
II Cyber Warfare & Critical Infrastructure·Analysis·Asia-Pacific
Edge devices become a shared doorway as patch windows shrink to three days
In September, 43 entries joined CISA's list of exploited vulnerabilities, 18 of them network and edge products. The median federal patch deadline fell from 21 days to three, while cyber insurance prices have fallen for 12 quarters.
Cyber & Critical Infrastructure Desk · 2 October 2026 · 6 min read · 17 sources
Why it matters
Edge devices, the VPN, gateway and SD-WAN boxes linking networks to the internet, are now pressed by state-linked spies and ransomware gangs alike. In September 2026, 43 exploited flaws joined the CISA catalogue, about 2.7 times the 16 a year earlier; 18 were edge products. The median federal patch deadline fell from 21 days to three, but binds only US federal agencies. In Asia, 350 devices were breached in eight countries; Gulf attack attempts quadrupled. Yet cyber insurance prices fell 4% in Q2 2026 and the VIX is 16.39. The risk is not yet priced.
Implications
- In September 2026, 43 vulnerabilities joined the CISA KEV catalogue, against 16 in September 2025. Of the 43 entries, 18 came from network and edge products such as Cisco, Citrix, Fortinet, SonicWall and Check Point.
- The median federal patch deadline in KEV was 21 days in 2025 and fell to three days in 2026. The deadline for the Cisco SD-WAN Manager flaw is 3 October.
- According to the Marsh index, global cyber insurance prices fell 4% in the second quarter of 2026, extending the decline to a 12th quarter. Attack intensity has not yet reached premiums.
One week, two kinds of attacker, one layer
Over four days from 27 to 30 September, the US Cybersecurity and Infrastructure Security Agency (CISA) added four entries to its catalogue of vulnerabilities proven to be used in attacks (KEV). Three of them were products at the edge of the network. Edge devices are the boxes that connect an organisation's network to the internet, such as gateways, VPNs, routers and SD-WAN appliances.
Citrix disclosed two NetScaler flaws rated 9.5 on 27 September. According to Help Net Security, they had been exploited for weeks before the announcement. The attackers dropped web shells and wiped their traces, and the source described the operation as probable state-linked espionage. On 30 September came Cisco's SD-WAN Manager flaw, rated 9.8. Rapid7 says it is the product's fifth zero-day of 2026.
The same week was busy on the ransomware side too. On 30 September, a Europol-backed operation took down five servers belonging to the KillSec gang. Since 2024 the gang had carried out about 1,000 attacks, 500 of them successful. It has not been disclosed which entry route KillSec used in those attacks. CISA data do show, however, that 6 of the 56 edge product entries added to the catalogue in 2026 are flagged as used in ransomware campaigns.
The patch window has shrunk to three days
Our calculation from the KEV catalogue shows that the 245 vulnerabilities added in 2025 had a median federal patch deadline of 21 days. For the 247 added in 2026 up to 1 October, the median fell to three days. In 124 entries the deadline is three days or less, compared with seven in 2025.
Volume has grown alongside speed. In September 2026, 43 vulnerabilities joined the catalogue, about 2.7 times the 16 of September 2025 and the highest month of the year. Of the 43 entries, 18 come from Cisco, Citrix, Fortinet, SonicWall, Check Point, F5, MikroTik, Zyxel and Arista products. The deadline for the Cisco SD-WAN flaw is 3 October. Because a single HTTP request grants administrator rights, three days is not too little; it is necessary.
The problem is that the three-day window binds only US federal agencies. Private companies and public bodies in other countries can face the same flaw within the same three days, but they are under no obligation to meet that deadline. In the Citrix case, exploitation began weeks before disclosure. When the window opened, some networks were therefore already living with an attacker inside.
