It does not mean SQL injection is rare. It means the disclosure regime records who was affected and not how.
Five million records from a platform none of the customers knew they were using. Correlated failure, uncorrelated disclosure.
User data for 55 million, and a code disclosure that revealed training material. Two exposures, two sets of interested parties.
Exploitation is arriving before organisations can deploy. Patching in twenty days is worth less than surviving a compromised appliance.
Privilege stops a court compelling disclosure. It says nothing about an intruder copying the file, and the gap is filled by IT controls.
1,596 disclosed, 97 patched. Discovery is now a capital expenditure; fixing is still one person in their own time.
Four business days from a materiality determination the company itself makes. The clock and the investigation run on incompatible timescales.
A deadline is an incentive when meeting it is possible. At this volume it becomes a countdown to publishing defects nobody has fixed.
A session token read out of appliance memory bypasses the second factor entirely, because authentication already happened.
The only accountability mechanism operating on the same timescale as the incidents — and it is triggered by disclosure rather than by harm.
The head start was the entire point of coordinated disclosure. At an interval measured in hours, publication is a starting gun heard equally by both sides.
This figure measures the category every disclosure-based count excludes by construction: the attacks that were stopped.
A country that strengthens its disclosure law appears to get worse. One that has none appears clean.
Where disclosure is not mandatory, the regional picture is assembled almost entirely from what attackers chose to publish.
The window between disclosure and exploitation is shortest exactly where the ability to respond is slowest.
837 incidents, 419 confirmed breaches. The 418 that never became a disclosure are the sector’s real attack volume.
A corpus assembled from disclosures records failures in detail and successes almost never.
Where disclosure is not mandatory, criminal forums become the primary public record — and affected people learn from researchers.
A sequel name is a judgement that this is the same mistake in the same place. Session tokens leak past authentication entirely.
A privately held operator using the same product would have had the same exposure and, quite possibly, produced no public record at all.
“Group X has been dismantled” is the form the good news usually takes in this field. It describes the destruction of the cheapest component.
The operation describing itself, to itself, with no expectation of being read. Nearly everything else in this corpus is an attacker described from outside.
The corpus does not record availability harm less because it matters less. It records it less because nothing compels anyone to measure it.
The rule requires disclosure of a material incident. It does not require the company to show its working — and Halliburton said so, in writing, to the SEC.
A 560 million claim graded low sits below a 110 million disclosure graded high. That ordering is the point of having grades.
Six days between patch and intrusion. Faster than most manage, and longer than the window now exists.
A stolen session token arrives after authentication. Multi-factor is not bypassed — it is never consulted.
Every control answers "should this account reach this data". Here the answer was yes.
No intruder, no exploit. A statutory duty answered, and a tab nobody checked.