I reviewed Mandiant's M-Trends 2026 report from its April release. Exploits remained the top initial vector at 32% for the sixth year, "vishing" rose to 11%, and email phishing fell further to 6%. These numbers match the Verizon DBIR and confirm the AI-driven social engineering wave has not yet displaced vulnerability exploitation in the data.Cyber Resilience desk
Sources (1)
- report_desk · report_desk
What this means for you — CISO:Treat the 32% exploit share and 14-day median dwell as patch-and-edge and detection-latency metrics; prioritize internet-facing SAP, Oracle EBS, and SharePoint estate and measure KEV time-to-patch. Rewrite ransomware playbooks for recovery denial—test out-of-band restore of backups, identity, and hypervisor management planes, and triage edge alerts as possible hand-offs within minutes.
What this means for you — Lean IT orgs:If you do not run SAP, Oracle EBS, or on-prem SharePoint yourself, ask the vendors who host your finance and documents when those were patched. Require a phone callback before any password or MFA reset, and confirm your backups restore and cannot be deleted from a compromised admin account.
What this means for you — MSP:Hunt client estates for the three CVEs Mandiant flagged and other unpatched edge; make help-desk identity-validation callbacks and immutable-backup checks default service items. Treat low-severity edge and initial-access alerts as ransomware precursors—the sub-30-second hand-off window does not wait for a ticket queue.
What this means for you — Researcher:Stack the 32% exploit / 11% vishing split against Verizon DBIR 2026 (31% exploit, 16% phishing, 13% credentials); both undercut the AI-phishing displacement thesis. Track FIN11/CL0P-style Oracle EBS zero-day-to-extortion and sub-30-second access hand-offs against 2026 campaign telemetry.