
Top 5 Ways You Get Hacked
Source: YouTube · John Hammond · published Sep 4, 2025 · 22:42
Ransomware attacks on SMBs in 2025 are driven by basic security flaws, not AI-based threats—effective prevention relies on foundational IT hygiene. 0:17
Key Takeaways:
• Missing multifact authentication (MFA) on remote services like RDP or Microsoft 365 allows attackers to gain access with just username and password. 4:47
• Exposed or unpatched edge devices—such as firewalls or MFT servers—with publicly accessible management interfaces are frequently exploited. 8:18
• Lack of basic network segmentation lets compromised users directly access servers, significantly expanding the attack surface. 12:59
• Misconfigured service accounts with high privileges (e.g., SVCSQL) can be exploited to gain domain admin access, creating a critical vulnerability. 14:32
• Absence of antivirus (AV) or EDR solutions and lack of alert monitoring mean threats go undetected, even when they trigger activity. 18:06
Ransomware remains rooted in fundamental security oversights, not advanced AI—SMBs and MSPs must prioritize basic controls to reduce risk.
Sources:
- 0:17 AI-based threats are not the primary concern in ransomware; access via valid credentials is the main vector.
- 4:47 MFA absence on remote services enables credential-based attacks.
- 8:18 Edge device exposure and patching gaps create major attack surfaces.
- 12:59 Basic network segmentation is missing in most SMBs, allowing broad access.
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Ransomware in small and medium businesses or SMBs. The top five missing or incomplete controls that could prevent or attackers. I think I've posted about these in the post on Twitter now X multiple times in fact, but I felt the subject deserves its own little article. Security Aura or Just Aura is their hacker handle, their alias, their online nickname. And I saw that they had shared this just previously and the reviews are in. Jeff K says it's literally the best thing written on the internet today. So, I would like to take a look through it. And just to say aloud, I did ask for their permission. I wanted their blessing and approval to be able to showcase this in a video. And they did say yes, absolutely. Go ahead. And Ora says, "I'm going to try and keep this article light. I don't intend…