Five Business Cyber Threats Now: Software Flaws Overtake Stolen Passwords

The threat list businesses used in 2022 no longer reflects how breaches begin. In the latest global dataset, exploited software vulnerabilities have displaced stolen passwords as the leading entry point, while ransomware appears in nearly half of breaches.
Phishing has not disappeared, but it now operates alongside mobile lures, AI-assisted deception and stolen sessions. The 2026 Verizon breach findings, covering incidents from November 1, 2024, through October 31, 2025, put software exploitation at 31% of breaches and ransomware involvement at 48%; they also report generative AI support across 15 attack techniques.
What changed after 2022
The older emphasis on home-office devices, generic malware and QR codes captured genuine concerns, but it mixed attack methods, working environments and delivery formats. A QR code, cloud service or personal laptop is not automatically a threat; the material risk is what an attacker does with it, such as stealing a session, exploiting exposed software or persuading an employee to approve a fraudulent payment.
The five priorities below are therefore organized around business outcomes and defensive decisions rather than fashionable labels. They are not a universal league table: risk varies by sector, geography, technology and attacker motive, and incident datasets measure different populations.
That distinction matters when comparing current evidence. The 2025 ENISA threat analysis examined 4,875 EU incidents from July 2024 through June 2025 and found phishing in about 60% of observed initial intrusions, followed by vulnerability exploitation at 21.3%; it also identified ransomware as the most impactful threat and noted greater targeting of digital supply-chain dependencies. Those figures describe a different territory and methodology from Verizon’s global breach dataset, so they complement rather than contradict it.
1. Exploitation of internet-facing software
Unpatched and poorly controlled software is now a primary front door. Attackers can scan widely for vulnerable VPN appliances, gateways, file-transfer products, web applications and other exposed systems, then automate exploitation without first convincing an employee to click anything.
The practical problem is not simply whether a patch exists. Businesses need to know which assets are reachable from the internet, who owns each one, whether compensating controls are available and how quickly a critical flaw can be removed from exposure. An accurate external asset inventory and an emergency patch process deserve priority over a policy that treats every update as equally urgent.
Where immediate patching is impossible, isolate the system, restrict administrative access, disable unnecessary services and monitor for the vendor’s published indicators of compromise. A successful update does not prove the asset was clean beforehand, so high-risk exposure should also trigger a review of logs, accounts and persistence mechanisms.
2. Ransomware with operational and data-extortion pressure
Ransomware is no longer only an encryption problem. Operators may steal information before disrupting systems, threaten publication or contact customers and partners, creating legal, reputational and operational pressure even when usable backups exist.
Recovery planning must therefore cover more than restoring files. Businesses should define which services must return first, keep protected recovery copies outside ordinary administrative reach and test whether identity systems, cloud configurations and essential applications can actually be rebuilt within an acceptable period.
Network segmentation and tightly controlled privileged accounts limit how far an intrusion can spread. An incident plan should also assign authority for technical containment, legal assessment, insurance notification, customer communication and law-enforcement contact before a crisis forces those decisions into the same hour.
3. Phishing, mobile lures and AI-assisted impersonation
Social engineering remains effective because it targets business processes rather than a particular device. Email is still important, but a convincing request can arrive through text messages, voice calls, collaboration platforms, social accounts or virtual meetings, sometimes using AI to improve language, research a target or scale variations of the same lure.
Traditional awareness training is insufficient if a single employee can authorize a sensitive action inside the same channel where the request appeared. Stronger defenses pair phishing-resistant authentication with procedural checks: payment changes, password resets, new payroll details and disclosure of sensitive records should require independent verification through a known contact path.
Employees also need a rapid, blame-free way to report a suspicious message or accidental interaction. Early reporting can allow the security team to revoke sessions, remove malicious mail, block infrastructure and warn other recipients before the same campaign succeeds elsewhere.
4. Compromise through suppliers and digital dependencies
A company can maintain its own controls and still inherit exposure from a software provider, managed service, contractor or connected business partner. The danger is concentrated access: one supplier account, update channel or remote-management platform may reach many systems or customers.
Vendor questionnaires alone do not reveal that exposure. Businesses need an inventory of third parties with network access, administrative privileges, sensitive data or responsibility for essential operations, followed by controls proportionate to that access. Separate identities, least-privilege permissions, restricted connection paths and logs retained by the customer reduce both likelihood and investigation time.
Contracts should establish breach-notification expectations, evidence preservation and responsibilities for containment and recovery. Exit planning matters too: dormant integrations, former support accounts and retained data can remain useful to attackers after the commercial relationship has ended.
5. Business email compromise and payment diversion
Business email compromise turns trusted communication and routine finance workflows into a route to theft. Criminals may compromise or imitate an executive, supplier, lawyer or employee and then request a changed bank account, urgent transfer, payroll update or release of confidential information.
The FBI’s 2025 IC3 report recorded 24,768 business-email-compromise complaints with reported losses of about $3.05 billion; it separately recorded 191,561 phishing or spoofing complaints. These are reports submitted to IC3, not a complete count of victims or losses, but they demonstrate why payment verification belongs in the security program rather than being treated only as an accounting control.
Technical measures such as multifactor authentication, mailbox forwarding alerts and domain protections can reduce exposure, but transaction design is decisive. Changes to beneficiary details should be confirmed through a previously established number or system, while high-risk transfers should require a second approver who can see the supporting records.
How to turn the five threats into priorities
A useful risk review begins with the paths that could interrupt revenue, expose regulated data or move money. For each path, identify the reachable technology, privileged identities, critical suppliers, responsible decision-makers and recovery dependencies; then test whether the controls work under realistic conditions.
- Map and reduce internet-facing exposure, with deadlines based on exploitability and business importance.
- Use phishing-resistant authentication for administrators, remote access, finance staff and other high-impact accounts.
- Test recovery of critical services, not merely the existence of backup files.
- Revalidate supplier access and remove unused accounts, integrations and data flows.
- Require out-of-band confirmation and dual approval for sensitive payment or identity changes.
This approach preserves what remained true in 2022—people, malware and connected services still create risk—while correcting the priority order. The most important change is that security can no longer focus mainly on whether an employee clicks: exposed software and trusted dependencies can give attackers a direct route into the business.
Also read:
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.