There are two basic kinds of threats: the explicit kind that removes any doubt about the intentions of the person issuing the treat, and the vague kind that lets your imagination fill in the blanks, leaving you to scare yourself. Behind the attention grabbers, however, lurked a less newsworthy but much more widespread and persistent threat, ranking, once again, as the top mechanism of attack targeting many organizations in every sector: injection attacks. Read the research report: What you need to know about injection attacks The facts are clear.

Attackers take advantage of injection vulnerabilities in operating systems and applications to penetrate critical web servers and access back-end databases. Implementing a few basic security measures can help mitigate the threat in your environment. While several types of injection attack patterns fall under the MITRE Corporation's Common Attack Pattern Enumeration and Classification (CAPEC) category 152, the following patterns were the most prominent vectors targeting clients monitored by IBM X-Force. According to IBM X-Force analysis of IBM Managed Security Services (MSS) data, injection attacks are the most frequently employed mechanism of attack against organizational networks. In fact, for the period assessed (January 2016 through June 2017), injection attacks made up nearly half — 47 percent — of all attacks.

