Bottom line: Stolen credentials are the most common initial access vector in data breaches, posing significant risks to organizations worldwide.
What's happening: Hackers exploited vulnerabilities in Microsoft Active Directory (CVE-2021-3693, CVSS score 9.3) and Adobe Acrobat Reader (CVE-2021-3600, CVSS score 8.5) to gain unauthorized access to sensitive data. Between January 2022 and June 2022, a total of 25% of organizations experienced a data breach, with an average loss of $3.86 million.
What to do: Implement multi-factor authentication (MFA) for all users and systems, using a combination of traditional and biometric factors. Conduct regular security audits and vulnerability assessments to identify potential weaknesses and address them promptly.