Cybersecurity services have released a collaborative study that includes the top 10 front-end attack vectors that malicious users most often exploit to compromise networks.
See also: Armageddon group launches new cyberattack in Ukraine

The research, jointly shared by agencies from the United States, Canada, New Zealand, the Netherlands, and the United Kingdom, includes guidance for mitigating these weak security controls, poor security configurations, and commonly used bad practices.
“Cyber actors systematically exploit poor security configurations (either incorrect or left unpatched), weak controls, and other poor cybersecurity hygiene practices to gain initial access or as part of other tactics to compromise a victim’s system,” the joint advisory.
Attackers also have a few favorite techniques they regularly use to gain initial access to their victims' networks, including exploiting applications exposed to the Internet, exploiting external remote services, phishing , abusing organizations' trust in their partners, and using stolen credentials .
See also: Ransomware: How 2,500 targets turn into 1 real attack

The full list of the top 10 initial access attack vectors targeted by malicious actors while using the above network compromise techniques includes:
- Multi-factor authentication (MFA) is not enforced.
- Incorrectly applied permissions or permissions and errors in access control lists.
- The software is not up to date.
- Using default configurations provided by the vendor or default login usernames and passwords.
- Remote services, such as a virtual private network (VPN), do not have sufficient controls to prevent unauthorized access.
- Strong password policies are not enforced.
- Cloud services are unprotected.
- Open ports and misconfigured services are exposed to the internet.
- Failure to detect or block phishing attempts.
- Poor endpoint detection and response.
See also: US, UK and EU blame Russia for cyberattack on Viasat
The joint advisory also includes a short list of best practices to help protect networks from attacks that target the above weak security controls, misconfigurations, and poor security practices.
It includes the use of access control, hardened credentials (including MFA and changing default passwords), centralized log management, and antivirus and detection tools, including intrusion detection and prevention systems.
It is also recommended that organizations always ensure that services used by the public use secure configurations and that software is kept up to date through a patch management program.
