The validation phase of continuous threat exposure management (CTEM) determines whether an attack could succeed in your particular environment. Your teams get proof of attack viability and can concentrate remediation efforts on exploitable exposures, not scoring severity. The 2026 Verizon Data Breach Investigation Report revealed that exploiting vulnerabilities was the most popular initial access vector,…
Global Security News
Don’t break in, log in: How abuse of trust leads to system compromise
Today’s attackers win not by defeating security controls, but by exploiting the trust we place in legitimate technologies.
Global Security News
Check Point hole grants unauthenticated attackers full SmartConsole admin privileges

Check Point has confirmed that a critical security hole in its SmartConsole management tool, one that allows unauthenticated attackers to assume full admin privileges, is now being exploited in the wild. The vulnerability, CVE-2026-16232, was given a CVSS score of 9.3. In its security alert, Check Point described the bug as one allowing an unauthenticated…
Global Security News
Australian energy provider Origin says data breach exposes client data
Global Security News
Rubio restricts visas for sextortionists, cyber scammers

The State Department will restrict visas for cybercriminals like scammers to sextortionists, and in some cases even their family members, Secretary of State Marco Rubio said Thursday. The Trump administration has sought to make a crackdown on foreign-based scams one of the signature issues of his second term. An executive order that the president signed…
Global Security News
Intel Sales Surpass Wall Street Expectations
Global Security News
Fake Claude app promoted by Bing ads pushes SectopRAT malware
Global Security News
What Is Network Security?
Global Security News
4 ways AI-driven defense is rewriting the cybersecurity playbook

The cybersecurity landscape has evolved beyond human scale. Today’s adversaries have replaced predictable, manual playbooks with machine-generated attack chains that can breach traditional controls in seconds. To bridge the gap, organizations must move past legacy, reactive controls and embrace a fundamentally different, AI-driven architecture: Agentic Endpoint Security (AES). AES represents a paradigm shift, moving security…
Global Security News
Google now lets you log into your account with a selfie
Getting locked out of an account is no fun. Google has a few ways to help you regain access if you happen to forget your password or lose an authenticator, including recovery contacts and backup codes. Now, Google has a completely new option: your face. You can now give Google a video record of your…
Global Security News
Zero Trust Architecture: Identity as the Security Perimeter
ZTA requires continuous verification of user and device identity before granting access to specific resources
Global Security News
These 3 Fire TV Sticks are on sale at Best Buy – here’s the one I recommend (and why)
Fire TV Sticks are back down to all-time low prices for Best Buy’s Black Friday in July sale. We’ll break down just how good of a deal you can get.
Global Security News
Reality Bites Elon Musk and His Tesla, SpaceX Believers
Global Security News
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client. The payload goes after the last 90 days of email, the organization’s entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it. The…
Global Security News
AMD raises the AI stakes with Helios, Venice and robotics

AMD executives took to the stage at its Advancing AI 2026 event in San Francisco today to detail the company’s next generation of AI infrastructure solutions, from Instinct MI455X AI accelerator GPUs and 6th Gen EPYC “Venice” CPUs, to Pensando networking, ROCm.AI software and its Helios rack-scale platform that ties it all together. AMD has…
Global Security News
Chaos ransomware deploys browser-based msaRAT to evade network detection

Cisco Talos uncovered msaRAT, a Chaos ransomware RAT that hides C2 traffic by routing it through Chrome or Edge using the Chrome DevTools Protocol. Cisco Talos disclosed msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that routes its entire command-and-control channel through the victim’s own Chrome or Edge browser. The malware…
Global Security News
Dell just dropped the price of this award-winning laptop to 50% off – and I highly recommend it
We granted the Dell 14 Plus an Editors’ Choice award for great hardware and design. Now, the high-end version of the PC is over $1,000 off.
Global Security News
Why Mythos is the cybersecurity crisis we need
Global Security News
Don’t swing at everything

Welcome to this week’s edition of the Threat Source newsletter. Lately I’ve found myself thinking a lot about the Australian TV series Mr. Inbetween (IMDb 8.7/10) — not because I’m a hitman for hire, but because I literally feel in-between. Specifically, in-between what I’d call the “pre-Mythos” and “post-Mythos” eras. We’ve crossed a capability threshold,…
Global Security News
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries

