Security1 distinct publisher3 min readPublished
Bitdefender puts 84% of its high-severity incidents on binaries that were already installed on the host. That figure and Microsoft's ClickFix number cover the two largest volume plays in the telemetry, and both sit outside what attachment scanning and patch cycles reach.
The Watch · Security desk
security
CRPx0 climbed to 46 claimed victims in July on countdowns that fired in near unison1 distinct publisher
leadership
Fake macOS troubleshooting posts route infostealers past Gatekeeper1 distinct publisher
security
Bring Your Own Runtime: Sophos MDR maps a repeatable Deno-based intrusion chain1 distinct publisher
leadership
TerminalFix sends the fake CAPTCHA command to PowerShell so multi-line payloads survive1 distinct publisher
Compiled by The WatchSomething wrong?How this is made
The percentages sit on different denominators, so they do not stack. Microsoft's 47% counts cases inside its own victim notifications [1]. Verizon's 31% counts initial access vectors across the DBIR corpus [5]. Summing them produces a figure nobody measured [20]. But one thing does hold up: in one large vendor's view of intrusions, the biggest single slice arrived with no file to inspect and no vulnerability to patch [3].
The vector that is growing fastest is the one that rewards scanning. Verizon moved vulnerability exploitation from 20% to 31%, which is 11 percentage points, and 11 over 20 is the 55% single-year rise the piece cites [5][6][7]. The procedure behind that number is short: watch new CVEs in internet-facing devices, keep the unauthenticated remote code execution ones, wait for someone to publish a working proof of concept on GitHub, then scan the internet and take what is still unpatched [8]. That chain does not require anyone to write an exploit, because the capability it demands is running other people's code at volume, and exposure, not identity, selects the victim [9]. The Hacker News piece calls this a generics business, waiting for someone else's research to go public and then producing a known formula at scale [18].
The leak-site rankings show the same preference. Qilin held the top spot for more than a year on roughly 1,600 self-claimed victims, which is about 133 a month if the span was twelve [10][15]. In June it was displaced by The Gentlemen, 121 claimed victims against Qilin's 80, a gap of 41 and roughly 51% more [11][14]. Both figures are published by the groups themselves and are not audited [12]. The Gentlemen branched out of a former Qilin affiliate, and Bitdefender's threat debrief describes ransomware playbooks being recycled and improved [13]. The transferable asset was the written procedure, and it worked in new hands.
For defenders the residuals still matter. If ClickFix was 47% of what Microsoft saw, 53% was something else [16]. If 84% of Bitdefender's high-severity incidents ran on-host binaries, 16% did not [17]. Mail filtering and patch velocity keep that share of the work.
The rest needs a different observable. In the chain as described, there is no payload and no exploit artifact, only a command the user pasted into a shell they opened themselves after reading a web page [2][19][21]. The signal is process lineage and command-line content, not a hash. On the execution side, the binaries in question are the administrative tools the IT team uses daily [4], so removing them is not on the table and the discriminator has to be context: who ran it, from where, with what arguments, at what hour. That is harder telemetry to buy and much harder to tune than a signature feed, which is exactly why the 84% keeps holding.
Ranked by verification strength, evidence, and original report placement.
ClickFix was the most common initial access method Microsoft's team observed last year, accounting for 47% of the attacks in their notifications.
Bitdefender analyzed 700,000 security incidents and found that 84% of the high-severity ones involved binaries that were already on the machine, the same administrative tools IT teams use every day.
In a ClickFix chain, a web page tells the visitor to prove they are not a robot, quietly places a command on their clipboard while they read the instructions, then talks them through opening a terminal and pasting it in.
In ClickFix, nothing arrives as an attachment, so there is nothing to scan, and no vulnerability is used, so there is nothing to patch.
Verizon's most recent Data Breach Investigations Report calls exploitation of vulnerabilities the most prominent initial access vector in its dataset this year, reaching 31%, up from 20% last year.
The source characterizes the move from 20% to 31% as a 55% increase in a single year.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Four borrowed numbers, one messenger
Everything quantitative here — 47%, 84%, 700,000, 31% — reaches us through The Hacker News alone, and none of the underlying material is in front of us: no Microsoft notification methodology, no Bitdefender incident breakdown, no DBIR table. The Verizon line at least survives as a verbatim quote with both endpoints, which is more scaffolding than the Microsoft figure gets. The technique descriptions are strong; the measurements are hearsay of a reputable kind.
Adoption measured on the attackers' side
Unusually for a technique story, the usage evidence is quantified rather than anecdotal: pre-installed binaries in 84% of Bitdefender's high-severity incidents, ClickFix at the top of Microsoft's notification volume, vulnerability exploitation at 31% of Verizon's initial access. Three separate telemetry sets pointing the same way is real signal. What drags the number down is the market-share proxy — leak-site victim counts are advertising copy written by the advertisers, and this reporting says so rather than pretending otherwise.
Restrained argument, stretched headline
The body of this piece under-claims more often than it over-claims. It declines to add Microsoft's 47% to Verizon's 31%, labels Qilin's 1,600 victims as self-published, and explicitly demotes evasion — 'the evasion came free' — rather than selling it. The stretch is at the top: 47% of the attacks in Microsoft's notifications is a narrower population than all the initial access Microsoft logged, and the framing lets those read as the same thing. Small overreach on a mostly disciplined argument.
Every yardstick sold by its maker
Each measurement comes from a company with revenue in the category it measured: Microsoft on initial access, Verizon on breach patterns, and Bitdefender twice over — the 84% figure and the threat debrief that hands the piece its 'playbooks' vocabulary. None of that makes the numbers wrong, but nobody in this sourcing chain is paid for the finding coming in smaller, and the piece never pauses on that. The ransomware groups themselves are the second interested party, publishing the victim totals used to rank them.
Trust the direction, not the decimals
The mechanics are described precisely enough to test in your own environment — a clipboard write, a guided paste, resident admin binaries doing the follow-on work. The quantities are another matter: one outlet's rendering of three vendors' data, 'last year' never pinned to dates, and an ending we do not have. The shape of the argument holds up better than any individual percentage in it.