The patch almost always arrives too late.
Six vulnerabilities that turned into real incidents over the past years, placed on one scale: the time between attackers starting to exploit them and anyone publishing an advisory about them. For four of the six, that difference is negative.
4/6
exploited before publication.
The exploitation window
The dashed line is the day the vendor published its advisory. Anything to the left of it was already being exploited before the vulnerability existed on paper. No patching policy, however tight, closes a window that opened before anyone knew it was there.
- CVE-2023-4966NetScaler ADC / Gateway≈-50 d · exploited before publication
- CVE-2023-20198IOS XE Web UI-18 d · exploited before publication
- CVE-2024-3400PAN-OS GlobalProtect-17 d · exploited before publication
- CVE-2023-34362MOVEit Transfer-5 d · exploited before publication
- CVE-2021-44228Log4j 20 d · exploited after publication
- CVE-2018-13379FortiOS SSL VPN+77 d · exploited after publication
That is why patching is necessary but not sufficient. What closes the gap is knowing what you have facing the internet, and having somebody look at it the way an attacker would before an attacker does.
From class to incident
None of these incidents rests on a new kind of mistake. They are the vulnerability classes this knowledge base explains, found in software thousands of organisations run. Understand the class and you recognise the next case before it has a name.
The six cases
- CWE-22A01:2021FortiOS SSL VPN (CVE-2018-13379)CVE-2018-13379 explained: how a path traversal in FortiOS SSL VPN exposed plaintext passwords, and why it was still being exploited years later.
- CWE-917A03:2021Log4Shell (CVE-2021-44228)Log4Shell explained: how one line of text in a log file ran code on your server, who exploited it, and what you should still be checking today.
- CWE-89A03:2021MOVEit Transfer (CVE-2023-34362)CVE-2023-34362 explained: how a SQL injection in MOVEit Transfer gave the Cl0p extortion group access to the data of thousands of organisations.
- CWE-420A05:2021Cisco IOS XE Web UI (CVE-2023-20198)CVE-2023-20198 explained: how an internet-exposed management interface in Cisco IOS XE let attackers create a full administrator account.
- CWE-119A07:2021Citrix Bleed (CVE-2023-4966)Citrix Bleed explained: how attackers read session tokens out of NetScaler memory, bypassed MFA with them, and why patching alone was not enough.
- CWE-77A03:2021PAN-OS GlobalProtect (CVE-2024-3400)CVE-2024-3400 explained: how a command injection in the PAN-OS GlobalProtect gateway handed attackers root on the firewall itself.
Who is behind it
Attackers are not an anonymous mass. They are organised groups with a business model or an assignment, and with a recognisable way of getting in. These six shape a large part of the picture.
Cl0p
extortion
Extortion at scale, without encryption
Cl0p does not buy access; it hunts for unknown vulnerabilities in file transfer software itself, then deploys them in a single wave against hundreds of organisations at once. Accellion FTA, GoAnywhere MFT, MOVEit Transfer and Cleo in turn. Nothing gets encrypted: the data is stolen and the threat to publish it is the leverage.
LockBit
extortion
Ransomware as a service
LockBit supplies the ransomware and the extortion platform; separate affiliates do the break-in and share the proceeds. Those affiliates are rarely creative about entry: they use unpatched edge appliances and stolen credentials. With Citrix Bleed they were the party that turned harvested session tokens into incidents.
Akira
extortion
Ransomware through the VPN
Akira has been active since 2023 and almost always arrives the same way: through VPN access with no second factor on it. No zero-day, no phishing, just a valid password on a portal that asks for nothing else. That makes the group a good gauge of how sound your access management really is.
Scattered Spider
access
Social engineering of the service desk
Scattered Spider needs no vulnerability. The group calls the service desk, poses as an employee and has a password or an MFA token reset. Alongside that: SIM swapping and wearing users down with endless MFA prompts. Technology does not stop this; procedure and harder identity verification do.
Volt Typhoon
state-linked
State-linked pre-positioning in critical sectors
Western agencies link Volt Typhoon to China, and the group stands out for what it does not do: no malware, no ransomware, no visible loot. It enters through edge equipment and then works with the administrative tooling already present, in order to stay inside critical infrastructure for years.
Sandworm
state-linked
Destructive state operations
Sandworm is attributed to Russian military intelligence and sits behind a series of destructive attacks, from NotPetya to repeated strikes on the Ukrainian power grid. The objective is not money but outage, which makes the group a different class of risk from an extortion gang.