthenticated privilege escalationMultipleEdge devices
Sev 5TargetCisco IOS XE devicesActorUnattributed
23-1010
File

LockBit Affiliates Used Citrix Bleed to Reach Boeing’s Parts Distribution Unit

A stolen session token arrives after authentication. Multi-factor is not bypassed — it is never consulted.

LockBit affiliatesMemory disclosureMultipleEdge devices
Sev 5TargetCitrix NetScaler appliancesActorLockBit affiliatesUSA
23-0518
File

Barracuda Told Customers to Replace ESG Appliances Rather Than Patch Them

The vendor did not tell customers to update the appliance. It told them to throw it away.

UNC4841Zero-day exploitationMultipleEdge devices
Sev 5TargetBarracuda ESG appliancesActorUNC4841
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging