Organizations continue to face security incidents not due to sophisticated adversary techniques, but because foundational security controls are often inconsistently implemented or poorly maintained.
Basic measures such as comprehensive logging, timely patching, proper access management and secure configuration of deployed technologies are often neglected or only partially enforced. In some cases, critical security tools are installed without proper tuning, leaving misconfigurations and visibility gaps that undermine their intended effectiveness. These operational shortcomings rather than advanced threat capabilities can provide adversaries with the opportunity to establish and maintain access. Strengthening adherence to core cybersecurity hygiene remains essential to reducing overall risk.
Understanding how these issues are exploited in practice requires insights from real-world adversarial testing. X-Force Red, an elite team of hackers and researchers, conducts exercises which provide a glimpse into many of the methods that attackers can use to exploit vulnerabilities in victim environments. To best organize the findings, we have categorized the results of their penetration testing engagements into the MITRE Corporation’s Common Attack Pattern Enumeration and Classification (CAPEC) framework.
CAPEC was designed to standardize how to describe, analyze, and reason about attacker behavior. It provides a public, structured catalog of attack patterns that adversaries repeatedly use to exploit systems, people and processes. The goal is to capture how attacks work at a conceptual and operational level, independent of any specific vulnerability, exploit or campaign.
The following chart lists the top ten attack patterns discovered by X-Force Red in 2025.
The frequency of these CAPEC attack patterns highlights significant systemic weaknesses in access control, credential management and software configuration.
Collectively, these trends indicate organizations face compounded risks from both preventable technical flaws and operational oversights. This finding underscores the need for stronger configuration controls, proactive vulnerability management and secure development practices to mitigate recurring exploitation paths.
Strengthen security and compliance with IBM IAM services, streamlining identity across hybrid cloud environments.
Optimize your security program with IBM’s global, vendor-independent threat response services.
Build a secure identity foundation with IBM Verify to simplify access, improve authentication, and scale with confidence.