Home » Emerging Technologies » Cyber Security » Cyberattackers Focus on Vendor Ecosystems, Study Finds
News Desk -

Share

Cyberattackers are increasingly targeting entire vendor ecosystems rather than chasing individual vulnerabilities, according to new joint research from SentinelOne® and Tenable. The study points to a widening gap between how vulnerabilities are discovered and disclosed and how they are actually exploited in the wild.

SentinelOne, the AI security firm listed on the NYSE under the ticker S, and Tenable Holdings, the Nasdaq-listed exposure management company trading as TENB, combined two distinct data sets for the report. Tenable contributed exposure data drawn from thousands of organizations along with remediation telemetry. SentinelOne added endpoint and post-exploitation detection data. Together, the two data sets paint a clearer picture of where cyber risk is building up, with implications for the emerging frontier AI era.

The central finding is straightforward. Both nation-state hackers and criminal groups are zeroing in on vendors and weak points across the attack surface, rather than fixating on specific CVEs. That shift matters because attacker timelines have already outpaced standard patch cycles. New frontier AI models can compress vulnerability discovery from months down to hours. As a result, the time attackers need to move from public disclosure to working exploit code has shrunk to roughly a week. Meanwhile, the median organization still takes five months to remediate known vulnerabilities.

According to the research, exposure data and runtime detection converge on the same edge-device vendor ecosystems 79% of the time. However, that overlap drops sharply to just 21% when measured at the individual vulnerability level. In other words, state-sponsored actors and ransomware operators tend to draw from the same small pool of high-severity, actively exploited flaws. The surfaces stay consistent, even as the actors exploiting them change. Tenable has coined a term for this pattern: the “Persistently Targeted Vendor.” The idea is that a limited set of vendor product lines, not isolated CVEs, represents the more durable and lasting unit of risk over time.

Several other findings stood out. Twelve vulnerabilities in the dataset carry confirmed “multi-nexus” attribution, meaning state-sponsored and ransomware groups have independently exploited the same flaw. That activity spans five distinct threat categories, including China, Russia, North Korea (DPRK), Iran-nexus actors, and financially motivated criminal groups. Separately, more than half of organizations running F5 products, 54%, carry at least one exposed and actively exploited vulnerability. Citrix customers, meanwhile, post the slowest remediation timeline of any vendor studied, at a median of 461 days. That gap illustrates how certain product lines remain exposed long after a fix becomes available. Additionally, remediation complexity on high-priority vulnerabilities adds a statistically significant 24-day delay, further widening the window attackers have to weaponize an exploit.

Steve Stone, Chief Customer Officer at SentinelOne, said speed alone is not sufficient. He noted that by the time a vulnerability reaches a remediation queue, adversaries are already refining their exploit. Static signatures, he added, operate on human timelines, while threats do not. As a result, runtime behavioral detection needs to match that faster pace, flagging exploitation patterns as they emerge instead of after damage is done.

Vlad Korsunsky, Chief Technology Officer at Tenable, echoed that view. He said attackers systematically target specific vendor ecosystems that offer a path to access, rather than obsessing over any single vulnerability. He added that defenders should adopt the same mindset. According to Korsunsky, the joint research confirms that both large and small attackers tend to target the same attack surfaces most of the time. He said the findings reinforce core exposure management principles: seeing, prioritizing, and fixing the exposures that create real business risk. As attackers increasingly weaponize AI to breach defenses faster, he said, organizations that embrace exposure management will come out ahead.

The report builds on an expanding partnership between the two companies. Notably, SentinelOne joined as a founding member of Tenable’s CyberAgents Exchange, which was announced at Black Hat USA 2026. Overall, the collaboration reflects deeper investment from both firms in AI-driven security. As threats targeting vendor ecosystems continue to evolve, the two companies say further joint research will follow. The full report is available at sentinelone.com and tenable.com.