X-Force Threat Intelligence Index 2026

Security 101: still lacking

Organizations continue to face security incidents not due to sophisticated adversary techniques, but because foundational security controls are often inconsistently implemented or poorly maintained.

Basic measures such as comprehensive logging, timely patching, proper access management and secure configuration of deployed technologies are often neglected or only partially enforced. In some cases, critical security tools are installed without proper tuning, leaving misconfigurations and visibility gaps that undermine their intended effectiveness. These operational shortcomings rather than advanced threat capabilities can provide adversaries with the opportunity to establish and maintain access. Strengthening adherence to core cybersecurity hygiene remains essential to reducing overall risk.

Understanding how these issues are exploited in practice requires insights from real-world adversarial testing. X-Force Red, an elite team of hackers and researchers, conducts exercises which provide a glimpse into many of the methods that attackers can use to exploit vulnerabilities in victim environments. To best organize the findings, we have categorized the results of their penetration testing engagements into the MITRE Corporation’s Common Attack Pattern Enumeration and Classification (CAPEC) framework.

Organizations continue to face security incidents not due to sophisticated adversary techniques, but because foundational security controls are often inconsistently implemented or poorly maintained.


CAPEC was designed to standardize how to describe, analyze, and reason about attacker behavior. It provides a public, structured catalog of attack patterns that adversaries repeatedly use to exploit systems, people and processes. The goal is to capture how attacks work at a conceptual and operational level, independent of any specific vulnerability, exploit or campaign.

The following chart lists the top ten attack patterns discovered by X-Force Red in 2025.

Bar chart showing the percentage of top 10 attack patterns discovered by X-Force Red in 2025
Top 10 attack patterns discovered by X-Force Red in 2025. Source: IBM X-Force.

The frequency of these CAPEC attack patterns highlights significant systemic weaknesses in access control, credential management and software configuration.

  • The high occurrence of exploiting incorrectly configured access control security levels (CAPEC-180) suggests misconfigurations remain a primary entry point for attackers, indicating persistent gaps in governance and enforcement of security policies.

  • The prominence of password brute forcing (CAPEC-49) and scanning for vulnerable software (CAPEC-310) reflects widespread exposure due to weak authentication practices and insufficient vulnerability management.

  • Frequent instances of query system for information (CAPEC-54) and code injection (CAPEC-242) reveal ongoing issues with information disclosure and insecure coding, which can facilitate further compromise.

  • Patterns such as privilege escalation (CAPEC-233) and session hijacking (CAPEC-593) demonstrate once attackers gain a foothold, they are able to move laterally and maintain persistence, amplifying the impact of initial breaches.

Collectively, these trends indicate organizations face compounded risks from both preventable technical flaws and operational oversights. This finding underscores the need for stronger configuration controls, proactive vulnerability management and secure development practices to mitigate recurring exploitation paths.

3d sphere and cube shapes surrounded by locks
Related solutions
Identity and access management (IAM) services

Strengthen security and compliance with IBM IAM services, streamlining identity across hybrid cloud environments.

Explore IAM services
Threat detection and response services

Optimize your security program with IBM’s global, vendor-independent threat response services.

Explore threat detection services
IBM Verify

Build a secure identity foundation with IBM Verify to simplify access, improve authentication, and scale with confidence.

Explore IBM Verify
Take the next step

Book a personalized discovery briefing to explore how IBM X-Force® can help you reduce cyber risk, validate your defenses and build lasting cyber resilience with offensive and defensive expertise.

  1. Schedule a discovery session with X-Force
  2. Explore IBM X-Force