Geopolitics widens the attack surface
According to Cisco Talos, the China-linked group UAT-11587 planted the Antino backdoor on about 350 devices in eight countries between September 2025 and July 2026. Targets included defence, foreign affairs and think-tank organisations in Taiwan, India, the Philippines and Pakistan. The Record reports that the campaign was spotted in March 2026 through targeted emails. The backdoor takes commands via Microsoft 365 every 10 seconds.
The identity layer is on the same list. Proofpoint says the pro-China group TA419 has impersonated a former White House science policy official since 8 July. It sent fake advisory board invitations to AI policy experts. According to The Register, the group had also impersonated an Anthropic executive in February 2026. One of its two fake offers was a fictitious Senate report on AI export controls. As this field becomes a bargaining chip, its experts become targets too.
The energy crisis and the war are having the same effect in the Gulf. A CloudSEK report cited by The National shows ransomware listings in the region rising from 17 in April 2025 to 357 in June 2026. In the UAE, daily attack attempts climbed from 200,000 before the war to about 800,000.
The cost accounting has not caught up
The ransomware attack on Keio on 26 September did not stop its trains. It did, however, cut card payments at its supermarkets, hotels and bus ticket counters. At Times Car, driving licence and identity data for 6.6 million accounts leaked. In Türkiye, the data protection authority KVKK announced nine breaches on 30 September. Across the cases with disclosed figures, at least 1,033,853 people were affected, and the Papara Menkul breach began with Okta-targeted phishing.
Insurance prices are moving the other way. According to the Marsh index, global cyber insurance prices fell 4% in the second quarter of 2026, the 12th consecutive quarter of decline. In the India, Middle East and Africa region the fall was 14%. Marsh attributes the decline to ample capacity, low reinsurance costs and strong profitability. September's 43 exploited vulnerabilities are not yet in this pricing.
Financial markets are calm as well. Cboe data show the VIX volatility index at 16.39 on 1 October. That calm suggests cyber risk is still confined to the balance sheets of individual companies and insurers. It has not moved into the systemic risk premium.
What to watch
Three indicators stand out for the next three months. The first is whether the monthly number of edge products added to KEV stays above September's 18. The second is whether Marsh's third-quarter index extends the fall in cyber prices to a 13th quarter. The third is the financial sector's share in KVKK's breach announcements, which continued with nine breaches on 30 September.
The gap between a three-day patch tempo and insurance prices that have fallen for 12 quarters will not stay open for long. When it closes, the cost will show up first in premiums and deductibles. After that it will reach regulators' patching and notification timetables.
Probabilities
Scenarios
| Scenario | Probability | Trigger | Market impact |
|---|---|---|---|
| H1High tempo, limited pricing | 55% | KEV keeps adding 15–20 edge product entries a month in October, but no incident causes a service outage in critical infrastructure. | The cost stays in organisations' IT budgets and individual breach expenses. The fall in insurance prices slows but does not reverse. |
| H2An edge incident becomes a systemic cost | 30% | A flaw in a widely used VPN or SD-WAN product causes simultaneous outages at several organisations in energy, transport or finance. | Insurers make edge device patching a policy condition, and regulators extend notification and patch deadlines to the private sector. |
| H3The tempo eases | 15% | September's 43 entries prove a one-off, and monthly KEV volume in October and November falls below the 2026 average of about 25. | Pressure on the patch window eases, and organisations get a chance to close accumulated flaws outside the three-day timetable. |
Module A
Constraints Matrix
STRUCTURAL AVG 4.0 · TACTICAL AVG 2.5Structural constraints dominate: the outcome is set more by these limits than by the actors' preferences.
Hard structural constraintspersistent · beyond the actors' will
Exploitation before disclosure
5/5Two Citrix NetScaler flaws rated 9.5 were exploited weeks before disclosure. When the patch window opened, some networks had already been compromised.
Patch mandate is federal only · United States
4/5KEV's three-day median deadline binds only US federal civilian agencies. The private sector and other countries face the same flaw with no obligation.
Geopolitical target selection · China
4/5UAT-11587 targeted defence, foreign affairs and think-tank organisations in eight Asian countries. TA419 went after AI policy experts with impersonated invitations.