A Russian state-sponsored threat group has been stealing sensitive data from governments and commercial organizations since July 2025 via a novel exploit in popular Linux-based enterprise software, U.S. authorities and cyber officials from more than a dozen other countries warned in a joint cybersecurity advisory Thursday. Laundry Bear’s most recent espionage campaign involves the exploitation…
Global Security News
AI is overwhelming patch management. Here’s how teams adapt
Global Security News
Mapping PCI DSS v4.0.1 to the NIST Cybersecurity Framework 2.0

The PCI Security Standards Council (PCI SSC) has published a document which maps the PCI Data Security Standard (PCI DSS) v4.0.1 to the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0. With both organizations sharing the common goal to enhance data security, this document provides a resource for stakeholders to use in…
Global Security News
Russian hackers exploit Zimbra zero-click flaw for email theft
Global Security News
Hackers abuse Notepad++ plugins to stealthily install malware
Global Security News
Enterprise security at machine speed: AWS Black Hat 2026 preview
Black Hat 2026 (Aug 1-6, 2026) brings together over 22,000 security practitioners, researchers, and CISOs who build, break, and defend enterprise infrastructure. They’re security professionals who push the limits of offensive and defensive security and demand proof over promises. As frontier security models like Mythos reshape the enterprise landscape, they need security that operates at…
Global Security News
Google CEO distracts from Gemini 3.5 Pro delay with talk of Gemini 4 and monthly releases

Google CEO Sundar Pichai has sought to allay concerns over the delayed release of the Gemini 3.5 Pro large language model. He dodged questions about it in Google’s quarterly earnings call on Wednesday by focusing on the company’s next frontier AI model, Gemini 4, and plans to release subsequent LLMs at an almost monthly cadence.…
Global Security News
Samsung Galaxy Z Flip 8 vs. Z Flip 7: Is the new flip phone worth the upgrade?
Comparing the Samsung Galaxy Z Flip 8 to the Z Flip 7 will largely come down to refinement and value for money.
Global Security News
OpenAI Presence Brings Governance to Enterprise AI Agents

OpenAI has introduced OpenAI Presence, a managed enterprise platform designed to help organizations build, deploy, monitor, and continuously improve governed AI agents for business-critical workflows. Available initially through a limited general availability program, the platform reflects a growing shift in enterprise AI from simply providing large language models to helping customers operate AI agents safely…
Global Security News
Russian Hackers Exploit New ‘Zero-Click’ Attack Against Western Organizations
Global Security News
Linux XFS has a decade-old race condition allowing full root access

Linux systems using the XFS filesystem suffer from a race condition that could enable an unprivileged local user to gain full root access. The flaw affects systems with Linux kernel 4.11 or later that have enabled the XFS feature reflink, which permits the creation of copies of a file without actually copying its data. According…
Global Security News
Microsoft 365 outage affects Teams, SharePoint and other services
Global Security News
Upbound Group reports $13 million in losses due to data breach and fraud
Global Security News
CVE-2026-14266: 7-Zip Heap Overflow Flaw Can Lead to Remote Code Execution
A newly disclosed flaw in 7-Zip has raised fresh concerns about malicious archive handling and user-driven exploitation. CVE-2026-14266 is a heap-based buffer overflow tied to the way 7-Zip processes XZ chunked data, and successful exploitation may allow arbitrary code execution in the context of the current user. The issue is especially important because 7-Zip remains…
Global Security News
What Is Cryptocurrency and How Does It Actually Work?
Global Security News
Andy Burnham’s Technology Policy Impact on the UK Channel

Andy Burnham became the United Kingdom’s new prime minister on July 20, ushering in a leadership change that could reshape technology procurement and public-sector IT priorities. While Burnham has pledged continuity on the government’s broader economic framework, his early policy decisions and emphasis on regional devolution suggest UK channel partners should prepare for shifts in…
Global Security News
CVE-2026-64600: RefluXFS Linux Kernel Flaw Can Lead to Root Privilege Escalation
Linux local privilege escalation bugs remain especially dangerous when they turn an ordinary user foothold into full root access. CVE-2026-64600, also referred to as the RefluXFS vulnerability and the RefluXFS Linux Kernel Vulnerability, is a race condition in the Linux kernel’s XFS copy-on-write path that allows an unprivileged local attacker to overwrite protected files on…
Global Security News
Blockchain Life Returns to Dubai — Featuring the Debut of AI Future
Global Security News
South Korean Ministry of Foreign Affairs data breach impacts thousands
Global Security News
Council worker sentenced for accessing sensitive family records
Global Security News
Ransomware payments fail to prevent repeat attacks, new data shows
Global Security News
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
Most of this week’s trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic. The threats change every week. Subscribe, and we’ll alert…
Global Security News
Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall
Cisco Firewall Migration Manager brings predictable timelines, resilient workflows, and multi-migration management to your move to Cisco Secure Firewall.
Global Security News
AI image fraud will cost $40 billion next year – can these international standards help?
Until now, efforts to identify and combat deepfakes and AI scams have been scattered. Which proposed standard will dominate?
Global Security News
Swimlane Launches AI SOC Platform for MSSPs

