logo

Picus Security Finds 46% of Enterprise Passwords Vulnerable to Cracking — 2X Increase from 2024

ID: d7139ed1-1052-597d-a3b1-4c7dd54c464f

STIX ID: report--d7139ed1-1052-597d-a3b1-4c7dd54c464f

Feed Name: Resources-2

Threat Score
70/100

Date Published: 2025-08-11

Date Updated: 2026-07-22

Author: Picus Labs

...
...

Picus Security’s Blue Report 2025 analyzes more than 160 million simulated attacks and finds sharp declines in defensive effectiveness: 46% of environments had at least one cracked password hash, attacks using valid credentials succeeded 98% of the time, and only 3% of data exfiltration attempts were blocked. The report calls out rising infostealer prevalence, difficulty preventing ransomware strains (e.g., BlackByte at 26% prevention), gaps in early detection and logging, and recommends continuous validation of identity controls and improved behavioral detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.