Vulnerabilities

CVE-None: Attack Behavior Slips Past Security Controls

August 19, 2026 08:10 · 12 min read
CVE-None: Attack Behavior Slips Past Security Controls

Security Controls Block Known Attacks, But Quiet Variants Slip Past Defenses

A prevention score indicates what a control recognizes, but it doesn't reveal what the control actually stops. The Blue Report 2026 from Picus Labs measures the performance of enterprise prevention and detection in production, across over 338 million attack simulations run in real customer environments from January to June 2026.

Prevention Effectiveness Rises, But Masks a Softer Interior

The headline shows a genuine recovery, with prevention effectiveness rising from 62% to 69%, back to its 2024 peak. However, this number is a stack-wide average, masking a softer, more vulnerable interior. The same controls that block a well-known attack tool let a quieter version of the same technique slip straight past defenses.

IOC-Based and TTP-Based Security Testing Measure Different Things

IOC-based testing asks whether a control recognizes known bad, while TTP-based testing asks whether a control stops the action, by any route. The former measures the ability to stop known-bad content at the edge, while the latter measures the ability to stop the action, regardless of the route taken.

Asymmetry is Structural and Intentional

The edge is slipping too, with the IOC-based prevention rate for malware downloads falling to 50% across customer environments, from 60% last year and 71% in 2024. Even the layer that signatures cover best is giving way.

Signature-Based Prevention Has Lost 21 Points in Two Years

Your controls stop the version of the attack they recognize, but take the same behavior by a quieter route, and it walks through, while your last test still says covered. The Blue Report 2026 reveals that the prevention scores for the same tool, Mimikatz, were shocking and could not have been further apart.

Change How Mimikatz Dumps Credentials, and Prevention Drops

Dumping credentials from LSASS process memory, the classic and heavily signatured path, was blocked in 94% of attempts. However, pulling RDP credentials from other memory locations with the same tool resulted in a 17% prevention rate, and reading LSA Secrets from the local registry resulted in a 3% prevention rate.

Closing the Gap

Run both IOC-based and TTP-based testing, and read each for what it measures. Known-bad testing is the baseline for perimeter controls, while behavioral validation is the other half, belonging to the endpoint and detection layer. Proving credential access is covered means testing every route to it.

Doing it by Hand Doesn't Scale

Validating only the famous procedure closes an item that's actually still open, producing the most dangerously incorrect verdict a validation program can produce. Picus Swarm, the orchestration layer, runs the many behavioral variations of an attack across the environment and validates each against the controls deployed, so coverage is proven by the behavior, not by the one procedure a signature already recognizes.

Ready for some good news? None of this calls for a bigger stack. It calls for knowing which controls you already own will break the chain, so every exposure becomes a decision you can defend: Patch, Mitigate, Monitor, or Accept with Evidence.

Download the full Blue Report 2026 to see how your industry scored and where to focus first.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free