Bottom line: According to an aDvens report, attackers are increasingly using IT service providers as an entry point into customer networks and OT environments, meaning companies should secure service provider access through least-privilege, MFA, segmentation and 72-hour patching.
The “Threat Status Report 2025/2026” by IT security provider aDvens shows that cybercriminals are increasingly using software manufacturers and external IT partners as an entry point to gain access to numerous customer networks or entire industries via a single compromised provider.
According to the report, attackers specifically target unpatched vulnerabilities, manipulated components, or inadequately protected remote maintenance access at software manufacturers and IT service providers. Once inside a system, they frequently plant malicious scripts, known as webshells, to establish persistent backdoors. The risk is no longer limited to classic office IT but is increasingly spreading to industrial production environments (OT).
Andreas Süß, CEO DACH at aDvens, warns that companies need to know which partners have access to their systems, what permissions they hold, and how that access is monitored. For CISOs, this means a shift in protective focus: their own attack surface is no longer defined solely by their own systems, but by the entire chain of connected service providers, cloud services, and remote maintenance access — including OT connectivity.
The report recommends a multi-layered protection concept: critical vulnerabilities in publicly accessible systems should be closed within 72 hours. Companies should maintain a complete inventory of all software vendors, cloud services, and remote maintenance access points, and grant service providers only the absolutely necessary system permissions according to the least-privilege principle, with unused accounts consistently deleted. All access by external partners should be mandatorily secured via multi-factor authentication.
In addition, the experts recommend the use of web application firewalls and automated scans to prevent the injection of webshells, as well as clear network segmentation between production, administrative, cloud, and OT networks to stop lateral spread in the event of an incident. Continuous logging of privileged account activity and regular attack simulations are meant to ensure the effectiveness of these measures.
Source: www.it-daily.net · Published August 19, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.