attackers and defenders. Cybercrime groups usually are assumed to be early adopters of new technology, used to outwit their adversaries and achieve their goals. However, threat actors are largely still using tried-and-true tactics like phishing, vulnerability exploitation, and compromised account credentials to achieve initial access. Credential abuse (22%), exploitation of vulnerabilities (20%), and phishing (19%) were the main data breach attack vectors over the past year, according to Verizon. There was a 34% annual increase in vulnerability exploitation this year, while employees were involved in 60% of breaches, driven by credential compromise and social engineering.