Legacy version burden
3/5Cisco SD-WAN Manager versions older than 20.9 have no patch and need migration. That work does not fit into a three-day timetable.
Tactical frictiontemporary · eases over time
Commercial IT disruption days
3/5The 26 September attack on Keio did not stop trains, but it disrupted card payments, hotel bookings and bus ticket counters for more than two days.
Insurance prices lag months
3/5Cyber insurance prices fell 4% in the second quarter of 2026, the 12th consecutive quarterly decline. Premiums trail the attack tempo by one to two quarters.
Attribution uncertainty weeks
2/5The Cisco SD-WAN attacker has not been tied to a group. Neither KillSec's entry route nor UAT-11587's non-email entry method has been disclosed.
Fragmented disclosure weeks
2/5KVKK announced nine breaches on 30 September, but no headcount was given for the Papara Menkul breach. The full scale is not visible.
Module B
Signal vs Noise
SIGNAL 60% · NOISE 40%
- SIGNAL
Both the volume and the speed of exploited flaws have risen
In September 2026, 43 vulnerabilities joined KEV, against 16 in September 2025. The median patch deadline fell from 21 days to three.
- SIGNAL
Edge products hold a permanent place in the catalogue
Of September's 43 entries, 18 were network and edge products. The fifth zero-day of 2026 in Cisco SD-WAN Manager was exploited on 30 September.
- SIGNAL
The AI policy community is on the target list
TA419 has impersonated a former White House official since 8 July. UAT-11587 breached about 350 devices in eight countries.
Data: USD/CNY ›The Record — Researchers find Chinese hacking campaigns targeting AI firms, Asian governments
- NOISE
The KillSec operation has reduced ransomware risk
The operation took down five servers, but Keio was attacked the same week. CISA linked 6 of 56 edge entries in 2026 to ransomware campaigns.
BleepingComputer — Police dismantle KillSec ransomware gang allegedly led by 16-year-old
- NOISE
A low VIX shows cyber risk is insignificant
The VIX was 16.39 on 1 October. The same week, 6.6 million Times Car accounts leaked and KVKK announced nine breaches in a single day.
Data: VIX volatility index ›Cboe — VIX Index historical data
Module C
Asset-Class and Positioning Implications
| Asset class | Exposure | Transmission channel | H1 | H2 | H3 | Expected | Conviction | Horizon | What to watch |
|---|---|---|---|---|---|---|---|---|---|
| Volatility | US equity volatility | Simultaneous outages in critical infrastructure move cyber risk from isolated losses to a market-wide risk premium | 0 | ++ | − | +0.45 | ●●● | 0–3 months | The 20 threshold on the VIX and the number of edge products added to KEV |
| Equities | Insurers writing cyber cover | If 12 quarters of price declines meet a rising attack tempo, loss ratios deteriorate | − | −− | + | −1.00 | ●●● | 3–12 months | The change in cyber prices in Marsh's third-quarter index |
| Equities | Network security and patching service providers | The three-day patch timetable and insurance conditions bring security spending forward | + | ++ | 0 | +1.15 | ●●● | 3–12 months | Monthly KEV volume and new patching mandates for the private sector |
| Equities | Japanese transport and consumer services | The Keio and Times Car incidents turn payment and identity data disruption into operating costs | − | −− | 0 | −1.15 | ●●● | 0–3 months | The date Keio's payment systems fully reopen and new ransomware claims |
| FX | Yuan | Attributions of China-linked espionage add further strain to US–China technology bargaining | 0 | − | 0 | −0.30 | ●●● | 0–3 months | AI export controls and new cyber attribution statements aimed at China |
Second-order effects
And then what?
Starting point
In September 2026, 43 exploited vulnerabilities joined the CISA KEV catalogue, 18 of them network and edge products. The median federal patch deadline fell to three days, and the Citrix flaws were exploited weeks before disclosure.
- 1
Operational costwithin days
Attackers entering through unpatched edge devices cause outages in the commercial IT layer. Incidents such as Keio's payment outage and the Times Car leak of 6.6 million accounts turn directly into operating costs.
Watch: KVKK's weekly breach announcements and the number of edge entries added to KEV
- 2
Insurance and reinsurancewithin months
As claims pile up, cyber insurance prices that have fallen for 12 quarters bottom out. Insurers make edge device patching and multi-factor authentication a policy condition.
Watch: Cyber prices in Marsh's third-quarter index departing from the 4% decline
- 3
Regulationwithin months
Insurers' conditions become regulators' timetables. The three-day patch rule for US federal agencies and the EU's 24-hour notification deadline spread to the private sector and supply chains.
Watch: New patching and notification mandates for the private sector; the financial sector's share of KVKK breach announcements
What breaks the chain
If monthly KEV volume in October and November falls below the 2026 average of about 25 and no major service outage occurs, the second link does not form. Ample reinsurance capacity would also delay a turn in insurance prices.
Triggers
Thresholds to watch
| Indicator | Threshold | Today | What it means |
|---|---|---|---|
| VIX volatility index | > 20 | 16.34 | A move above this threshold from 16.39 on 1 October would show an edge device or ransomware incident turning from a single company's loss into a market-wide risk premium. |
Sources
- CISA — Known Exploited Vulnerabilities Catalog (CSV)
- Cisco Talos — China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
- The Record — Researchers find Chinese hacking campaigns targeting AI firms, Asian governments
- The Register — Suspected Chinese spies spoofed an Anthropic exec, ex-White House official in AI phishing
- Rapid7 — Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)
- The Hacker News — Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
- Help Net Security — Citrix NetScaler RCE zero-days exploited for weeks
- Rapid7 — Zero-day exploitation of Citrix NetScaler ADC and Gateway
- BleepingComputer — Police dismantle KillSec ransomware gang allegedly led by 16-year-old
- BleepingComputer — Apple patches CoreGraphics zero-day flaw exploited in attacks
- Memurlar.net — KVKK publishes data breaches at 9 companies, affecting 1 million people
- Carrier Management — Marsh Global Insurance Market Index, Q2 2026
- Insurance Edge — Commercial insurance rates are falling, says new report from Marsh
- The National — Ransomware activity rises across Middle East as criminal groups attack Gulf
- BleepingComputer — Japan's Keio confirms ransomware attack disrupted business systems
- BleepingComputer — Times Car confirms data breach affecting 6.6 million user accounts
- Cboe — VIX Index historical data
Sourcing and verification rules: methodology · Report an error: contact
Related reports
VTech & AI·Analysis·Asia-Pacific
Beijing now has the final say on chip sales to China
The US granted H200 licences to 10 Chinese companies in May, but shipments have not begun. On 27 September Beijing signalled approval for the RTX Pro 5500, a chip of its own choosing; ByteDance is reported to be considering about 1 million units.
Technology Geopolitics Desk · 29 September 2026 · 6 min
VTech & AI·Analysis·Asia-Pacific
TSMC makes promises to Arizona as packaging capacity gathers in Taiwan
Against TSMC's 265-billion-dollar Arizona plan, Taiwan has approved 44 billion dollars since 2020. In the same week the way opened for 5 new packaging plants in Chiayi, where the park's target is 10 facilities.
Technology Geopolitics Desk · 28 September 2026 · 5 min
VTech & AI·Analysis·Asia-Pacific
Xi–Trump summit ends with a two-month truce: decisions on chips, Taiwan and artificial intelligence deferred to 10 January
No joint statement emerged from the 24 September summit. The tariff truce had been extended a day earlier from 10 November to 10 January; no signed decision was announced on tariff cuts, new chip licences, the Taiwan package or an AI incident hotline.
Technology Geopolitics Desk · 25 September 2026 · 8 min