Swimlane, an agentic AI automation provider, has launched Swimlane AI SOC for MSSPs, a platform designed to help managed security service providers (MSSPs) build AI-powered security operations centers without competing for their customers. Swimlane positions AI SOC as an MSSP-owned platform According to Swimlane, the new offering addresses a growing trend of AI SOC providers…
Global Security News
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know
You can’t have failed to hear the news headlines about “rogue” OpenAI models hacking into another AI organisation, Hugging Face. But what has actually happened, who is to blame, and is it as serious as some of the reports suggest? Find out in my article on the Hot for Security blog.
Global Security News
FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires
FedRAMP 20X replaces point-in-time assessments with continuous, machine-readable evidence that demonstrates security controls are working. Anecdotes explains what the transition from Rev5 to FedRAMP 20X means and how organizations can prepare for continuous, evidence-based assurance. […]
Global Security News
Microsoft Copilot Deployments Delayed Over Security Concerns
Global Security News
When the “Autonomous Attacker” Is Your Own AI Model, (Thu, Jul 23rd)
Two disclosures, five days apart, described the same intrusion from opposite ends — one from the victim, one from the party that turned out to be responsible — and together they make one of the more instructive incidents of the year for defenders. On July 16, Hugging Face disclosed an AI-driven intrusion into its production…
Global Security News
OpenAI’s attack agent did exactly what it was told – just more relentlessly than expected
OpenAI’s unintended attack on Hugging Face startled the world because its AI agent was acting on its own. But that’s exactly what agentic AI is designed to do. We just didn’t expect it to do it so well.
Global Security News
Iranian Hackers Target Siemens and Schneider Industrial Systems, CISA Warns
Global Security News
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic’s Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac. Accomplish AI, which shared details of the vulnerability with The Hacker News ahead…
Global Security News
MacBook Neo’s success wasn’t luck, it was a plan

It’s difficult to ignore the fact that Apple seems to have turned its MacBook Neo into a weapon to promote platform growth, with enough performance under the hood to make competitors seem inferior. And even as the PC industry moves to try to compete with Apple’s last huge Mac success, the company is already planning a powerful follow-up.…
Global Security News
OpenAI Presence raises new questions about enterprise automation and jobs

OpenAI has launched Presence, an enterprise service for deploying voice and chat agents that can resolve customer and employee requests, potentially automating some work now handled by frontline support teams. The agents can answer questions and operate IT systems, and enterprises can decide what actions the agents may take and when they should seek human…
Global Security News
How attackers hosted a fake Claude download page on the claude.ai domain

A threat actor abused Anthropic’s Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed. Employees at at least 29 organizations were compromised over two days in July, after searching for the Claude desktop app and clicking a sponsored Bing ad. The ad pointed to the genuine claude.ai domain, but landed on an…
Global Security News
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

The Chaos ransomware group ran its command-and-control through the victim’s own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound connection of its own. Its process talks to 127.0.0.1 and nothing else. It starts Chrome or…
Global Security News
Cobalt adds Autonomous Pentest to scale application security testing

Cobalt has introduced Cobalt Autonomous Pentest, a new offering that enables continuous offensive security across an organization’s application portfolio by delivering actionable penetration testing results in as little as 24 hours. AI-assisted development enables organizations to ship software faster than ever, while attackers are using AI to automate reconnaissance and accelerate exploitation. Pentesting performed quarterly…
Global Security News
EU fines Google $1 billion for search, app store antitrust violations
Global Security News
Cato Networks integrates SASE with CrowdStrike Falcon

