Expel Quarterly Threat Report Q3: Top 5 takeaways
ID: e6773c65-6f3f-5eb8-b11a-02ae14d80067
STIX ID: report--e6773c65-6f3f-5eb8-b11a-02ae14d80067
Feed Name: Expel Blog
Q3 2022 Quarterly Threat Report: SOC analysis shows identity-based attacks (credential theft, credential abuse, and long-term access key theft) comprised ~60% of incidents, with BEC/BAC responsible for 55% of events and all BEC incidents observed in Microsoft 365; MFA push-notification fatigue is an increasing cause of successful compromises. Attackers frequently use U.S.-geolocated VPN/hosting IPs to bypass conditional access, and ransomware groups favor zipped JavaScript and ISO attachments over VBA/Excel macros as initial vectors; common phishing subject themes include blank subjects and payment/invoice lures. The report provides practical mitigations such as enforcing stronger MFA (FIDO/number matching), monitoring IP organizations, and updating detection for zipped JS/ISO payloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
