🚀 CloudSEK featured in the 2026 Frost Radar™!
Read more
An attack vector is the method or entry point an attacker uses to gain unauthorized access to a system, network, application, or account. A phishing email, a stolen password, an unpatched service, and a misconfigured cloud bucket are all attack vectors.
It answers one question: how did they get in? That is separate from the weakness being exploited and separate from the code used against it, and those three things get confused constantly.
An attack vector carries an attacker from outside a system to inside it. The sequence rarely varies.
The attacker finds a weakness first: outdated software, a reused password, an exposed cloud service. A vector then delivers the attack against that weakness. Access widens from there through malware installation, data theft, or movement toward other systems.
Every vector targets a weakness in technology, in human judgement, or in configuration. A phishing message works on judgement. An unpatched flaw works on technology. An open storage bucket works on configuration, and no exploit is needed at all.
Vectors split into two categories based on whether the attacker changes anything.
They observe the target without altering anything on the system. Network traffic monitoring, packet capture, and collection of credentials from exposed data sources all fall here. Nothing changes, so the activity can run unnoticed for a long time.
Active vectors interact with the target directly and leave a change behind. Phishing messages that install malware, exploitation of unpatched flaws, brute-force login attempts, and code injection against a web application all produce traces.
Almost every documented intrusion uses one of ten recurring categories. Exploitation of vulnerabilities leads the current figures, recorded by Mandiant as the most common initial infection vector for the sixth consecutive year at 32 percent of intrusions where the vector could be established.

Deceptive messages persuade a user to reveal credentials or run a malicious file, most commonly by impersonating a trusted sender. Phishing covers email, spear phishing, voice, and SMS variants. CloudSEK's investigation into an APT36 campaign shows the current form: a phishing archive carrying a Linux shortcut disguised as a procurement document.
Valid usernames and passwords obtained through reuse, credential stuffing, brute force, or infostealer malware. The attacker logs in as a legitimate user and triggers no failed login alert. CloudSEK's FortiBleed research documented an operator holding a database of validated credentials for internet-facing gateways, assembled entirely without exploiting any software flaw.
Malware delivered through attachments, trojanized applications, or compromised websites. Once it runs, it steals data, installs a backdoor, or hands over remote control of the host.
Unpatched flaws in applications, operating systems, and network devices give an attacker code execution or direct access. Internet-facing systems carry the highest risk here, because exploitation needs no user involvement and no credentials.
Exposed cloud storage, open services, default credentials, and permissive access settings create entry points that require no technical skill to use. Configuration errors produce more accessible openings than most vulnerability classes do.
Attackers compromise a trusted software provider, library, or update mechanism, not the target itself. CloudSEK's investigation into the March 2026 LiteLLM compromise traced the entry point to a security scanner inside LiteLLM's own build pipeline. Malicious packages sat on PyPI for around 40 minutes and reached more than 2,500 organizations and roughly 434,000 CI/CD pipelines.
Misuse of legitimate access by employees, contractors, or partners, whether deliberate or careless. Authorization is already in place, which makes this the hardest vector to separate from normal activity.
Injection flaws, broken authentication, insecure object references, and abused API endpoints reach data and back-end systems directly. CloudSEK's investigation into public Postman workspaces found more than 30,000 of them leaking access tokens and API keys, which turns an application vector into a credential vector.
Exposed storage buckets, over-broad IAM roles, stolen OAuth tokens, and session-token theft. A stolen session token skips authentication entirely, so multi-factor authentication does not stop this category once the token is in hand.
Tailgating into a facility, plugging in a rogue USB device, or using an unlocked workstation. Digital-only security programs leave this category unaddressed, and it remains the route into environments with no internet exposure at all.
Single-vector intrusions turn out to be the exception rather than the norm. Real campaigns combine several, because each one solves a different problem for the attacker.
A common sequence runs like this. Phishing delivers an infostealer; the infostealer harvests saved browser credentials; those stolen credentials open a VPN portal, and an unpatched internal server then supplies the privilege escalation. Four vectors, one intrusion, and each stage leaves a different kind of evidence.
Chaining matters for defense because closing one vector rarely ends the exposure. Blocking the phishing message stops that route, and the harvested credentials remain valid until somebody revokes them. Treating each vector as an isolated finding is how organizations remediate an incident and get breached through the same campaign a month later.
Vector inventories understate risk for the same reason. A list records which doors exist. It says nothing about which doors open onto each other, and that second question is the one that decides remediation order.
These terms describe different parts of the same event, and practitioners use them interchangeably every day. Separating them matters, because each one answers a different question during an investigation.
A worked example ties them together. An unpatched VPN appliance is the vulnerability. The code targeting that flaw is the exploit. The internet-facing appliance itself is the attack vector. Every other exposed service forms the attack surface, and the route from that appliance toward a domain controller is the attack path.
The same objective can be reached through completely different vectors, as these three incidents show.
Ransomware spread by exploiting the EternalBlue flaw in unpatched Windows systems. The vulnerability was the vector, and the campaign self-propagated across more than 200,000 systems in over 150 countries with no user action required.
Operators planted malicious code inside legitimate Orion platform updates. Roughly 18,000 customers installed the compromised build, which let the attacker in without a single phishing message or stolen password.
Attackers used phone-based social engineering against employees to reach internal administrative tools, then hijacked high-profile accounts for a cryptocurrency scam. Mature technical controls made no difference, because the vector bypassed all of them.
Cloud migration and AI adoption moved the entry points. These categories barely existed as vectors five years ago.
Identification means finding the entry points before an attacker does. Four practices carry most of the work.
Prevention closes entry points and limits what any single one achieves. Sequence matters, because identity controls and patch velocity outperform everything else on current data.

Enumerating attack vectors turns out to be the easy half of the problem. The harder question is which of them actually connects to something worth protecting, because an exposed asset leading nowhere is a different priority from one reaching a domain controller in two steps. Nexus AI correlates initial access vectors across external exposure, dark web activity, AI infrastructure, and third-party ecosystems into validated attack graphs, which convert a queue of findings into a ranked list of paths worth breaking.
Vulnerability exploitation, phishing and social engineering, compromised credentials, and malware. Exploitation of exposed systems currently leads the incident response data.
Yes. It delivers initial access by persuading a user to reveal credentials or run malicious code, which makes it one of the most common vectors.
A vulnerability is the weakness itself. The attack vector is the path used to reach and exploit it. One is the flaw; the other is the route.
The specific vector used for an attacker's first foothold. MITRE ATT&CK treats initial access as the opening tactic of an intrusion.
Yes. Operators chain them routinely, using phishing to steal credentials and then exploiting a flaw to widen access once inside.
Insider misuse and stolen credentials, because both generate the same telemetry as legitimate activity and trigger no failed access attempts.
