Pretnje
16 direktnih pogodaka-
№ 015
Brute-force attack … P server exposed to the internet with admin/admin credentials and no limit on failed logins. This happens far more often than you would think.pretnja · identity
-
№ 017
Credential stuffing … nd Instagram, counting on people reusing the same credentials on several services — which in most cases holds.pretnja · identity
-
№ 067
IoT Device Compromise IoT device compromise hits cameras, routers, sensors, smart televisions, locks, controllers and all the equipment connected to a network that does not behave like a classic computer. The problem is that these devices are often forgotten the moment they are switched on.pretnja · physical / IoT
-
№ 004
Keylogger Keylogger embedded in a trojan collecting banking credentialspretnja · malware
-
№ 016
Password spraying Password spraying is brute force turned around. Instead of trying many passwords on one account, the attacker tries common passwords across many accounts. That avoids lockout, because each individual account sees only an attempt or two.pretnja · identity
-
№ 006
Backdoor … chine or network, regardless of patching, changed credentials or a reinstalled system.pretnja · malware
-
№ 057
DNS Poisoning … ut DNS poisoning takes them to a page that steals credentials.pretnja · availability
-
№ 012
Infostealer … n infostealer has one basic role: to collect your credentials. Saved browser passwords, cookies and session tokens, autofill data, crypto wallet keys — all of i …pretnja · malware
-
№ 047
Path Traversal … . One configuration file read can reveal database credentials, API keys and internal paths, and from there the attack is no longer reading but a breach of the a …pretnja · applications
-
№ 026
Phishing … a link, opening an attachment, or entering their credentials somewhere.pretnja · social eng.
-
№ 020
Privilege Escalation … running with more rights than they need. Leftover credentials and forgotten administrator accounts are frequent prizes. Each of those mistakes is a shortcut fro …pretnja · identity
-
№ 034
QR phishing - Quishing … ed document check, but the page asks for business credentials.pretnja · social eng.
-
№ 030
SMS phishing - Smishing … rom outside the official store, the attacker gets credentials, payment details or access to the phone.pretnja · social eng.
-
№ 045
SSRF … dpoint, the attacker can try to extract temporary credentials and move from one hole in an application to a compromise of the cloud account.pretnja · applications
-
№ 062
Shared Account Abuse … access belongs behind PAM, session recording and credentials issued for a limited time.pretnja · trust
-
№ 033
Whaling … uments, and the login leads to a page that steals credentials.pretnja · social eng.
Tehnike
8 direktnih pogodaka-
№ 009
AiTM … it forwards everything to the real site), enters credentials and even the MFA code — the proxy passes them through, the real service issues a session token, an …tehnika · initial access
-
№ 026
Configuration Abuse Using default admin credentials on a network devicetehnika · discovery
-
№ 003
Credential Abuse Logging into a corporate VPN with credentials stolen via an infostealertehnika · initial access
-
№ 019
Lateral Movement Attackers use stolen credentials, password hashes, authentication tokens, or exploit trust relationships between systems to move through the network.tehnika · privileges
-
№ 028
Network Sniffing Can capture credentials, session tokens, email content, and API keys.tehnika · discovery
-
№ 001
Phishing … link, opening an infected attachment, or entering credentials on a fake page.tehnika · initial access
-
№ 002
Social Engineering Call from fake tech support requesting login credentialstehnika · initial access
-
№ 035
Website Defacement … lnerabilities, web server flaws, or administrator credentials.tehnika · exfiltration / impact
Odbrane
4 direktna pogotka-
№ 014
Secrets Management Applications, scripts, and services need secrets to do their work — passwords, API keys, certificates, database connection strings. The wrong place for them is code, a config file, a repository, or a chat message. Secrets management means a central, protected store (a vault) from which an application fetches a secret exactly when it needs it, instead of carrying it around in plaintext.odbrana · identity / access
-
№ 031
Deception Technology Honeytokens are fake credentials or files whose use triggers an alert.odbrana · resilience
-
№ 010
Privileged Access Management … ons provide a secure vault for storing privileged credentials, automatic password rotation, real-time session monitoring, and just-in-time access approval inste …odbrana · identity / access
-
№ 036
Virtual Private Network A VPN (virtual private network) creates an encrypted tunnel between a device and the network it connects to. For an organization this primarily means controlled remote access to internal resources — from home, on the road, in the field. Traffic inside the tunnel cannot be read in transit, even on hotel Wi-Fi.odbrana · resilience