CyberSafe LogoCyberSafe

Threat intelligence

Modern cyber threats,
mapped to defenses that work.

An operational encyclopedia of attack classes CyberSafe sees in assessments and response work — identity abuse, ransomware, cloud exposure, malware, application flaws, AI-assisted campaigns, and OT risk — with concrete control responses, not marketing scare lists.

25+ documented threat classesMITRE-aligned where applicable
Abstract visualization of cyber threats
Live threat classes · continuous scan

2026 priority board

What to worry about first

Ranked by operational impact for organizations without a full-time SOC — not by hype cycle.

  1. #1

    Human-operated ransomware with data theft

    Highest combined downtime + extortion pressure for most organizations.

  2. #2

    Identity-first compromise (MFA bypass, token theft)

    Valid sessions defeat perimeter tools and scale across SaaS.

  3. #3

    Cloud misconfiguration & control-plane abuse

    Exposure without exploits; blast radius is environment-wide.

  4. #4

    BEC and deepfake-assisted fraud

    Direct financial loss with minimal technical sophistication required.

  5. #5

    Software supply-chain compromise

    One poisoned dependency trusts hundreds of downstream systems.

  6. #6

    AI-assisted phishing & agent/tool abuse

    Attacker productivity and new agent attack surfaces are rising fast.

3D attack-surface graph

Scanning · Cloud

Identity · Cloud · Endpoint · Email · Data · OT

Intrusion model

Interrupt the chain early

CyberSafe engagements are designed to break intrusions at delivery and exploit — before command-and-control and impact stages become expensive.

3D stage stack

See

Attack-surface and identity visibility so you know what can be reached.

Harden

Close the paths that convert phishing and vulns into domain or cloud takeover.

Detect & recover

Monitoring tuned for real stages, plus backups that survive sabotage.

Encyclopedia

Threat classes & defensive responses

Identity & access

Most modern breaches begin with valid credentials or abused sessions — not a novel exploit.

CriticalT1566 / T1534

Business email compromise (BEC)

Fraudulent payment or data requests that look like trusted internal mail.

How it works
Lookalike domains, mailbox rules, or compromised executive accounts redirect invoices and wire instructions.
Business impact
Direct financial loss; hard to recover once funds leave the jurisdiction.
CyberSafe response
Out-of-band payment verification, mailbox-rule monitoring, DMARC enforcement, and executive impersonation playbooks.
HighT1110

Credential stuffing & password spraying

Automated login attempts using breached password lists or common passwords.

How it works
Attackers replay leaked username/password pairs or spray a few passwords across many accounts.
Business impact
Account takeover of email, VPN, SaaS, and customer portals.
CyberSafe response
Phishing-resistant MFA, breached-password blocking, adaptive authentication, and impossible-travel alerts.
HighT1621

MFA fatigue / push bombing

Flooding users with MFA prompts until one is approved.

How it works
Stolen passwords trigger repeated push notifications; users approve to stop the noise.
Business impact
Full account takeover despite MFA being “enabled”.
CyberSafe response
Number matching, rate limits, phishing-resistant authenticators (FIDO2/passkeys), and prompt anomaly detection.
HighT1528

OAuth consent phishing

Malicious apps requesting persistent API access via user consent.

How it works
Victims grant an attacker-controlled app Mail/Files/Contacts scopes.
Business impact
Silent long-lived access even after password resets.
CyberSafe response
App consent policies, admin consent for high-risk scopes, and continuous OAuth grant review.
CriticalT1550

Pass-the-Hash / Pass-the-Ticket

Reusing stolen authentication material without knowing the cleartext password.

How it works
Credential dumpers extract NTLM hashes or Kerberos tickets from memory for lateral movement.
Business impact
Domain-wide compromise from a single endpoint foothold.
CyberSafe response
Credential Guard, LSA protection, tiered admin model, disable legacy auth, and privileged access workstations.
HighT1558

Kerberoasting / AS-REP roasting

Offline cracking of Kerberos tickets for service or user accounts.

