< Back to all clusters
[TECHNOLOGY] · 2 sources

Software Vulnerabilities Overtake Credential Theft as Leading Cyber‑Attack Vector

A new analysis by ESET Latinoamérica, using Verizon’s 2026 Data Breach Investigations Report, finds that exploitation of software flaws now initiates 31% of security breaches, surpassing credential theft for the first time. Only 26% of known vulnerabilities listed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) were fully remediated in 2025, with patch‑deployment taking an average of 43 days, creating a large window for attackers. The report also notes that artificial‑intelligence tools are accelerating the discovery and exploitation of vulnerabilities, reducing the response time from months to hours.

Separately, researchers at Palo Alto’s Unit 42 identified a phishing campaign that uses fake browser‑window pop‑ups mimicking Microsoft 365 login pages to steal credentials. The malicious windows adapt to the victim’s OS and browser, conceal the true URL, and can disable browser console functions. Experts advise users to open login pages directly in the browser, enable two‑factor authentication, and keep software fully patched to mitigate such attacks.