Skip to content

The patch almost always arrives too late.

Six vulnerabilities that turned into real incidents over the past years, placed on one scale: the time between attackers starting to exploit them and anyone publishing an advisory about them. For four of the six, that difference is negative.

4/6

exploited before publication.

The exploitation window

The dashed line is the day the vendor published its advisory. Anything to the left of it was already being exploited before the vulnerability existed on paper. No patching policy, however tight, closes a window that opened before anyone knew it was there.

That is why patching is necessary but not sufficient. What closes the gap is knowing what you have facing the internet, and having somebody look at it the way an attacker would before an attacker does.

From class to incident

None of these incidents rests on a new kind of mistake. They are the vulnerability classes this knowledge base explains, found in software thousands of organisations run. Understand the class and you recognise the next case before it has a name.

The six cases

Who is behind it

Attackers are not an anonymous mass. They are organised groups with a business model or an assignment, and with a recognisable way of getting in. These six shape a large part of the picture.

Cl0p

extortion

Extortion at scale, without encryption

Cl0p does not buy access; it hunts for unknown vulnerabilities in file transfer software itself, then deploys them in a single wave against hundreds of organisations at once. Accellion FTA, GoAnywhere MFT, MOVEit Transfer and Cleo in turn. Nothing gets encrypted: the data is stolen and the threat to publish it is the leverage.

also known asTA505, FIN11, Lace Tempest

AttributedCVE-2023-34362

LockBit

extortion

Ransomware as a service

LockBit supplies the ransomware and the extortion platform; separate affiliates do the break-in and share the proceeds. Those affiliates are rarely creative about entry: they use unpatched edge appliances and stolen credentials. With Citrix Bleed they were the party that turned harvested session tokens into incidents.

also known asBitwise Spider

AttributedCVE-2023-4966

Akira

extortion

Ransomware through the VPN

Akira has been active since 2023 and almost always arrives the same way: through VPN access with no second factor on it. No zero-day, no phishing, just a valid password on a portal that asks for nothing else. That makes the group a good gauge of how sound your access management really is.

also known asStorm-1567

Scattered Spider

access

Social engineering of the service desk

Scattered Spider needs no vulnerability. The group calls the service desk, poses as an employee and has a password or an MFA token reset. Alongside that: SIM swapping and wearing users down with endless MFA prompts. Technology does not stop this; procedure and harder identity verification do.

also known asUNC3944, Octo Tempest, 0ktapus

Volt Typhoon

state-linked

State-linked pre-positioning in critical sectors

Western agencies link Volt Typhoon to China, and the group stands out for what it does not do: no malware, no ransomware, no visible loot. It enters through edge equipment and then works with the administrative tooling already present, in order to stay inside critical infrastructure for years.

also known asVanguard Panda, BRONZE SILHOUETTE

Sandworm

state-linked

Destructive state operations

Sandworm is attributed to Russian military intelligence and sits behind a series of destructive attacks, from NotPetya to repeated strikes on the Ukrainian power grid. The objective is not money but outage, which makes the group a different class of risk from an extortion gang.

also known asAPT44, Seashell Blizzard

Press / to search · Esc