The record
Written from the 1 report below. Nothing here is unsourced.
- Cyber attackers increasingly favour repeatable, standardised attack playbooks over inventing new techniques, according to security researchers at Microsoft and Bitdefender.
- ClickFix, a trick where a webpage convinces users to paste a malicious command into their own terminal, was the most common initial access method Microsoft observed last year, accounting for 47% of the attacks in its notifications.
- Bitdefender's analysis of 700,000 security incidents found 84% of high-severity cases involved administrative tools already present on the victim's machine, with nothing malicious installed.
- Verizon's latest Data Breach Investigations Report shows exploitation of vulnerabilities rose to 31% of breaches, up from 20% the previous year, because it rewards scanning at volume over skill.
- The shift matters because it means attackers are competing on throughput and consistency like a business, as seen in ransomware groups Qilin and The Gentlemen trading the top spot on leak-site leaderboards with recycled playbooks.
What to watch next
- New CVEs in internet-facing devices that allow unauthenticated remote code execution, since proof-of-concept code often appears on GitHub within days.
- Whether ransomware playbooks continue to be recycled and improved by former affiliates, as happened when The Gentlemen emerged from a Qilin affiliate.
- Whether organisations deploy protections against ClickFix-style social engineering, since no patch or signature exists for a person being talked through pasting a command.
Coverage1
1 report
English national1
All filed from India
Named United States · GitHub · Bitdefender · Microsoft · Qilin · The Gentlemen · Verizon
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
