CVE Tools

Через что вас взломают: векторы атак, zero-day, OWASP Top 10 и самые дорогие уязвимости в истории

Хабр — Информационная безопасностьBy HACKERMAN

Research

Our summary

The article reviews how attackers most often gain access, emphasizing that exploitation of known but unpatched vulnerabilities has become the leading driver of successful compromises. It specifically calls out longstanding high-impact issues such as CVE-2021-44228 (Apache Log4j 2 “Log4Shell”), CVE-2020-1472 (Microsoft Netlogon “Zerologon”), and Citrix edge exposure CVE-2023-4966, while also noting zero-day examples like CVE-2019-0708 (Windows RDP “BlueKeep”) and CVE-2018-20250 (WinRAR). The takeaway is that rapid patching and hardening—especially for perimeter and web-facing systems—directly reduce the window of mass exploitation and the likelihood of domain-wide takeover.

Read at Хабр — Информационная безопасность

Хабр — Информационная безопасность publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store