IBM X-Force Report Surfaces Increased Exploitation of Public-Facing Apps
嗯,用户让我用中文总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头。好的,首先我需要通读一下这篇文章,了解它的主要内容。 文章主要讲的是IBM X-Force在2025年对网络安全攻击的分析。他们发现针对公开应用程序的攻击增加了44%。然后提到超过一半的漏洞不需要认证就能被利用,这挺严重的。还有恶意软件部署是最常见的攻击行为,占41%,其中18%是勒索软件,18%是webshell。另外,网络犯罪分子还使用合法工具进行恶意活动,占28%。 接下来,文章提到了缺乏基本认证的问题,很多组织在开发软件时没有遵循安全原则。还有软件供应链中引入的新漏洞越来越多,这可能是因为开发者更多地使用AI工具导致的。此外,攻击者也在利用AI来更快地发现漏洞和生成攻击。 最后,文章提到凭证盗窃仍然是主要问题,尤其是访问生成式AI平台的凭证。CI/CD平台也成为目标,恶意脚本可以窃取令牌和API密钥。报告还指出勒索软件团伙增加了49%,达到了109个。 总结下来,文章主要讲了2025年网络攻击的增长情况、漏洞利用、恶意软件类型、合法工具滥用、安全问题、AI的影响以及勒索软件的增长。 现在我要把这些信息浓缩到100字以内,并且直接描述内容。要注意不要遗漏关键数据和趋势。 好的,先列出关键点: - 2025年公开应用攻击增长44% - 56%漏洞无需认证 - 恶意软件占41%,包括勒索和webshell - 合法工具滥用占28% - 缺乏安全设计原则 - AI工具增加漏洞 - 凭证盗窃严重 - 勒索软件团伙增加49% 现在把这些点整合成一句话: IBM报告指出2025年公开应用攻击激增44%,56%漏洞无需认证;恶意软件部署占比最高达41%,其中勒索和webshell各占18%;合法工具滥用占比28%;缺乏安全设计原则及AI工具使用增加导致漏洞增多;凭证盗窃仍是主要威胁;勒索软件团伙增长49%至109个。 检查一下字数是否在100字以内: 这句话大约有77个字左右?可能有点长了。再简化一下: IBM报告指出2025年公开应用攻击激增44%,56%漏洞无需认证;恶意软件部署占比最高达41%,其中勒索和webshell各占18%;合法工具滥用占比28%;缺乏安全设计原则及AI工具使用增加导致漏洞增多;凭证盗窃仍是主要威胁;勒索软件团伙增长49%至109个。 看起来差不多了。 </think> IBM报告指出2025年公开应用攻击激增44%,56%漏洞无需认证;恶意软件部署占比最高达41%,其中勒索和webshell各占18%;合法工具滥用占比28%;缺乏安全设计原则及AI工具使用增加导致漏洞增多;凭证盗窃仍是主要威胁;勒索软件团伙增长49%至109个。 2026-2-25 05:1:36 Author: securityboulevard.com(查看原文) 阅读量:15 收藏

An analysis of cybersecurity attacks published today by the X-Force arm of IBM finds there was a 44% increase in the exploitation of public-facing applications in 2025.

More troubling still, out of the 40,000 vulnerabilities tracked by IBM X-Force, more than half (56%) didn’t require any type of authentication for an attacker to bypass before exploiting.

In total, public-facing applications accounted for 40% of incidents, compared to 32% of incidents where cybercriminals were able to gain access to a set of valid credentials.

According to X-Force, the deployment of malware was the most observed action being taken by cybercriminals, making up 41% of cases. Of all the malware cases, 18% included the deployment of ransomware, while another 18% deployed webshells. Infostealers and backdoors both made up 10% of malware cases. The next most observed action on objective was the use of legitimate tools for malicious purposes, accounting for 28% of cases. Those efforts reflect utilization of hands-on-keyboard post-exploitation efforts and the deployment of utilities that enable lateral movement and privilege escalation.

Chris Caridi, a strategic threat analyst for IBM X-Force, said that lack of fundamental authentication suggests that far too many organizations are not adhering to secure-by-design principles when building and deploying software.

More challenging still, there are more new vulnerabilities being introduced into software supply chains, noted Caridi. It’s not clear to what degree that trend reflects weaknesses across the complex ecosystem relied on to build software or if researchers are simply discovering and reporting more vulnerabilities, but the number of vulnerabilities being created as developers rely more on artificial intelligence (AI) coding tools to create software is only going to increase. Unfortunately, adversaries are also increasingly using AI tools to not only discover vulnerabilities faster but also generate exploits quicker than ever.

Of course, the path of least resistance remains stealing credentials. Among the most valuable credentials, not surprisingly, are ones that malicious actors can use to access generative AI platforms. According to IBM X-Force researchers, more than 300,000 ChatGPT credentials were observed for sale on various forums in 2025.

Continuous integration and continuous delivery (CI/CD) platforms that are used to build and deploy applications have also become prime targets for credential theft and workflow abuse. Malicious scripts are capable of harvesting tokens, application programming interface (API) keys and cloud credentials directly from DevOps pipelines, while compromised personal access tokens provide long-term access across repositories and cloud environments. Once attackers obtain developer or CI/CD credentials, they can easily pivot into cloud platforms using legitimate API calls to create unauthorized admin accounts and extract sensitive data, the IBM X-Force report noted.

Finally, the IBM X-Force report noted there was a 49% increase in active ransomware groups compared to 2024, with 109 different ransomware extortion groups identified by X-Force in 2025.

The challenge, as always, is to not only prevent as many breaches as possible but also limit the blast radius whenever they inevitably occur. As such, there is no substitute for cybersecurity fundamentals, said Caridi. The issue, of course, is that given the ever-expanding size of the attack surface that needs to be defended, it’s still too easy for even the most experienced IT professional to make a mistake.

Recent Articles By Author


文章来源: https://securityboulevard.com/2026/02/ibm-x-force-report-surfaces-increased-exploitation-of-public-facing-apps/
如有侵权请联系:admin#unsafe.sh