Verizon’s 2026 Data Breach Investigations Report (DBIR) reports that attackers are increasingly gaining entry through software and vulnerability exploitation rather than stolen credentials. Multiple outlets note that vulnerability exploitation is now the top initial access vector, with Verizon stating this is the first time credential theft is no longer the most common way attackers begin an incident in the report’s 19-year history. SecurityWeek and Infosecurity Magazine cite figures indicating vulnerability exploits are involved in a substantial share of incidents, including “31%” of breaches beginning with software flaws. Dark Reading and Help Net Security also emphasize that patching lags behind attacker activity, contributing to the shift.
In addition, Dark Reading highlights ongoing pressure across sectors, including healthcare, where evolving social engineering tactics are described as increasing exposure. Across coverage, ransomware remains a persistent backdrop, alongside continuing breaches involving third parties or vendors. Collectively, the sources present a consistent picture: attackers exploit vulnerabilities more often at the outset, patch delays hinder remediation, and other threat activity such as ransomware and social engineering continues alongside.