Most people assume there’s a clean line between nation-state hackers and run-of-the-mill cybercriminals. One side runs quiet, patient espionage campaigns against strategic targets. The other side sprays ransomware at whoever forgot to patch. Different budgets, different goals, different playbooks. A new joint study from Tenable and SentinelOne says that line is a lot blurrier than most security teams assume, and it matters for how you think about cybersecurity at your own organization, because state-backed crews and criminal gangs are increasingly picking the exact same vulnerable edge devices to break in through.
That’s not a coincidence. It’s a signal about where the easy wins are, and it should change how you prioritize your defenses.

The Assumption That’s Costing You
The comfortable mental model goes like this: if you’re not a defense contractor, a utility, or a government agency, sophisticated state actors aren’t your problem. You worry about ransomware crews and opportunistic scanners, and you leave the exotic threat modeling to whoever handles critical infrastructure. That framing has always been a little too tidy, but the Tenable and SentinelOne data makes it hard to defend at all. Two independent research teams, looking at two different datasets, landed on the same conclusion: VPN gateways, firewalls, and other perimeter devices with known, exploitable flaws get hit by everyone. State-sponsored operators and financially motivated crews are frequently going after the identical CVE, sometimes within days of each other, because the vulnerability doesn’t care who’s exploiting it.
If your firewall or edge appliance has an unpatched flaw, you’re not choosing your adversary. You’re choosing whichever one gets there first.
What “Convergence” Actually Means for Threat Detection
Convergence isn’t just a research curiosity. It changes the math on threat detection and incident response. Security teams that build separate playbooks for “APT scenario” and “commodity ransomware scenario” are optimizing for a distinction that increasingly doesn’t hold at the point of initial access. The exploit doesn’t announce its author. A webshell dropped through an unpatched edge device looks the same in your logs whether it was planted by a state-sponsored operator doing reconnaissance or a criminal affiliate setting up for a ransomware deployment three weeks later.
This is also why takedowns and arrests don’t move the needle as much as headlines suggest. The DOJ’s disruption of the China-linked QTFY infrastructure, and the modular GoCaracal framework that Dark Caracal just added to its espionage toolkit, both point at the same underlying reality: infrastructure and tooling get rebuilt faster than defenders can chase individual actors. The vulnerability is the constant. The attacker attribution is the variable, and it’s often irrelevant to your response.
The Perimeter Is Bigger Than You Think It Is
Part of what makes edge infrastructure such an attractive convergence point is sheer volume. Chrome’s latest update patched 327 separate vulnerabilities, some of which could be triggered just by visiting a malicious page. Adobe and Nvidia both shipped advisories this week covering dozens more flaws across widely deployed software. Kaspersky’s Q2 2026 exploit report, for the first time, started tracking vulnerabilities in open-source AI agents and frameworks as their own category, because that attack surface has grown large enough to matter. Every one of these products sits at some edge of your environment, whether that’s a browser rendering untrusted content, a design tool parsing untrusted files, or an AI agent framework nobody remembers deploying.
None of this requires a nation-state budget to exploit. It requires patience, automated scanning, and a target that hasn’t gotten around to patching. That’s exactly the profile both sides of the convergence share.
A Defense-in-Depth Playbook That Doesn’t Assume You Know Your Attacker
The practical response to convergence isn’t more attribution research. It’s building layered defenses that don’t depend on correctly guessing who’s on the other end of the connection. A few concrete moves matter more than others here:
- Inventory every internet-facing device, not just your obvious perimeter. VPN concentrators, firewall management consoles, and edge appliances are the common thread in the Tenable/SentinelOne data. If you can’t list every device with a public IP, you can’t prioritize patching them.
- Patch edge infrastructure on a faster cycle than internal software. A device sitting at your perimeter with a known exploited vulnerability is a race against every actor scanning for it, not just the sophisticated ones.
- Assume brute-force and credential-stuffing attempts against exposed management interfaces are constant background noise, and log them as a security hardening baseline, not an afterthought. Dynamic blocking of repeat offenders at the network layer buys time that manual review never will.
- Separate detection logic from attribution. Your SOC playbooks should trigger on behavior, unusual outbound connections, unexpected admin logins, new scheduled tasks, not on a guess about who’s responsible. Threat detection tuned to behavior catches both a criminal affiliate and a state operator using the same technique.
- Build incident response plans that assume dwell time before ransomware deployment. Access brokered by one actor is frequently resold or handed to another. A quiet foothold today can become a loud problem next month.
None of this is exotic. It’s defense in depth applied with the assumption that your adversary pool is wider and less predictable than your org chart suggests.
Why the Line Between Spy and Criminal Keeps Fading
There’s a broader industry story running underneath this too. The NSA’s decision to host a reunion for former Tailored Access Operations members, as it rebrands the unit, is a reminder that offensive cyber talent moves between government and private life constantly. Skills, tools, and sometimes actual code migrate across that boundary in both directions. Meanwhile, AnonyMousKIT, a phishing-as-a-service platform automating Apple ID theft with AI voice calls, shows criminal tooling has gotten sophisticated enough to mimic techniques once associated with more resourced operations. The gap in capability between “state actor” and “well-funded criminal crew” is shrinking from both directions at once.
That’s the real takeaway buried in the Tenable and SentinelOne research. It’s not that spies have started acting like criminals or vice versa. It’s that the vulnerable edge device doesn’t discriminate, and neither should your defenses.
Frequently Asked Questions
- Does this mean small organizations face the same risk as government agencies?
- Not identical risk, but overlapping risk at the point of initial access. If your edge devices carry the same unpatched vulnerability as a government network, automated scanning by either type of actor will find you just as easily.
- Should incident response plans differ based on suspected attacker type?
- The initial response, containment, evidence preservation, and access review, should stay consistent regardless of attribution. Attribution can inform later strategic decisions, but it shouldn’t slow down the first 24 hours of response.
- What’s the single highest-value fix for this kind of convergence risk?
- Faster patch cycles specifically for internet-facing edge infrastructure. That’s the common entry point both state and criminal actors are shown to exploit, so shrinking that window closes the door to both at once.
Sources
- Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who’s Exploiting Your Perimeter
- Dark Caracal Adds New Malware to Cyber Espionage Arsenal
- FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
- Exclusive: NSA to host a hacker reunion in bid to rebuild secretive unit
- Update Chrome before you browse again
- Exploits and vulnerabilities in Q2 2026
- Adobe and Nvidia Patch Dozens of Vulnerabilities
- AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
