For years, firewalls, VPN gateways and other perimeter appliances have been positioned as the systems protecting the enterprise from external threats. Increasingly, they are becoming the way attackers get in.
Recent ransomware activity illustrates a shift that every CISO should take seriously: security infrastructure itself has become a high-value target. Vulnerabilities in Palo Alto Networks, Fortinet, Citrix and Check Point products are being actively targeted because compromising an edge device can provide attackers with exactly what they need — internet exposure, privileged access and a path around endpoint security controls.
The implication for security leaders is significant.
The network perimeter can no longer be considered a trusted security boundary. It should increasingly be treated as hostile infrastructure.
The attacker is moving toward the edge
A recent example is CVE-2026-0257, a critical authentication bypass vulnerability affecting Palo Alto Networks GlobalProtect portal and gateway appliances.
According to Arctic Wolf Labs, the vulnerability was exploited in a series of intrusions associated with Qilin ransomware shortly after public disclosure. The resulting attacks ranged from rapid encryption operations to full double-extortion campaigns.
But this is not about one vulnerability or one vendor.
Qilin has also targeted weaknesses affecting Fortinet FortiGate, Citrix NetScaler and Check Point Remote Access VPN infrastructure. Qilin was reported as the most active threat group during Q2 2026, responsible for approximately 14% of attacks in NCC Group’s quarterly threat intelligence data.
Other ransomware groups are following the same playbook.
The Gentlemen, ranked second in NCC Group’s Q2 data with 238 victims, has been associated with compromises involving firewalls, VPNs and other internet-facing infrastructure. Akira, with 127 reported victims, has similarly used VPN vulnerabilities and legitimate credentials, particularly against Ivanti, Cisco and Fortinet environments.
This pattern matters more than the individual campaigns.
Attackers have understood something that security architectures sometimes still fail to reflect:
The infrastructure designed to provide secure access is itself one of the most attractive paths into the enterprise.
Why edge infrastructure is so attractive
Internet-facing security appliances have several characteristics attackers value.
They must remain reachable from the internet. They often provide access deep into corporate environments. They may hold highly privileged configuration or authentication information. And because they sit outside traditional endpoint environments, compromises may bypass some of the controls and telemetry organisations have spent years developing around workstations and servers.
Recorded Future’s Alexander Leslie described perimeter devices as particularly valuable because they are continuously internet exposed and may provide privileged access while bypassing endpoint controls.
This creates an uncomfortable architectural reality.
An organisation may have excellent endpoint detection, hardened laptops, application control and sophisticated SOC monitoring – yet an unpatched or poorly monitored VPN gateway can provide an attacker with an entirely different route into the environment.
That is why edge security should no longer be treated primarily as a networking problem.
It is a cyber risk problem.
And therefore, it belongs directly on the CISO agenda.
Vulnerabilities are only half of the problem
There is another important lesson in the recent attacks.
Not every successful VPN compromise requires a zero-day.
Attackers frequently use stolen credentials against exposed remote-access infrastructure, particularly where strong MFA is absent.
Huntress reported that VPN infrastructure represented the initial-access point in around 70% of cases involving advanced threat actors seen by the company. More importantly, the majority of those incidents were not based on vulnerability exploitation. Attackers were authenticating using compromised credentials, often against accounts without MFA.
This distinction is essential.
CISOs often concentrate heavily on vulnerability management:
Is the appliance patched?
But the more complete question is:
If an attacker had a valid username and password today, what would stop them?
If the answer depends primarily on that password, the security model is already fragile.
The modern perimeter therefore has two simultaneous risks:
software compromise through vulnerabilities and identity compromise through stolen credentials.
Both must be addressed together.
The 30-day patching model does not work at the edge
Traditional enterprise vulnerability-management programmes frequently operate around monthly patching cycles, severity classifications and remediation SLAs.
That model becomes increasingly difficult to defend for exposed infrastructure.
In the GlobalProtect example, exploitation reportedly began within days of disclosure. Security teams therefore had only a very small window between vulnerability awareness and active attacker exploitation.
For critical internet-facing infrastructure, vulnerability management must therefore become threat-informed rather than calendar-driven.
The recommendation by CISOnode.com is aggressive: critical edge-device updates may need to be applied within 24 to 48 hours, particularly where active exploitation is known.
For many organisations, this requires more than changing an SLA in a policy document.
It requires the operational capability to actually patch within that timeframe.
That means identifying owners, testing emergency changes, maintaining support contracts, understanding dependencies, having rollback procedures and ensuring that critical security infrastructure can be upgraded without creating unacceptable business disruption.
A theoretical 24-hour SLA without the capability to execute it provides little security.
The CISO action agenda
The response should not be to abandon VPNs or edge security infrastructure. These technologies remain necessary in many architectures.
The objective is to stop treating them as inherently trusted security controls.
1. Identify every internet-facing security asset
The CISO should be able to answer a simple question:
What security infrastructure is exposed to the internet right now?
That includes VPN gateways, firewalls, remote-access portals and other externally accessible management or security interfaces.
Unknown exposure is unmanaged risk.
2. Separate edge patching from normal patching
A vulnerability in an internal application server and a remotely exploitable vulnerability in an internet-facing VPN gateway do not present the same risk.
Threat intelligence, active-exploitation evidence and internet exposure should directly influence remediation priority. This is also the approach recommended in the source reporting.
3. Make phishing-resistant MFA the default
If attackers increasingly use legitimate credentials instead of exploits, password security alone is insufficient.
Strong MFA – ideally phishing-resistant authentication for privileged and remote access – should be treated as part of perimeter security, not merely identity governance.
4. Assume the gateway can be compromised
Zero trust becomes particularly relevant here.
If a VPN or firewall is compromised, the architecture should still limit what an attacker can reach.
Network segmentation, restricted administrative paths and controlled lateral movement can transform an edge compromise from an enterprise-wide incident into a contained security event.
5. Monitor the security controls themselves
Security appliances should not disappear into the infrastructure simply because they are security products.
Authentication anomalies, administrative activity, configuration changes, new privileged accounts and unusual network behaviour around edge systems deserve the same — and arguably greater — monitoring attention as critical servers.
Security products are not inherently secure
There is a broader leadership lesson here.
Organisations often invest heavily in new cybersecurity technologies while assuming that the security products themselves form part of the trusted foundation.
Attackers do not share that assumption.
They see a firewall as software.
They see a VPN gateway as an internet-facing application.
They see an administrative interface as an opportunity.
And they see credentials as credentials, regardless of whether those credentials provide access to Microsoft 365, a workstation or the organisation’s primary remote-access gateway.
That mindset should influence how CISOs design security architectures.
A security control should never automatically become a trust anchor merely because its purpose is security.
From perimeter defence to perimeter resilience
The perimeter is not disappearing.
It is changing.
Cloud adoption, remote access, hybrid infrastructure and distributed services have made the traditional concept of a single corporate boundary increasingly irrelevant. Yet organisations still operate numerous internet-facing systems that provide privileged paths into internal environments.
Those systems must be designed with the assumption that one day they may be compromised.
For the CISO, the question is therefore no longer:
“How strong is our perimeter?”
The more useful question is:
“What happens when one component of our perimeter fails?”
If the answer is lateral movement, privileged access and ransomware propagation, the organisation does not have a perimeter problem.
It has a resilience problem.
And that is exactly where modern cybersecurity strategy needs to focus.
