How attackers actually get in, and the boring fixes that stop them
By VA2PT Team, . 7 min read

When people picture a breach, they picture a hooded genius defeating clever defences. The reality is duller and more useful to know: most companies are compromised through a handful of ordinary weaknesses that have unglamorous, well-understood fixes. If you close these five, you are ahead of the majority of organisations that get hit. This is a defender's guide to where the danger actually is, and the boring work that removes it.
The problem
Security spending often chases the exciting threat while the front door stays unlocked. Teams buy advanced tooling to detect sophisticated intrusions, then get compromised because an employee reused a password, or a database was left open to the internet, or a server went unpatched for a year. The problem is a mismatch: attention goes to the rare, dramatic attack, while the common, boring routes stay open because fixing them is nobody's exciting project.
Why it happens
Attackers are economically rational. They use the cheapest route that works, and the cheapest routes are the ordinary mistakes that scale: credentials that can be phished or reused, software with known holes that were never patched, secrets accidentally published, and services exposed that should have been private. These do not require genius; they require the target to have left something open. The reason they keep working is that the fixes are tedious, ongoing and invisible when they succeed, so they lose the competition for attention inside busy teams.
The five ordinary routes, and their fixes
1. Stolen and reused logins
By far the most common starting point. A password is phished, reused from a leaked database, or simply guessed. Once an attacker has a valid login, most systems let them in as that user, no exploit required.
The boring fix: multi-factor authentication everywhere, so a password alone is not enough. Route all logins through one identity provider, and use a password manager so staff never reuse credentials. This one control blocks the majority of real-world intrusions.
2. Unpatched software
Known vulnerabilities in operating systems, libraries and applications are published publicly. Attackers scan the internet for systems still running the vulnerable version, sometimes within hours of a fix being released.
The boring fix: a patching process with an owner and a deadline, covering your servers, your dependencies and your container images. Track it like any other work. This is the finding in nearly every security assessment, precisely because it is nobody's favourite task.
3. Leaked secrets
API keys, database passwords and access tokens get committed to code repositories, pasted into tickets, or baked into mobile apps. Automated tools continuously scan public sources for exactly these, and a leaked cloud key can be found and abused in minutes.
The boring fix: keep secrets in a secrets manager, never in code. Add secret scanning to your repositories so a key is caught before it is committed, and rotate any credential that has ever been exposed. Treat every public repository as if a hostile reader has its full history.
4. Exposed services
A database, cache, admin panel or monitoring dashboard reachable from the public internet, often with weak or default authentication. These need no skill to abuse; the attacker simply connects.
The boring fix: nothing sensitive should be reachable from the internet. Put databases and internal tools in private networks, reachable only through a VPN or bastion. Review your cloud firewall rules for anything open to 0.0.0.0/0 that should not be:
# Terraform: a database security group that only its app tier can reach — not the internet
resource "aws_security_group_rule" "db_from_app_only" {
type = "ingress"
from_port = 5432
to_port = 5432
protocol = "tcp"
security_group_id = aws_security_group.database.id
source_security_group_id = aws_security_group.app.id
}
5. Over-privileged access
When every account and service can do everything, one compromised login becomes a full takeover. Attackers rely on this: get in anywhere, then move sideways because nothing is fenced off.
The boring fix: least privilege. Give each person and service the minimum access they need, scope cloud IAM roles tightly, and remove standing admin rights. When an account is compromised, least privilege is what limits the blast radius to one small area instead of the whole business.
What to do this week
- Enforce multi-factor authentication on every system, with no exceptions.
- Review your cloud firewall rules and close any database or admin port open to the internet.
- Add secret scanning to your repositories and rotate anything it finds.
- Assign an owner and a schedule for patching servers, dependencies and images.
- Audit who has admin rights and remove the ones nobody can justify.
Notice that none of these are exotic. They are the boring, repeatable disciplines that quietly remove the routes attackers actually use. For a deeper look at the code-level bugs behind web breaches, see our OWASP Top 10 explainer.
When to bring in a partner
If you want to know which of these doors are open right now, a vulnerability assessment and penetration test finds them and ranks the fixes by impact. For keeping them closed over time, VA2PT runs managed cloud security across AWS, Azure and Google Cloud, so patching, monitoring and access reviews happen on a schedule instead of after an incident.
- security
- breaches
- attack-surface
- hardening
- startups