Hacker News new | ask | show | jobs
by noinsight 2363 days ago
It's still one of the top methods.

See for example Symantec's report [1] with lots of data.

[1] https://www.symantec.com/content/dam/symantec/docs/reports/i...

2 comments

I'm sorry, I can't seem to find any references to driveby exploits in that report. I see many mentions of malicious office documents with downloader macros and similar attacks that certainly happen regularly today.

I do not see any mentions of attacks fitting the driveby pattern you described earlier. I am aware such targetted attacks do exists, but they're extremely rare these days compared to a few years back.

Almost all attacks today rely on social engineering to trick the victim into handing out their credentials or opening a malicious file, not a link.

I literally just got a call about someone being hit. The avenues used to penetrate are email spam and RDP.
When was the last time you saw email spam linking to a browser driveby exploit?