Almost all ransomware attacks are exploiting weak firewalls, according to new research from Barracuda, with adversaries targeting decade-old algorithms embedded across legacy systems and outdated devices.
The cyber firm’s latest Managed XDR Global Threat Report found that almost all (90%) of tracked ransomware incidents last year exploited firewalls through unpatched software or a vulnerable account, allowing attackers to gain control over the network to hide malicious traffic and activity.
This level of freedom should be a cause of concern, with the study finding that 96% of incidents involving lateral movement ended with the release of ransomware.
The fastest ransomware case observed involved Akira ransomware and took just ten minutes for attackers to gain lateral movement, and three hours from breach to encryption, a timeline leaving defenders with scant opportunity to respond, and evidence of how fast modern ransomware operations have become.
Analysing more than two trillion IT events over 2025, Barracuda also discovered that threat actors are also weaponising known software bugs, with one in 10 detected vulnerabilities linked to a known exploit.
The most widely detected vulnerability was found in an outdated encryption algorithm related to the design of the RC4 protocol, which makes it easier for remote attackers to conduct plaintext-recovery attacks, and dates back to 2013.
Barracuda said that this flaw (CVE-2013-2566) is most often found in legacy systems such as old servers, embedded devices and applications, and was the entry point for more than 320 attacks last year.
Other flaws, such as CVE-2024-6387, which allows attackers to run malicious code in OpenSSH, and CVE-2020-11022, a bug in jQuery that can lead to security issues in web pages, were among the top detected software vulnerabilities, and at the root of hundreds of cyber assaults.
However, the study found that incidents involving supply chains or third parties shot up over the last year, rising to 66% from 45% in 2024, as adversaries actively hunt for weaknesses in third-party software to breach defences otherwise outside of their reach.
And all of these problems are about to become a lot harder to manage as attackers begin to lean more heavily on agentic AI, which Barracuda expects to allow for the automation of the early and repetitive stages of breaches, such as environment scanning and the identification of weak configurations.
Recommended reading
- Data Theft Surges to 96% of Ransomware Attacks
- Comment | The History of Ransomware
- Ransomware “Supergroups” Emerge After Record‑Breaking Year of Attacks
“What makes targets vulnerable is often easy to overlook — a single rogue device, an account that wasn’t disabled when someone left, a dormant application that hasn’t been updated, or a misconfigured security feature. Attackers only need to find one to succeed,” said Merium Khalid, director of SOC Offensive Security at Barracuda.
“Organisations and their security teams, especially if that ‘team’ is a single IT professional, face an immense challenge. With limited resources and fragmented security tools, they must safeguard identities, assets and data from an evolving threat landscape and attacks that can unfold in a matter of hours”
To counter these modern cyber threats, Barracuda said organisations need a unified security strategy that combines AI‑driven detection, automated threat response and a fully autonomous SOC, reinforced by continuous training and a resilient security culture.





