Report: Software Vulnerabilities Present Higher Risk than Phishing

by Zachary Barlow

July 30, 2026

Historically, hackers don’t gain entry into computer systems the way 90’s and 00’s media would have you believe. There’s a lot less technobabble and keyboard sharing involved in “hacking the mainframe.” Instead, hackers traditionally resort to social engineering. It’s always been easier to trick a person into giving you their password than it is to code your way into their account. However, there is evidence that this may be changing. A recent Mintz memo discusses the findings of Verizon’s 2026 Data Breach Investigations Report, which found a troubling new trend: Due to the rise of AI and Software as a Service (SaaS), software vulnerabilities present higher cybersecurity risks than phishing:

“For the first time in the report’s 19-year history, the most common way attackers gain initial access is by exploiting known software vulnerabilities, rather than by stealing usernames and passwords. Approximately 31% of analyzed breaches began with the exploitation of software vulnerabilities, surpassing credential theft as the leading method of intrusion.

The message for business leaders is straightforward: cybercriminals are increasingly targeting organizations that are slow to fix known weaknesses in their technology, and advances in artificial intelligence (AI) are allowing attackers to find and exploit those weaknesses much faster than in the past.”

This trend may shift cybersecurity priorities. Employees still need training on data security and avoiding phishing attacks, but organizations should also place a greater emphasis on updating outdated or vulnerable software. You may also need to review how third-party SaaS applications connect to your sensitive data. It is possible to have your data breached as a result of software vulnerabilities in programs licensed by third parties.