HomeSecurityIncreased exploitation of vulnerabilities for initial access to networks

Increased exploitation of vulnerabilities for initial access to networks

A new report from Mandiant shows that hackers are moving away from phishing and turning to exploiting vulnerabilities in systems to gain initial access to a network.

exploitation of vulnerabilities

In 2023, attackers gained access through exploiting vulnerabilities in 38% of reported attacks (a 6% increase from the previous year).

Mandiant also found that phishing decreased from 22% in 2022 to 17% in 2023. It is still a major threat, being the second most common initial access.

Zero-Days that were actively exploited

Researchers observed 97 zero-day vulnerabilities being exploited in 2023, (a 56% increase compared to 2022).

See also: Dependency Confusion vulnerability found in Apache Project

Chinese espionage groups have been the most prolific attackers to exploit zero-days . These vulnerabilities are very useful to attackers because they are vulnerabilities that are not known to software vendors, so there are no security patches.

Additionally, financially motivated cybercriminals have also used zero-days to infiltrate systems and steal financial data.

The most frequently targeted vulnerability observed by Mandiant in 2023 was CVE-2023-34362, a SQL injection vulnerability in MOVEit Transfer.

Next is CVE-2022-21587, a critical vulnerability in Oracle E-Business Suite.

In third place was CVE-2023-2868, a critical command injection vulnerability in Barracuda Email Security Gateways.

And while exploits were primarily used for initial access, a Mandiant researcher said phishing is now often used to steal credentials for later attacks. This is partly a result of improved security tools that protect users from receiving malicious emails.

See also: APT28 hackers exploit Windows vulnerability and use GooseEgg tool

The shift towards exploiting software vulnerabilities requires a more sophisticated approach from attackers compared to traditional phishing.

Zero -day and n-day bugs, which have not been discovered or fixed, allow attackers to choose how they attack, at their leisure.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Increased exploitation of vulnerabilities for initial access to networks

Protection from vulnerabilities

awareness and training are crucial. Employees need to be aware of the risks associated with cybersecurity and good practices for avoiding attacks.

Using advanced security solutions, such as intrusion protection systems (IPS), intrusion detection systems (IDS), and antivirus software, can help counter attacks and protect against errors.

See also: MITRE: Hackers breached systems through Ivanti vulnerabilities

Applying updates is one of the most effective ways to protect against security vulnerabilities. Attackers often exploit known vulnerabilities in older versions of software, so keeping your software up to date is crucial.

Using multi-factor authentication (MFA) can provide an extra layer of protection, as it requires users to provide two or more elements to prove their identity.

Finally, creating and implementing an information security policy can prevent the exploitation of vulnerabilities. This policy should include data protection, system and network protection, and response to security breaches.

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS