{"id":33278,"date":"2020-02-11T17:10:00","date_gmt":"2020-02-11T17:10:00","guid":{"rendered":"https:\/\/www.darkreading.com\/risk\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/d\/d-id\/1337019"},"modified":"2020-02-11T17:10:00","modified_gmt":"2020-02-11T17:10:00","slug":"cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/","title":{"rendered":"Cybercriminals Swap Phishing for Credential Abuse, Vuln Exploits"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/twimgs.com\/nojitter\/darkreading\/dr-logo.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<header>\n<\/header>\n<p><span class=\"strong black\">Infection vectors were evenly divided among phishing, vulnerability exploitation, and unauthorized credential use in 2019.<\/span> <\/p>\n<p class>Phishing attacks are growing less popular as cybercriminals learn they don&#8217;t need to manipulate targets to gain access to their accounts. Instead they are breaking in with stolen credentials and known vulnerabilities, both of which are more difficult for enterprise victims to detect.<\/p>\n<p>This trend is one of many highlighted in IBM&#8217;s &#8220;X-Force Threat Intelligence Index 2020,&#8221; which aims to provide an overview of the threat landscape to security pros often caught in the weeds of day-to-day alerts. The report emphasizes today&#8217;s popular attack vectors, the evolution of malware, commonly exploited flaws, and intensified activity against operational technology.<\/p>\n<p>Phishing made up 31% of attacks in 2019, a notable drop from about half of attacks the year prior, according to the report. Exploits of known vulnerabilities came in second, spiking from 8% in 2018 to 30% in 2019. In third place were incidents using stolen credentials, a technique close behind at 29% of attacks.<\/p>\n<p>&#8220;From a response perspective, those are generally harder for organizations to detect,&#8221; says Wendi Whitemore, vice president of IBM X-Force Threat Intelligence, of the latter two tactics.<\/p>\n<p>They&#8217;re also not hard for attackers to pull off. Ideally, every business will have patched every system, Whitemore continues, but &#8220;the reality is, most organizations are struggling.&#8221; More than 150,000 vulnerabilities have been disclosed to date, IBM reports. Flaws in Microsoft Office and Windows Server Message Block were still seeing &#8220;alarming rates&#8221; of exploitation in 2019.<\/p>\n<p>Attackers are especially fond of remote code execution flaw <a href=\"https:\/\/www.darkreading.com\/vulnerabilities---threats\/old-flaws-new-tricks-cve-2017-0199-and-powerpoint-abuse\/d\/d-id\/1329634\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2017-0199<\/a> and CVE-2017-11882, which was a favorite <a href=\"https:\/\/www.darkreading.com\/operations\/microsoft-office-bug-remains-top-malware-delivery-vector\/d\/d-id\/1336182\" target=\"_blank\" rel=\"noopener noreferrer\">delivery mechanism<\/a> in the second and third quarters of 2019. Both are patched and account for nearly 90% of flaws attackers tried to exploit via spam campaigns.<\/p>\n<p>Those who choose to break in using stolen credentials will find no shortage of them. More than 8.5 billion records were exposed in 2019, at least triple the amount compromised in 2018. Much of this was due to misconfigurations, which increased nearly tenfold in the same time frame and made up 86% of records compromised in 2019. Last year brought a decrease in the overall number of misconfigurations, indicating each one exposed more data.<\/p>\n<p>&#8220;There&#8217;s so much data that attackers can leverage,&#8221; Whitmore says, and it&#8217;s easy and cheap for them to get it. Credentials are often stolen from third-party websites or taken in a phishing attack against a target business. They help attackers blend in with legitimate traffic and make them harder to find.<\/p>\n<p><strong>Ransomware Ramps Up as Malware Shifts<br \/><\/strong>About half of the attacks IBM observed in the first half of 2019 were related to ransomware, compared with 10% in the second half of 2019. The fourth quarter of 2019 brought a 67% increase in ransomware incidents compared with the fourth quarter the previous year. <a href=\"https:\/\/securityintelligence.com\/posts\/x-force-threat-intelligence-index-reveals-top-cybersecurity-risks-of-2020\/\" target=\"_blank\" rel=\"noopener noreferrer\">Researchers attribute<\/a> the surge to the increase in attackers and campaigns targeting a variety of organizations in 2019; in particular,&nbsp;<a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/baltimore-ransomware-attack-takes-strange-twist\/d\/d-id\/1334706\" target=\"_blank\" rel=\"noopener noreferrer\">municipal<\/a> and <a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/attacks-on-healthcare-jump-60--in-2019---so-far\/d\/d-id\/1336364\" target=\"_blank\" rel=\"noopener noreferrer\">healthcare<\/a> providers were caught unprepared.<\/p>\n<p>Attackers often use downloaders like Emotet or Trickbot to deploy ransomware on a target system. From there they use multiple stages to infect victims, a technique that gives them better control over the system so as to evade detection and controls and convince victims to pay.<\/p>\n<p>Data from Intezer, which worked with IBM X-Force on the report, indicates attackers are invested in developing new code to expand their capabilities. In 2019, there was a strong focus on evolving codebases of banking Trojans and ransomware while building cryptominer strains.<\/p>\n<p>Banking Trojans had the highest level of new code (45%) in 2019, followed by ransomware (36%). Researchers believe these malware families will target enterprise users in 2020. &#8220;[This activity] means attackers are dedicating time to rebuilding code, rebuilding infrastructure, because these are attacks are so effective,&#8221; Whitmore explains.