Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Vulnerability exploitation is beating credentials. Are your tests keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20026
Topic starter  

TL;DR: Verizon's DBIR 2026 shows exploited vulnerabilities rising to 31% of breaches while credentials fell to 13%, and only 26% of CISA Known Exploited Vulnerabilities were fully remediated in 2025, according to FireCompass' analysis. Annual pen testing is increasingly misaligned with a threat model defined by continuous exploitation, third-party trust paths, and chained attack paths.

NHIMG editorial — based on content published by FireCompass: Verizon DBIR 2026 and what the shift from credentials to vulnerabilities means for pen testing

By the numbers:

Questions worth separating out

Q: What breaks when organisations rely on annual pentesting alone?

A: Annual testing leaves long periods where new deployments, identity changes, and exposed endpoints go unvalidated.

Q: Why do exploited edge vulnerabilities often lead to identity compromise after initial access?

A: Because the first foothold rarely stays isolated.

Q: How do security teams know whether their vulnerability programme is keeping up?

A: Look for measurable reductions in time from disclosure to validated remediation, fewer exceptions on internet-facing assets, and faster containment when active exploitation appears.

Practitioner guidance

  • Map exploited-vulnerability paths to identity dependencies Trace how exposed edge services connect to VPN access, SSO, service accounts, API keys, and administrative sessions so you can see where a vulnerability becomes an identity compromise.
  • Shift testing from calendar-based to KEV-triggered validation Run offensive validation whenever a relevant Known Exploited Vulnerability affects your stack, then confirm whether the issue can be chained into production access rather than only whether the CVE exists.
  • Scope third-party trust junctions into pen tests Include OAuth flows, supplier portals, federated identity providers, partner SFTP, webhooks, and service accounts in scope so you can test how vendor trust meets your environment at runtime.

What's in the full article

FireCompass's full blog covers the operational detail this post intentionally leaves for the source:

  • The DBIR 2026 figures and how FireCompass mapped them to continuous offensive security priorities.
  • Evidence-backed pen testing workflow examples for chaining vulnerabilities into real access paths.
  • Third-party trust, OAuth, and service-account attack paths that implementation teams need to scope.
  • Shadow AI and AI-agent testing considerations that extend beyond conventional web application testing.

👉 Read FireCompass's analysis of Verizon DBIR 2026 and pen testing implications →

Vulnerability exploitation is beating credentials. Are your tests keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19617
 

Vulnerability exploitation is now an identity problem as much as a patching problem. Once an attacker uses a vulnerable edge service to enter, the next question is which identities, sessions, tokens, and trust relationships remain reachable. That makes the boundary between vulnerability management and IAM much thinner than many programmes assume. The practical conclusion is that access governance must start where exploitability begins, not where authentication ends.

A question worth separating out:

Q: Should organisations prioritise patching internet-facing vulnerabilities over expanding credential controls?

A: Yes, when the initial access data shows exploitation outrunning credential abuse. Credential controls still matter, but a hardened login layer does little if a public edge service is already exploitable. The right sequencing is to reduce exposed KEVs first, then reinforce identity controls so a second-stage compromise does not become lateral movement.

👉 Read our full editorial: Vulnerability exploitation overtakes credentials: what pen test teams must adjust



   
ReplyQuote
Share: