Cybersecurity posture is shifting as threat actors refine their strategies to target vendor ecosystems rather than chasing single software flaws. According to new research from SentinelOne and Tenable, exposure data and runtime detection converge on the exact same edge-device vendor surfaces 79 percent of the time. However, those same datasets share only 21 percent overlap at the individual vulnerability level. This gap demonstrates that while specific vulnerabilities change, the target product lines remain remarkably constant.

Modern threat actors operate on accelerated timelines that routinely outpace standard corporate patching routines. The emergence of frontier AI tools has compressed vulnerability discovery from months into a matter of hours, giving attackers the ability to move from initial disclosure to functional exploit code within approximately a week. Meanwhile, the median organization still takes five months to remediate known vulnerabilities. Because patching cannot always keep up, security experts argue that defenders must change how they prioritize risk. Tenable has termed this enduring threat pattern the “Persistently Targeted Vendor,” emphasizing that specific vendor product lines represent the true unit of risk over time.

The study analyzed telemetry from both companies, bringing together exposure metrics across thousands of organizations with real-time endpoint and post-exploitation detection data. The findings reveal that both state-sponsored groups and criminal ransomware operators frequently pull from the same small pool of high-severity flaws. Twelve vulnerabilities within the dataset carried confirmed multi-nexus attribution, meaning state-sponsored and ransomware operators independently exploited the exact same flaw across five threat categories, including China, Russia, DPRK, Iran-nexus and criminal actors.

Specific edge product lines show severe prolonged exposure. For instance, more than half of organizations running F5 products carry at least one exposed, actively exploited vulnerability. In addition, Citrix customers posted the slowest remediation rate among vendors studied, requiring a median of 461 days to fix issues. Remediation complexity on high-priority flaws introduces a statistically significant 24-day gap, which expands the opportunity window for adversaries.

Security leaders emphasize that runtime behavior detection and exposure management must work together to counter these modern vectors. “Speed alone is not enough. By the time a vulnerability hits a remediation queue, adversaries are already iterating the exploit,” said Steve Stone, Chief Customer Officer at SentinelOne. “Static signatures run on human timelines, the threat does not. Runtime behavioral detection has to match that cadence, flagging exploitation patterns as they emerge rather than after the fact.”

Adversaries rely on systemic access rather than isolated exploits. “Attackers systematically target specific vendor ecosystems that could provide access. They aren’t obsessing over single vulnerabilities, and neither should defenders,” said Vlad Korsunsky, Chief Technology Officer, Tenable. “Our joint research confirms that attackers, big and small, target the same attack surfaces the majority of the time. This research underscores exposure management principles: seeing, prioritizing and fixing exposures that create real business risk. As attackers weaponize AI to breach defenses faster, organizations that embrace exposure management will win.”

Defenders looking to adapt can review the full research published on the SentinelOne website to better align their runtime security with exposure data

Leave a Reply

Discover more from Biz Tech Journals

Subscribe now to keep reading and get access to the full archive.

Continue reading