8 results ·
● Live web index
D
darktrace.com
article
https://www.darktrace.com/cyber-ai-glossary/the-most-common-cloud-security-th…
Misconfigurations in cloud environments are among the most common and critical security risks. These occur when cloud resources, such as storage buckets, databases, or virtual machines, are set up with weak security controls or improper access permissions. Examples include leaving storage buckets open to the public, not enabling encryption, or failing to configure identity and access management (IAM) settings correctly. These misconfigurations can expose sensitive data and cloud infrastructure [...] Employees with malicious intent may intentionally misuse the system by altering or sharing data or transferring it to unauthorized sources. Security becomes a shared responsibility due to the increased complexity of using third-party cloud-based systems. Since organizations often lose visibility and control over their operations on these systems, there are frequent delays between detecting and responding to insider threats. Insider violations can seriously impact an organization's operations [...] Compliance violations in cloud environments occur when organizations fail to meet the stringent regulatory standards governing data protection and privacy, such as GDPR, HIPAA, or PCI-DSS. These regulations require specific security measures to safeguard sensitive data, especially in cloud environments where data is often stored, processed, and transmitted across multiple locations and jurisdictions. Failure to implement adequate security controls in the cloud exposes sensitive data to
I
identitymanagementinstitute.org
article
https://identitymanagementinstitute.org/cloud-security-risks-and-solutions
1. Theft or loss of intellectual property
An outstanding 21% of data uploaded by companies to cloud-based file management services contain sensitive data. The analysis that was done by Skyhigh found that companies face the risk of having their intellectual property stolen. [...] Violation of business contracts through breaching confidentiality agreements is common. This is especially when the cloud service maintains the right to share all data uploaded with third parties. [...] 5. Contract breaches with clients and/or business partners
Contracts restrict how business partners or clients use data and also who has the authorization to access it. Employees put both the firm and themselves at risk of legal action when they move restricted data into their cloud accounts without permission from the relevant authorities.
O
orca.security
article
https://orca.security/resources/blog/cloud-data-security-risks-best-practices
Misconfigurations on cloud storage resources, including public Amazon Simple Storage Service (S3) buckets and shared Relational Database Service (RDS) snapshots, cause most data exposure incidents; Cloud Security Posture Management (CSPM) tools that continuously evaluate configuration state catch these before exploitation. [...] The specific control that most directly reduces unauthorized access is encryption combined with key management. Data encrypted with customer-managed keys (CMKs), in AWS Key Management Service (KMS) and Azure Key Vault, or customer-managed encryption keys (CMEKs) in Google Cloud Platform (GCP) Cloud Key Management Service (Cloud KMS) remains protected even if the storage resource is publicly exposed, because the attacker cannot decrypt the data without access to the key management service. [...] The compliance challenge specific to cloud environments is that configuration drift can occur without any deliberate action by the security team. Auto-scaling events can create EC2 instances with default security group rules. Developers can modify S3 bucket policies through the console without triggering a change management process. Automated compliance assessment that runs continuously and alerts on configuration drift is the only operationally sustainable approach at cloud scale.
P
pmc.ncbi.nlm.nih.gov
official
https://pmc.ncbi.nlm.nih.gov/articles/PMC12743334
### Results
Ten key challenges were identified: 1. data breaches and unauthorized access, 2. compliance with regulations such as HIPAA and GDPR, 3. data sovereignty and jurisdictional issues, 4. shared infrastructure vulnerabilities, 5. insider threats, 6. data loss and availability concerns, 7. inadequate security measures by cloud providers, 8. application vulnerabilities, 9. limited visibility and control, and 10. the complexity of cloud security management.
### Conclusion [...] Cloud environments typically operate on shared infrastructure, where multiple tenants utilize the same underlying hardware through virtualization technologies. While this model enables scalability and cost efficiency, it also introduces risks. A failure in isolation mechanisms through hypervisor exploits, container escape vulnerabilities, or misconfigured virtual machines could result in unauthorized access to sensitive data hosted by other tenants. [...] ### 6. Data Loss and Availability Concerns
Service outages, accidental deletions, or even data corruption can also occur in cloud-based systems and seriously impact the continuity of EQA operations and the availability of critical laboratory information. Without robust backup and recovery strategies, such events can lead to irreversible data loss or extended downtime that put at risk the reporting schedules and stakeholder trust.
