What actually happens.
BRUTE FORCE ON REMOTE ACCESS
Continuous automated password guessing.
Defeated by key-based authentication with passwords disabled.
VULNERABILITY SCANNING
Automated probing for known weaknesses in software versions.
Defeated by keeping everything patched.
EXPLOITING WEB APPLICATIONS
Out-of-date applications, plugins and themes.
The most common route in, on servers hosting websites.
MALICIOUS UPLOADS
Files uploaded through a web form and then executed.
Prevent execution in upload directories.
EXPOSED SERVICES
Databases, admin interfaces and management tools reachable from the internet.
Firewall them.
STOLEN CREDENTIALS
From a compromised machine, or reused passwords.
Unique passwords, key authentication, and a clean workstation.
WHAT MOST COMPROMISES HAVE IN COMMON
Something out of date, or something exposed that should not have been.
Neither is exotic. Both are preventable.