A recent report published by Imperva shows that the healthcare sector and the sites hosted on WordPress were the favorite targets of attacks during the previous year.
The healthcare sector was also hit hard by hackers
The Imperva Web Application Attack Report includes statistical data from the analysis of 297.954 attacks and 22850023 notifications for 198 applications.
The data emphasize that each application suffered an attack from at least 75% of the total possible attack types, showing that the hackers had a diversified portfolio at their disposal during the past year.
XSS and SQLi saw the biggest increase in 2015
Among all attack types, XSS (cross-site scripting) and SQLi (SQL injection) recorded the largest increase compared to last year. XSS attacks increased 3 times compared to last year, while SQLi increased 2.5 times.
The report also shows that, during 2015, there was a large number of blind attacks over the Web, with hackers randomly looking for a way to infiltrate applications.
WordPress, the favorite CMS of all
In addition to healthcare, attackers also show a preference for WordPress powered sites-. This may be related to the large target area they provide, as WordPress has a market share of 25% of all websites on the internet, and a market share of 50% among CMSs.
During 2015, sites hosted on WordPress faced 250 times more attacks than non-CMS sites, but also received 7 times more spam beyond non-CMS sites. Another attack that saw a significant increase for WordPress sites compared to last year was RFI (remote file inclusion), which also increased 7 times.
But attacks on CMS sites, in general, were up 3x more than non-CMS sites. Compared to the previous year, Drupal, Joomla, Magento, and Blogger all saw an increase in hacking activity. The favorite attack vector for attackers was RCE, which was used in 31% of all attacks on CMSs, 41% of all attacks against non-CMSs, 48% for WordPress, 53% of non-WordPress, 35% on PHP Web applications, and 45% on non-PHP.

