The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a Binding Operational Directive (BOD) ordering federal civilian agencies to identify and remove end-of-life/end-of-service (EOS), internet-facing edge devices—citing widespread active exploitation by sophisticated threat actors, including activity with ties to nation-states. CISA warned that unsupported devices remain in service long after vendors stop providing firmware and security updates, making them persistently vulnerable to exploitation and a recurring entry point for high-impact intrusions.
The directive requires agencies to inventory unsupported edge devices within three months, decommission/replace identified EOS devices on an accelerated timeline (reported as within one year for removal), and establish ongoing processes for continuous discovery/monitoring to prevent unsupported technologies from re-entering networks. Device categories called out include common perimeter and network infrastructure such as firewalls, routers, load balancers, switches, wireless access points, network security appliances, and IoT edge devices; CISA is also producing a government-wide list of EOS edge devices to guide compliance. Officials emphasized the action is not tied to a single incident, but reflects the sustained risk and observed exploitation of unsupported edge infrastructure across federal environments, while encouraging non-federal organizations to adopt similar practices.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CISA created an end-of-support edge device list to help agencies identify affected products, versions and support dates, but said the list would not be published publicly. The agency said it developed the directive with OMB and would track agency compliance while providing implementation support such as guidance and reporting templates.
The directive requires agencies to inventory end-of-support edge devices within three months, decommission or replace unsupported devices within one year, and establish an ongoing process within two years to identify devices approaching or reaching end of support. It also calls for immediate upgrades where hardware is still vendor-supported but running unsupported software, when operations will not be disrupted.
On Feb. 5, CISA issued Binding Operational Directive 26-02 ordering U.S. federal civilian executive branch agencies to address end-of-support edge devices because of widespread exploitation risk. The agency said unsupported internet-facing devices such as firewalls, routers, load balancers and similar perimeter systems are being targeted by advanced and in some cases nation-state-linked actors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcecsoonline.com
Open sourcenextgov.com
Open sourcetherecord.media
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.