Cato Networks and CrowdStrike have integrated their security platforms to unify network and endpoint telemetry, giving customers a more streamlined way to investigate threats while creating new managed security and consolidation opportunities for channel partners. Cato and CrowdStrike connect network and endpoint data This unified integration will help security teams unify network and endpoint visibility,…
Global Security News
I use Anthropic’s Claude AI tools for very different jobs: How to pick between models, Code, and Cowork
Here’s how Anthropic’s AI tools work, what they can accomplish, and why security, cost, and your oversight still matter.
Global Security News
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud’s Singapore region; it was offline by the…
Global Security News
CIOs brace for AI threats while investing in AI defense
Global Security News
How Synthetic Identity Fraud is Coming for Machine Identities

Most people understand identity theft as an attacker stealing a real person’s sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several real data points with fabricated ones to create a person who doesn’t exist. Since no…
Global Security News
Google Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability Hunting

Google DeepMind unveiled Gemini 3.5 Flash Cyber, an AI model for vulnerability discovery and patching, available only to governments and trusted partners. Google DeepMind announced Gemini 3.5 Flash Cyber on Tuesday, a security-focused AI model built on top of the existing 3.5 Flash architecture and designed specifically to find, validate, and patch software vulnerabilities. It…
Global Security News
New RefluXFS Linux flaw lets attackers gain root privileges
Global Security News
AI Agents Now the Enterprises Fastest Growing Exposed Attack Surface
Global Security News
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances. The activity involves malicious Packagist development versions spanning 10 packages associated with a legitimate PHP and DevOps developer, dinushchathurya, between July 12 and 13,
Global Security News
Millions of cars could be tracked and unlocked by a hidden security flaw
A car alarm vendor’s coding mistake has left millions of vehicles vulnerable to theft and location tracking. Thanks to the way dealers sell car alarms, many affected drivers don’t even know they have one installed. The device is the KARR Security System, a Bluetooth-enabled aftermarket alarm built by Acrisure Protection Group. It’s installed by dealers,…
Global Security News
WhatsApp Web chats exposed by Adobe’s Acrobat extension flaw
HermeticReader is the name given to a recently disclosed vulnerability in the Adobe Acrobat PDF extension for Chrome, tracked as CVE-2026-48294. Researchers discovered the issue in early June 2026 and reported it to Adobe, which patched the flaw over a single weekend. They found that a single visit to a malicious website could turn Adobe’s…
Global Security News
Agentic AI Challenges Progress in Confidential Computing
Global Security News
The best Wi-Fi routers of 2026: Expert tested and reviewed
The best Wi-Fi routers provide a strong internet connection, rapid speeds, and plenty of coverage for working, streaming, gaming, and more.
Global Security News
Should you replace a traditional Wi-Fi router with mesh? I compared the two, and here’s my verdict
Global Security News
Months-long breach exposes South Korean diplomats’ personal data

South Korea’s Foreign Ministry has disclosed that attackers breached the Korea National Diplomatic Academy’s online education system, compromising personal data belonging to current and former ministry staff and diplomats stationed abroad. The Korea National Diplomatic Academy launched the online training platform in 2022 to support remote learning during the COVID-19 pandemic. Since then, it has…
Global Security News
We tested 15 Wi-Fi 7 routers in our lab – this one had the best coverage
ZDNET’s latest Lab Award goes to the Wi-Fi router with the widest coverage.
Global Security News
What the recent SharePoint bugs told us about the patch race
Global Security News
The organizations that got breached had strong identity programs
Global Security News
Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)
Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls). “An unauthenticated attacker can obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes…
Global Security News
Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process

Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the victim machine and controls it through Chrome DevTools Protocol, a debugging interface built into both…
Global Security News
New TrickBot Variant Spotted Using DNS to Control Infected Windows PCs
Global Security News
New Dolphin X Stealer Employs AI Profiling to Prioritize Targets
Global Security News
10 Best Threat Intelligence Feeds for SOCs and MSSPs in 2026

Threat intelligence feeds give SOCs and MSSPs the data they need to detect malicious activity, enrich alerts, investigate threats, and respond faster. Depending on the platform, this may include malicious IPs, domains, URLs, file hashes, malware behavior, threat actor activity, vulnerabilities, phishing infrastructure, and geopolitical risk. This guide covers several commercial and open-source threat intelligence solutions used…
Global Security News
Wall Street Firms Already Trade Trump’s Truth Social Feed. Now They Can Pay to Be Faster.
Global Security News
Google will let you upload a video selfie to recover your account – but should you?
Google’s new account recovery option prompts users to upload a selfie to prove their identity. Here’s what to know.
Global Security News
Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel
Cisco Talos has discovered a new Rust-based remote access trojan (RAT) we call “msaRAT” attributed to the Chaos ransomware group. The name is derived from the binding names found in the binary: “msaOpen,” “msaClose,” “msaError,” and “msaMessage”. msaRAT is implemented using the Tokio asynchronous runtime, with primary capabilities of browser-leveraged remote code execution and covert…
Global Security News
Preview: Cisco Talos at Black Hat USA 2026
We’re looking forward to having some great conversations with those of you heading to the desert for Hacker Summer Camp 2026. We have a presence within the Cisco and Splunk booth (2633) during Black Hat where you can chat to us about our latest threat research, incident response, and how Talos powers the Cisco portfolio…
Global Security News
Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts
Global Security News
ANCHOR-CI could fix 20 years of broken government-industry collaboration