How it works
Request service tickets or AS-REP responses for accounts with weak encryption/passwords.
Business impact
Service account takeover and privilege escalation.
CyberSafe response
Strong service-account passwords or gMSA, AES Kerberos, and detections for anomalous ticket requests.

Ransomware & extortion

Double and triple extortion remain the highest operational-impact threat for mid-market and critical services.

CriticalT1486

Human-operated ransomware

Also: Big-game hunting

Operators manually escalate, steal data, disable backups, then encrypt.

How it works
Initial access via phishing, RDP, or vulns → discovery → credential theft → backup sabotage → encryption.
Business impact
Days to weeks of downtime; ransom + recovery + regulatory cost.
CyberSafe response
EDR isolation, immutable/offline backups, segmentation, least privilege, and rehearsed IR/recovery drills.
Critical

Data-extortion without encryption

Steal sensitive data and threaten leak/sale without encrypting systems.

How it works
Exfiltrate file shares, databases, or SaaS exports; pressure via leak sites.
Business impact
Reputation, regulatory fines, customer churn — even if systems stay up.
CyberSafe response
DLP, egress monitoring, SaaS activity analytics, and classified data inventories.
CriticalT1490

Backup and recovery sabotage

Delete or encrypt backup catalogs before the ransomware payload runs.

How it works
Compromise backup consoles, volume shadow copies, or cloud snapshot permissions.
Business impact
Recovery becomes impossible without clean offline copies.
CyberSafe response
Immutable backups, separate backup admin plane, MFA on backup consoles, restore testing.

Cloud & SaaS

Misconfiguration and identity sprawl create exposure without a single exploit being written.

High

Public storage / snapshot exposure

Buckets, blobs, or snapshots left publicly readable.

How it works
Default ACLs, overly broad IAM, or forgotten test buckets indexed by scanners.
Business impact
Mass PII/IP disclosure; often discovered by third parties first.
CyberSafe response
CSPM continuous posture, public-access blocks, and least-privilege IAM reviews.
Critical

Cloud control-plane compromise

Abuse of privileged cloud identities to alter infrastructure at scale.

How it works
Stolen access keys, over-privileged roles, or federation abuse.
Business impact
Environment-wide data access, crypto-mining, or destructive delete.
CyberSafe response
Key rotation, workload identity, CloudTrail/activity alerts, SCPs/guardrails.
High

SaaS session hijack & token theft

Reuse of stolen session cookies or refresh tokens against SaaS apps.

How it works
Infostealers, MITM phishing kits, or malware export browser sessions.
Business impact
Mailbox and file access without password prompts.
CyberSafe response
Session binding, conditional access, continuous access evaluation, endpoint hardening.
HighT1552

SSRF to cloud metadata

Server-side request forgery reaches instance metadata for credentials.

How it works
Vulnerable web apps fetch attacker-controlled URLs including 169.254.169.254.
Business impact
Cloud role credentials stolen from the workload.
CyberSafe response
IMDSv2, egress controls, WAF/app hardening, and metadata hop-limit protections.

Malware & intrusion

From commodity loaders to living-off-the-land — detection must be behavioral.

HighT1204

Initial-access loaders & RATs

Malicious documents or installers that stage remote access tools.

How it works
User opens a lure; macro/script/LNK launches a downloader.
Business impact
Persistent foothold for ransomware or espionage.
CyberSafe response
Attachment sandboxing, ASR/exploit protection, EDR behavioral blocks, user reporting.
HighT1218

Living-off-the-land binaries (LOLBins)

Abuse of signed system tools (PowerShell, wscript, certutil) for stealth.

How it works
Attackers chain built-in utilities to download, decode, and execute payloads.
Business impact
Signature AV misses activity that looks like admin work.
CyberSafe response
Script-block logging, constrained language mode, allowlisting, and process-tree analytics.
CriticalT1542

Firmware / bootkits

Implants below the OS that survive reimaging.

