January 19, 2018 By Shane Schick 2 min read

Less than a week before political and business leaders descend on Davos, Switzerland, the World Economic Forum has released a study with cybersecurity attack statistics that suggest cybercriminals will be a key topic during the three-day event.

According to the “The Global Risks Report 2018,” threats against industrial systems and critical infrastructure rank high among the major forces that could threaten international stability. Though the possibility of nuclear war and extreme weather topped the list, the report’s cybersecurity attack statistics indicated a major incident could happen in the next five years.

The work of cybercriminals has been growing in frequency, intensity and sophistication, according to the World Economic Forum. The report’s cybersecurity attack statistics included details on how threats such as NotPetya crippled some organizations to the tune of $300 million per quarter. In addition, technologies such as aviation systems can get hit by malware or other exploits an average of 1,000 times every month.

Other well-known cases cited in the report include the WannaCry incident from May 2017, but ransomware in general was called out among the statistics covered. Out of all the email that includes malicious code or some kind of phishing scheme, 65 percent was intended to take over a device and hold it hostage until a victim pays up.

The World Economic Forum is also concerned by threats against the Internet of Things (IoT) — an issue that was highlighted in last year’s report.

As Fortune pointed out, the World Economic Forum’s research divides risks into two categories: likelihood and potential impact. Whereas threats from cybercriminals are in the top five in the first category, they rank sixth in the latter.

While that ranking is still alarming, cybersecurity attacks statistics tend to reveal the severe effects on companies or industries rather than threats that affect entire populations. This year’s World Economic Forum may be the place where we learn whether the top minds in business and government believe that will change anytime soon.

More from

FYSA — VMware Critical Vulnerabilities Patched

< 1 min read - SummaryBroadcom has released a security bulletin, VMSA-2025-0004, addressing and remediating three vulnerabilities that, if exploited, could lead to system compromise. Products affected include vCenter Server, vRealize Operations Manager, and vCloud Director.Threat TopographyThreat Type: Critical VulnerabilitiesIndustry: VirtualizationGeolocation: GlobalOverviewX-Force Incident Command is monitoring activity surrounding Broadcom’s Security Bulletin (VMSA-2025-0004) for three potentially critical vulnerabilities in VMware products. These vulnerabilities, identified as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, have reportedly been exploited in attacks. X-Force has not been able to validate those claims. The vulnerabilities…

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today