Knowledge
Nobody Clicked Anything. They Got In Anyway.
Recent threat data says exploits have overtaken social engineering as the top way attackers break in. More than half of exploited flaws are 'zero-click': no password, no user interaction, no mistake required. Here's what that means for your store's exposed systems.
July 27, 2026 · Confidanti · 4 min read
- news
- zero-click
- vulnerabilities
- attack-surface
- patching
For years, security advice to teams has started the same way: don't click the suspicious link. That's good advice and we've given it ourselves. It still matters, but recent threat data carries an uncomfortable update: the most common way attackers now get in doesn't involve anyone clicking anything at all.
In its Q1 2026 threat landscape report, the security firm Rapid7 found that exploiting vulnerabilities has overtaken social engineering as the number-one initial access vector, at 38% of intrusions. And of the vulnerabilities being actively exploited, more than half are what the report calls "zero-click, network-facing": flaws that require no authentication and no user interaction. No password to steal, no employee to fool, no mistake to make. The attacker connects to something you have exposed to the internet.
"Zero-click" — what it means for a business
The term may ring a bell from spyware headlines, where a crafted message silently takes over a phone. That version is real but rare: expensive attacks aimed at specifically chosen, high-value people. The zero-click that shows up in this data is different, more mundane, and far more relevant to you: an exposed system that lets someone in. An admin panel reachable from any browser. A database listening on a public port. A VPN box or plugin with a known flaw and no patch applied.
Against those, the attacker doesn't need your team at all. Your people can pass every phishing test, verify every payment request, do everything right — and the intrusion happens anyway, through a system nobody remembers is exposed.
For an online store, that surface is bigger than it feels: the store platform and its plugins, the admin dashboard, the payment and shipping integrations, the database behind them, and the forgotten things — like the staging copy of your store somebody set up in 2024 and never took down.
Speed is the other half of the story
The report's second theme is pace. Exploitation, Rapid7 notes, is "frequently preceded by large spikes in public discussion across forums, blogs, and social media platforms". In other words, the moment a flaw becomes public knowledge, attackers race to industrialize it. We wrote recently about an AI agent that ran a ransomware intrusion in 31 seconds; this data shows the same shift from the other side. Scanning the internet for exposed, unpatched systems is cheap, automated, and constant.
The report also notes ransomware crews shifting toward "pure extortion": rapid data theft over slow encryption. Faster attacks, needing less time inside, against doors that open without a key.
Put the two findings together and the conclusion is plain: the window between "a flaw is announced" and "someone tries it on you" keeps shrinking, and the try requires nothing from your team.
What we'd do about it
As the security team you don't have to hire, here's where we'd focus, because "zero-click" doesn't mean "no defense." It means the defense is entirely on your side of the door, before anyone knocks.
- Know what you have exposed. You can't patch what you forgot exists. The starting point isn't a tool or a policy — it's an honest inventory of everything about your store that faces the internet: platform, plugins, integrations, admin panels, old subdomains, test environments. This is exactly what an exposure scan produces, and it's the part we do first in every engagement.
- Patch internet-facing systems fast. Prioritize by exposure, not by convenience. A flaw in something only your team can reach can wait for the maintenance window. A flaw in something the whole internet can reach cannot. When your platform or a plugin ships a security update, that's the queue-jumper.
- Shrink the surface. Every exposed system is a door that can develop a flaw. Admin panels, databases, and management tools that don't need to be public shouldn't be. The cheapest vulnerability to defend is the one on a system that's no longer reachable.
- Let something watch the doors. At this speed, you won't out-react an automated attacker. But continuous monitoring notices the new exposure, the strange connection, the door that just appeared. That's the part we handle while you run the store.
The calm version, as always
None of this retires the human-layer work. Phishing and payment fraud haven't gone anywhere, and social engineering is still a strong second place. What the data changes is the balance: your risk now leads with what you expose, not what your team clicks. The good news is that exposure is the most controllable risk you have. You can't stop criminals from scanning the internet. You can make sure that when they scan your store, every door they find is patched, closed, or watched.
Rapid7's own conclusion says it plainly: periodic check-ups and reacting after the fact are no longer enough. Security teams need continuous visibility into their attack surface, sharper prioritization of what's actually exploitable, and "a pace that matches modern attackers before small exposures become large-scale incidents." We couldn't have described our own job better.
For your IT team. The report's zero-click majority means unauthenticated, network-facing vulnerabilities deserve the top of the patch queue. Track them against CISA's KEV catalog, treat edge devices and VPN appliances as first-class assets, and audit for unauthenticated services and orphaned subdomains on a schedule. We keep the technical version of this playbook for whoever owns that side of your stack. See what we'd check →
Not sure what your store actually exposes to the internet? Finding every reachable system, panel, and forgotten subdomain — before someone else does — is the first step of every Confidanti engagement. Talk to us.