<\/p>\n<p>Most of these code changes are not significant, she adds. Attackers are primarily trying to evade detection, so they&#8217;ll do a &#8220;cheap quick fix&#8221; so code slips past security tools. Still, their investment in changing code likely means we&#8217;ll see these attacks taking place for a long time.&nbsp;<\/p>\n<p><strong>Targeting Operational Tech&nbsp;&nbsp;<br \/><\/strong>IBM X-Force data shows a 2,000% increase in incidents targeting operational technology (OT) since 2018, which could indicate a greater interest in attacking industrial control systems (ICSs) in 2020. Most of these incidents leveraged a combination of known flaws in SCADA and ICS hardware, in addition to password-spraying attacks using brute-force login against ICS targets.<\/p>\n<p>Researchers report the overlap between OT and IT infrastructure; for example, programmable logic controllers (PLCs) and ICSs posed a risk to firms relying on these infrastructures in 2019. This kind of hybrid infrastructure enables attacks on IT to also target OT devices that control physical assets, they explain. This can significantly increase the cost of recovery from an attack.<\/p>\n<p>&#8220;There are more systems than awareness of those systems,&#8221; says Whitmote of OT environments. &#8220;There are more of them out there now \u2026 and that&#8217;s an area we have a lot of concern for.&#8221; She anticipates we&#8217;ll see a broader attack surface as criminals take advantage.<\/p>\n<p><strong>Related Content:<\/strong><\/p>\n<p> <span class=\"italic\">Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance &amp; Technology, where she covered financial &#8230; <a href=\"https:\/\/www.darkreading.com\/author-bio.asp?author_id=837\">View Full Bio<\/a><\/span> <\/p>\n<p><span class=\"smaller strong red allcaps\">More Insights<\/span><\/p>\n<p> Read More <a href=\"https:\/\/www.darkreading.com\/risk\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/d\/d-id\/1337019?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Infection vectors were evenly divided among phishing, vulnerability exploitation, and unauthorized credential use in 2019. Read More <a href=\"https:\/\/www.darkreading.com\/risk\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/d\/d-id\/1337019?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple\">HERE<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[151],"tags":[],"class_list":["post-33278","post","type-post","status-publish","format-standard","hentry","category-darkreading-ti"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cybercriminals Swap Phishing for Credential Abuse, Vuln Exploits 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cybercriminals Swap Phishing for Credential Abuse, Vuln Exploits 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-02-11T17:10:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/twimgs.com\/nojitter\/darkreading\/dr-logo.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Cybercriminals Swap Phishing for Credential Abuse, Vuln Exploits\",\"datePublished\":\"2020-02-11T17:10:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\\\/\"},\"wordCount\":885,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/twimgs.com\\\/nojitter\\\/darkreading\\\/dr-logo.jpg\",\"articleSection\":[\"DarkReading |TI\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\\\/\",\"name\":\"Cybercriminals Swap Phishing for Credential Abuse, Vuln Exploits 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/twimgs.com\\\/nojitter\\\/darkreading\\\/dr-logo.jpg\",\"datePublished\":\"2020-02-11T17:10:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\\\/#primaryimage\",\"url\":\"https:\\\/\\\/twimgs.com\\\/nojitter\\\/darkreading\\\/dr-logo.jpg\",\"contentUrl\":\"https:\\\/\\\/twimgs.com\\\/nojitter\\\/darkreading\\\/dr-logo.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybercriminals Swap Phishing for Credential Abuse, Vuln Exploits\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cybercriminals Swap Phishing for Credential Abuse, Vuln Exploits 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/","og_locale":"en_US","og_type":"article","og_title":"Cybercriminals Swap Phishing for Credential Abuse, Vuln Exploits 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-02-11T17:10:00+00:00","og_image":[{"url":"https:\/\/twimgs.com\/nojitter\/darkreading\/dr-logo.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Cybercriminals Swap Phishing for Credential Abuse, Vuln Exploits","datePublished":"2020-02-11T17:10:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/"},"wordCount":885,"commentCount":0,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/#primaryimage"},"thumbnailUrl":"https:\/\/twimgs.com\/nojitter\/darkreading\/dr-logo.jpg","articleSection":["DarkReading |TI"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.threatshub.org\/blog\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/","url":"https:\/\/www.threatshub.org\/blog\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/","name":"Cybercriminals Swap Phishing for Credential Abuse, Vuln Exploits 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/#primaryimage"},"thumbnailUrl":"https:\/\/twimgs.com\/nojitter\/darkreading\/dr-logo.jpg","datePublished":"2020-02-11T17:10:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/#primaryimage","url":"https:\/\/twimgs.com\/nojitter\/darkreading\/dr-logo.jpg","contentUrl":"https:\/\/twimgs.com\/nojitter\/darkreading\/dr-logo.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/cybercriminals-swap-phishing-for-credential-abuse-vuln-exploits\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Cybercriminals Swap Phishing for Credential Abuse, Vuln Exploits"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/33278","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=33278"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/33278\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=33278"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=33278"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=33278"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}