Exploit kits still the number one web-based threat
In a 2018 report of current web-based threats, researchers state that so far this year, cybercriminals are targeting unpatched PCs with ancient CVEs and well-known exploit kits. This latest iteration, CVE-2018-9442, was revealed on Thursday by a team of eight academics from four universities and two private companies, who published a technical breakdown of the vulnerability. In the first quarter of 2018, Unit 42 found 1583 malicious URLs across 496 different domains. Hackers used at least eight old and public vulnerabilities. The Top 3 CVEs used are CVE-2014-6332 ( IE VBScript ), CVE-2016-0189 ( IE VBScript ), and CVE-2015-5122 ( Adobe Flash Player ).
The report also found that out of the 1,583 URLs found in malicious emails it examined, 1,284 were exploit kit related. Top exploit kits are KaiXin, Sundown, Rig, and Sinowal.