M
microsoft.com
article
https://www.microsoft.com/en-us/security/business/security-101/what-is-cloud-…
Cloud adoption continues to accelerate as organizations deploy applications, workflows, and services across multiple platforms. This shift unlocks scalability and flexibility, but it also introduces significant risks to your data. Distributed data stores, overlapping services, and variations in shared responsibility models increase the likelihood of security gaps and misconfigurations that expose your sensitive and proprietary information. [...] Risks often originate early in the development and deployment process through insecure configurations, overly broad permissions, or inadequate encryption practices. These weaknesses can persist into production and manifest as runtime vulnerabilities. Addressing security from design through deployment ensures that controls are embedded throughout the lifecycle, reducing the likelihood of exposure in active workloads.
## Cloud data security benefits and risks [...] Several factors make robust cloud data security a critical business priority for businesses in any sector:
Data breaches. Misaligned identities, open storage configurations, or unmonitored access points create pathways for attackers to reach regulated data.
Expanding cloud architectures. Multicloud deployments and integrated software as a service (SaaS) applications multiply the number of services to secure, requiring consistent governance across environments.
S
sei.cmu.edu
research
https://www.sei.cmu.edu/blog/12-risks-threats-vulnerabilities-in-moving-to-th…
Threat actors look for vulnerabilities in management APIs. If discovered, these vulnerabilities can be turned into successful attacks, and organization cloud assets can be compromised. From there, attackers can use organization assets to perpetrate further attacks against other CSP customers. [...] #10 Stored Data is Lost. Data stored in the cloud can be lost for reasons other than malicious attacks. Accidental deletion of data by the cloud service provider or a physical catastrophe, such as a fire or earthquake, can lead to the permanent loss of customer data. The burden of avoiding data loss does not fall solely on the provider's shoulders. If a customer encrypts its data before uploading it to the cloud but loses the encryption key, the data will be lost. In addition, inadequate [...] This attack can be accomplished by exploiting vulnerabilities in the CSP's applications, hypervisor, or hardware, subverting logical isolation controls or attacks on the CSP's management API. To date, there has not been a documented security failure of a CSP's SaaS platform that resulted in an external attacker gaining access to tenants' data.
No reports of an attack based on logical separation failure were identified; however, proof-of-concept exploits have been demonstrated.
C
coursera.org
article
https://www.coursera.org/articles/cloud-data-security
Hackers and other bad actors are a major threat to the cybersecurity of both on-premise and cloud-based data storage. In fact, according to IBM’s Cost of a Data Breach Report 2025, the average cost of a data breach reached a whopping $4.4 million in 2025 . While many attacks simply rely on run-of-the-mill phishing schemes or stolen credentials, a significant amount of these attacks exploit all-too-common cloud misconfigurations within an organization.
### 2. Insecure APIs [...] Read more: 4 Cloud Computing Career Paths to Know
## How secure is your data in the cloud? Dangers of cloud data storage
Although there are many benefits to cloud data storage, there are also many potential dangers to their security that both organizations and individuals should consider. Some of the most common threats include:
### 1. Data breaches and misconfigurations [...] Accessibility is one of the great benefits of cloud data storage, but it could also be one of its major problems if not managed properly. Organizations that don’t limit privileged access to some data may inadvertently compromise it. Furthermore, employees who aren’t properly trained accidentally reveal and share sensitive information without realizing it.
### 4. Inside actors
P
proofpoint.com
article
https://www.proofpoint.com/us/threat-reference/cloud-security
Cloud computing—a broad term that describes the move to the cloud and a mobile workforce—has brought new security and compliance risks. Cloud account takeover, data oversharing, and usage of unapproved cloud applications present considerable challenges to security teams. That’s why gaining visibility into and control over IT-approved applications is critical to cloud security. Many organizations must secure Microsoft Office 365, Google G Suite, Box, Dropbox, Salesforce, Slack, AWS, ServiceNow, [...] According to the latest statistics by Colorlib, 94% of organizations use cloud computing and cloud-based collaboration or messaging tools to share files and information with colleagues and partners. At the same time, regulated data and intellectual property (IP), such as trade secrets, engineering designs, and other sensitive corporate data, are put at risk. [...] Cloud security is essential in helping organizations address specific vulnerabilities and threats. Employee negligence or lack of training can create cloud security threats, such as oversharing files via public links that anyone can access. Data theft by insiders is also common. For example, salespeople leaving a company can steal data from cloud CRM services.