logo

Teetering on the Edge: VPNs, Firewalls' Nonexistent Telemetry Lures APTs

ID: e6c5fd03-33f7-57b4-899d-0f34bcc73e5e

STIX ID: report--e6c5fd03-33f7-57b4-899d-0f34bcc73e5e

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-04-23

Date Updated: 2026-04-21

Author: Robert Lemos, Contributing Writer

...
...

Mandiant's M-Trends analysis reports a shift by China-linked espionage actors toward compromising edge/network appliances (firewalls, VPNs, email gateways) using exploits and native device functionality to evade detection; a bespoke Fortinet-targeting backdoor (BoldMove) and growing exploit-driven initial access and data leak sites were notable trends, and responders face forensic challenges due to limited telemetry and vendor control over device images.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.