On July 1, the Cybersecurity and Infrastructure Security Agency (CISA) published a seven-page notice in the Federal Register that could fundamentally change how the U.S. government works with private companies to protect critical infrastructure from cyber threats and natural disasters. The notice, “Establishment of the Alliance of National Councils for Homeland Operational Resilience – Critical…
Global Security News
Google Study Says AI Is Helping Workers, Not Replacing Them
Global Security News
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
Global Security News
PyPI hardens package security with new upload restrictions

The Python Package Index (PyPI) now rejects uploads of new files to releases older than 14 days to prevent attackers from poisoning long-stable releases if a project’s publishing tokens or release workflows are compromised. “This change will protect Python users and reduce the amount of “cleanup” work associated with project compromises for PyPI admins. This…
Global Security News
Google Has the Muscle to Overpower Spending Worries
Global Security News
Microsoft working to fix Exchange Online mailbox quarantine issue
Global Security News
Cohesity Taps Seb Fitzjohn to Lead Partner Sales, GTM in Europe

Data security and data management enterprise, Cohesity, has named Seb Fitzjohn as Vice President, Partner Channel Sales and GTM, Europe. Cohesity eyes data resiliency demand in EMEA Fitzjohn will be charged with expanding the organization’s partner ecosystem as data resiliency becomes a key priority for organizations. Working through the Cohesity Aspire Partner Program, Fitzjohn will…
Global Security News
Swiss rail manufacturer Stadler refuses to pay $12.3 million ransom after cyberattack

Cybercriminal group Everest is demanding 10 million Swiss francs ($12.3 million) from Swiss rail vehicle manufacturer Stadler after breaching a data exchange platform shared with one of its suppliers through compromised credentials. Stadler operates 16 production and component plants and eight engineering centers, backed by a global service network of more than 95 locations, and…
Global Security News
CMMC Compliance Uncertainty Expands MSP Opportunity

The Defense Department’s decision to pause the next phase of Cybersecurity Maturity Model Certification (CMMC) implementation has added another layer of uncertainty for defense contractors. But while assessment timelines may have shifted, the need for cybersecurity preparation has not—creating a growing opportunity for managed service providers, security consultants, and compliance specialists to help customers navigate…
Global Security News
GitHub revamps bug bounty program with new VIP tier, payout changes

GitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports. The changes will take effect on July 27, 2026. Reports submitted before that date will be honored under the previous bounty structure. “Alongside the growth in legitimate reports, we’ve seen a sharp increase in submissions that…
Global Security News
Check Point patches actively exploited SmartConsole authentication bypass flaw

Check Point addressed a critical authentication bypass flaw, tracked as CVE-2026-16232, in SmartConsole that is being actively exploited. Check Point has released security updates to fix multiple vulnerabilities, including CVE-2026-16232 (CVSS score of 9.3), a critical authentication bypass flaw affecting Security Management and Multi-Domain Management (MDSM). The vulnerability, which is under active exploitation, allows unauthenticated…
Global Security News
Check Point warns of SmartConsole zero-day exploited in attacks
Global Security News
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterprise Linux and its derivatives, Fedora Server, and Amazon Linux can meet the conditions for exploitation. The…
Global Security News
Two-Thirds of Ransomware Victims Say AI Boosted Attack Effectiveness
Global Security News
1-15 July 2026 Cyber Attacks Timeline Infographic

Cyber Crime dominated the first half of July 2026, driving 76.5% of all confirmed activity, with Malware the clear weapon of choice at 43.5% of attack techniques. Exploitation of public-facing applications (MITRE T1190) led initial access methods at 27.6%, while Information & Communication infrastructure bore the brunt of targeting, accounting for 32% of sector hits…





































