Software with system-level permissions, such as your operating system or internet browser, has easy access to your data and device features. If a vulnerability is discovered, it can be exploited to gain control over these access rights and permissions, potentially leading to significant security risks. This is why hackers actively target even the smallest vulnerabilities in such software.
A common scenario involves attackers attempting to disable your devices or hold your data hostage in exchange for a ransom—an attack known as ransomware. A well-known example of this occurred in 2017 with the worldwide impact of the WannaCry/EternalBlue attack.
How do these attacks usually happen?
A known mistake that caused a vulnerability is fixed by the manufacturer of critical software (e.g., operating systems, browsers, PDF readers). While some unknown vulnerabilities may be exploited by nation-states, most malware targeting the average organization relies on exploiting known vulnerabilities that have already been fixed and publicly disclosed by the manufacturer.
An update is released, referencing the fix as a ‘CVE’ (Common Vulnerabilities and Exposures). Manufacturers must strike a balance between informing users about critical fixes and avoiding providing too much information to hackers. Hackers often use these details to target users who have not yet applied the update. While software updates typically contain numerous security fixes, not all of them are registered as CVEs. Update notes may include descriptions such as: “CVE-1234: Fixed an issue that allowed remote access without a password.”
Once a vulnerability is publicly disclosed, hackers have a limited window of opportunity to exploit it before users update their systems. Over the years, the time required for attackers to develop and deploy exploits has significantly decreased—often down to just a few days or weeks. One of the most dangerous forms of exploitation is Remote Code Execution (RCE), which allows attackers to remotely gain system-level access through vectors such as network connections, malicious email links, or compromised website code.
Once an exploit is developed, it is released “in the wild,” meaning it becomes actively used by attackers to compromise vulnerable systems. The method of spreading the exploit varies depending on the type of vulnerability and the affected software. Attackers may distribute the exploit through various channels, such as:
- Network-based attacks, where vulnerabilities are exploited directly over the internet or internal networks.
- Phishing emails, containing malicious links or attachments designed to trick users into executing the exploit.
- Text messages (SMS), which may include harmful links leading to compromised websites or malware downloads.
- Once a device is infected, the malware often remains dormant, waiting for the right moment to pivot and spread within a larger network. The infected device may already be inside—or be carried into—a broader organizational environment where it can exploit the same vulnerability across multiple devices. Additionally, it may use a combination of other exploits to compromise as many systems as possible and continue spreading further.
Internal company networks, where infected devices may eventually end up, often have weaker security due to the false assumption that “hackers can’t access this network.” This makes them an ideal target for malware to continue its spread and establish deeper access.
To mitigate these risks, organizations should implement a defense-in-depth strategy and adopt a zero-trust approach—ensuring that no layer of security is blindly trusted.
- Once enough devices have been compromised, all devices lock down at the same time, encrypting the data, showing a warning on the screen, and requesting payment.
This has been an effective strategy for many hackers, effectively holding the entire company hostage and making the company lose money, time, and, potentially, data. In some targeted cases, the data is also exfiltrated and used for bigger ransoms.
While common good practices like backups sound like a solution, they often result in significant losses as well. It’s unknown how long the malware has been pivoting through the organization or whether it has compromised the backups. Restoring from an older backup reverts the system to an outdated version of the software, potentially allowing the malware to reinfect the machine. This makes the recovery process tedious and resource-intensive.
Though rarely reported, it is widely believed that, in many cases, companies end up paying the ransom.