How it works
UEFI/SPI flash modification or bootloader replacement.
Business impact
Extremely durable persistence; hard for standard IR to clear.
CyberSafe response
Secure Boot, measured boot/attestation, firmware updates, and hardware root of trust.

Application & API

Customer-facing apps remain a direct path to data and trust failure.

CriticalT1190

Injection (SQLi, command, template)

Untrusted input reaches interpreters and executes attacker code.

How it works
Missing parameterization, unsafe deserialization, or SSTI sinks.
Business impact
Database dump, RCE, or full host compromise.
CyberSafe response
Secure coding standards, SAST/DAST, WAF as compensating control, and runtime RASP where justified.
High

Broken object-level authorization (BOLA)

API returns or mutates objects the caller should not reach.

How it works
Guessable IDs without ownership checks on every request.
Business impact
Mass customer data exposure via scripted enumeration.
CyberSafe response
Authorization tests in CI, consistent policy middleware, and abuse-rate detection.
CriticalT1195

Supply-chain / dependency compromise

Malicious or hijacked packages enter the build pipeline.

How it works
Typosquatting, dependency confusion, or compromised maintainer accounts.
Business impact
Trusted updates deliver malware to every consumer of the build.
CyberSafe response
SBOM, pinned hashes, private registries, package scanning, and signed builds.

AI-assisted & AI-system threats

AI raises attacker scale and introduces new failure modes around agents, prompts, and model supply chains.

High

AI-augmented social engineering

Personalized phishing and deepfake voice/video at commodity cost.

How it works
LLMs draft lures; voice clones spoof executives for urgent payments.
Business impact
Higher click and compliance rates than template phishing.
CyberSafe response
Out-of-band verification, deepfake awareness, payment dual-control, and mail behavioral models.
High

Prompt injection (direct & indirect)

Attacker content overrides model instructions or tool policies.

How it works
Malicious web pages or documents retrieved into RAG/agent context.
Business impact
Data leakage, unauthorized tool calls, or goal hijacking.
CyberSafe response
Input/output filtering, tool allowlists, retrieval trust scoring, and human approval for high-risk actions.
High

Model / RAG poisoning

Corrupt training or knowledge sources to bias outputs.

How it works
Poisoned fine-tune sets or malicious documents in the knowledge base.
Business impact
Wrong decisions at scale; covert backdoors in model behavior.
CyberSafe response
Data provenance, change control on corpora, evaluation harnesses, and model signing.
Critical

Agent / MCP tool abuse

Compromised or over-privileged agents act as internal operators.

How it works
Malicious tool servers or prompt-driven misuse of connected systems.
Business impact
Automated lateral impact across SaaS and infrastructure.
CyberSafe response
Least-privilege tool scopes, action monitoring, sandboxing, and signed tool registries.

OT, infrastructure & nation-state

When IT compromise reaches OT or civic systems, consequences leave the screen.

Critical

IT-to-OT lateral movement

Office-network footholds pivot into industrial or building-control networks.

How it works
Shared jump hosts, flat VLANs, or vendor remote access bridges.
Business impact
Safety, availability, and physical process disruption.
CyberSafe response
Strict IT/OT segmentation, unidirectional gateways where needed, and monitored remote access.
Critical

Living-off-the-land + APT dwell

Long-term stealthy access for espionage or pre-positioning.

How it works
Valid accounts, scheduled tasks, and native admin tools avoid malware signatures.
Business impact
Strategic data loss; delayed detection measured in months.
CyberSafe response
Threat hunting, identity analytics, network beacons detection, and IR retainers.

Want this mapped to your environment?

We translate this encyclopedia into a prioritized backlog for your identity plane, cloud estate, and recovery posture — starting with what would hurt most if it failed tomorrow.