WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Eighty Percent of the Top Exploited Vulnerabilities in 2018 Targeted Microsoft
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Eighty Percent of the Top Exploited Vulnerabilities in 2018 Targeted Microsoft

Author: Charles Egli

Created: Thursday, March 21, 2019 - 18:11

Categories: Cybersecurity

A just released report from Recorded Future observes that eight out of ten vulnerabilities exploited via phishing attacks, exploit kits, or remote access trojans targeted Microsoft products. This was the second year in a row in which Microsoft was targeted the most. In 2017, seven of the top ten vulnerabilities affected Microsoft. The top exploited vulnerability on Recorded Future’s list, CVE-2018-8174, a Microsoft Internet Explorer vulnerability nicknamed “Double Kill,” was included in four exploit kits (RIG, Fallout, KaiXin, and Magnitude). These exploit kits spread the malware TrickBot through phishing attacks (WaterISAC posted a TrickBot security primer from MS-ISAC to its portal on Tuesday). Interestingly, Recorded Future also noted the development of new exploit kits has continued to drop amid a shift to more targeted attacks and less availability of zero-day vulnerabilities.

Attached Files:

Recorded Future - 2018 Top Vulnerabilities

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar