There are a number of ways that operating systems can be vulnerable. - Vulnerabilities in the operating system itself can be exploited by attackers. This drives ongoing operating system patching as well as configuring systems to minimise their attack footprint. - Defaults like default passwords and insecure settings are potential paths for attackers as well. - Configurations can also introduce vulnerabilities. Unlike defaults, configurations are intentional but may be insecure. - Misconfigurations, unlike configuration and defaults, occur when a mistake is made. Human error remains a consistent way for attackers to successfully overcome default operating system and application security.