惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Jina AI
Jina AI
博客园 - 司徒正美
大猫的无限游戏
大猫的无限游戏
博客园 - 三生石上(FineUI控件)
J
Java Code Geeks
博客园 - 聂微东
酷 壳 – CoolShell
酷 壳 – CoolShell
爱范儿
爱范儿
美团技术团队
腾讯CDC
博客园 - Franky
MyScale Blog
MyScale Blog
人人都是产品经理
人人都是产品经理
罗磊的独立博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
aimingoo的专栏
aimingoo的专栏
博客园_首页
V
V2EX
Martin Fowler
Martin Fowler
T
The Blog of Author Tim Ferriss

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Verizon DBIR: Vulnerability Exploits Overtake Credentials...
Phil Muncaster · 2026-05-20 · via www.infosecurity-magazine.com

Vulnerability exploitation has overtaken compromised credentials for the first time in nearly two decades as the most common initial access vector for data breaches, according to Verizon.

The tech giant’s Data Breach investigations Report (DBIR) has been providing threat landscape insight to industry professionals for 19 years, based as it is on a variety of Verizon, incident response, law enforcement and industry data on real breaches and incidents.

The latest edition revealed that nearly a third (31%) of data breaches over the past year started with vulnerability exploitation. This is up from 20% in last year’s report.

That made it the top initial access vector, with credential abuse down from 22% to 13%.

Read more on the DBIR: Verizon DBIR: Small Businesses Bearing the Brunt of Ransomware Attacks

Verizon suggested the figures could indicate that AI is already being used by threat actors to find and exploit more vulnerabilities.

However, it’s not just zero-days that are at issue. The report revealed that firms aren’t patching known bugs quickly enough.

Only 26% of critical vulnerabilities listed in the Cybersecurity Infrastructure and Security Agency Known Exploited Vulnerabilities (CISA KEV) catalog were fully remediated by organizations in 2025, a drop from 38% the previous year.

That could be due to the increased patch load. Organizations had 50% more critical vulnerabilities to patch in this year’s reporting dataset versus 2025, Verizon said.

Jon Baker, VP of threat-informed defense at AttackIQ, said organizations are struggling to prioritize patches.

“Security teams are being asked to fix more critical issues, but they still need to know which ones actually create a path to compromise,” he argued. “A vulnerability on paper is one thing, but a vulnerability that can be chained into lateral movement, ransomware deployment, or data theft is something else entirely.”

Patrick Münch, CSO at vulnerability management services firm Mondoo, said manual remediation is letting firms down. “You don't close the gap with another scanner,” he added. “You close it with transparent agentic AI: humans in the loop on decisions, AI automation on remediation and mitigation execution, and a clear audit trail from identifying the issue to verifying it's fixed.”

AI Threats to the Fore of the Verizon DBIR

AI is more obviously growing as a threat in other parts of the report.

“The median threat actor researched or used AI assistance in 15 different documented techniques, with some actors leveraging as many as 40 or 50,” it noted.

Shadow AI is also a growing enterprise threat: it’s now the third most common “non-malicious insider action” detected in Verizon’s data loss prevention (DLP) dataset, a fourfold percentage increase from last year.

Some 45% of employees are now regular users of managed and unmanaged AI on their corporate devices, up from 15% last year.

Supply Chains and Social Engineering

Elsewhere in the report, mobile users were targeted more frequently by social engineering attacks over the past year, as individuals got better at spotting phishing attempts via other channels.

In phishing simulations, the median rate of successful “click” rates in mobile vectors like voice and text is 40% higher than via email, Verizon claimed. The “human element” was present in 62% of breaches, up slightly from 60% last year.

Supply chain-related breaches also surged, by 60% annually, to account for nearly half (48%) of all data breaches recorded in the report.

Just 23% of third-party organizations fully remediated missing or improperly secured multifactor authentication (MFA) on their cloud accounts. For weak passwords and permission misconfigurations, time to resolve 50% of all findings reached almost eight months.

As a share of breaches, ransomware nudged up from 44% last year to 48% this, but 69% of victims elected not to pay, squeezing threat actor margins.