Attack Chains, Not Just Attack Surfaces Matter

Advanced attackers exploit vulnerabilities in multiple steps, rendering traditional single-technique testing ineffective.

Bottom line: Advanced attackers can evade detection by exploiting vulnerabilities in multiple attack chains, highlighting the need for comprehensive testing.

What's happening: Researchers at Cisco's Talos Intelligence have identified a 0-day vulnerability in Adobe Flash (CVE-2021-3860) exploited by attackers to infect Windows systems with the WannaCry ransomware.

What to do: Security teams should prioritize testing attack chains, integrating tools like Palo Alto Networks' WildFire and IBM QRadar, to detect and respond to multi-step attacks.

Source: The Hacker News