Top attack vectors: September 2021
ID: 47a7fb20-6c98-5109-95e6-e7f42b1c8892
STIX ID: report--47a7fb20-6c98-5109-95e6-e7f42b1c8892
Feed Name: Expel Blog
This September 2021 SOC report highlights three main threats: exploitation of public-facing vulnerabilities (notably CVE-2020-36239 and CVE-2021-26084) repeatedly used to deploy XMRig cryptominers; widespread use of PowerShell and .NET by malware (e.g., SolarMarker) to obfuscate payloads; and a majority of critical incidents being BEC, with attackers increasingly harvesting SSO credentials (Okta) to move into cloud apps — the report provides detection signals and actionable resilience recommendations such as EDR, MFA, PowerShell logging, patching, and WAFs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
