Teetering on the Edge: VPNs, Firewalls' Nonexistent Telemetry Lures APTs
ID: e6c5fd03-33f7-57b4-899d-0f34bcc73e5e
STIX ID: report--e6c5fd03-33f7-57b4-899d-0f34bcc73e5e
Feed Name: Dark Reading
Threat Score
Mandiant's M-Trends analysis reports a shift by China-linked espionage actors toward compromising edge/network appliances (firewalls, VPNs, email gateways) using exploits and native device functionality to evade detection; a bespoke Fortinet-targeting backdoor (BoldMove) and growing exploit-driven initial access and data leak sites were notable trends, and responders face forensic challenges due to limited telemetry and vendor control over device images.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
