8 results ·
● Live web index
news
C
checkpoint.com
article
https://www.checkpoint.com/cyber-hub/cloud-security/what-is-cloud-security/to…
Insiders can accidentally put an organization’s data and cloud infrastructure at risk via misconfigurations, shadow IT, and negligence. However, an organization also faces the risk that insiders may take deliberate malicious action against the organization. [...] Companies face a variety of security risks in the cloud. However, the majority of cloud data breaches and other security incidents originate from one or more of the following 7 cloud vulnerabilities.
### #1. Misconfiguration [...] ### #5. Access Management
Cloud environments lie outside the traditional network perimeter and are accessible via the public Internet. This makes it easier for attackers to gain access to vulnerable cloud infrastructure. One factor that increases these security risks is the fact that many cloud environments have subpar access controls. Some common issues include weak passwords, a failure to use multi-factor authentication (MFA), and granting excessive permissions to cloud users.
U
unit42.paloaltonetworks.com
article
https://unit42.paloaltonetworks.com/2025-cloud-security-alert-trends
The changes we observed in the number of alerts align with our 2024 State of Cloud-Native Security Report, which found that 71% of organizations attribute increased vulnerability exposures to accelerated deployments. Furthermore, 45% of those organizations report a rise in advanced persistent threat (APT) attacks over the last year. [...] We have observed a clear increase in the number of alerts in 2024, correlating with the rise in attacks on cloud environments.
High severity cloud alerts increased by 235% throughout 2024. The largest single-month spike (281%) occurred in May, and we noted the most substantial increase in these alerts (204%, 247% and 122%) in August, October and December, as shown in Figure 1. [...] Unlike the end-of-year high severity alert spike, we saw a sustained spike in medium severity alerts mid-2024. This spike included an initial 186% and subsequent 24% increase, before a downward trend through December, as Figure 2 shows.
S
sysdig.com
article
https://www.sysdig.com/learn-cloud-native/top-cloud-vulnerabilities-and-mitig…
Weak authentication and authorization protocols, and unpatched vulnerabilities, enable attackers to use APIs to steal sensitive data. For example, attackers used an unpatched vulnerability in the 2024 Snowflake data breach to access data and customers’ personally identifiable information (PII).
Other attacks involved exploiting Google OAuth APIs for session hijacking, exploiting Docusign APIs to conduct phishing attempts, and inundating APIs with too many requests in a DDoS attack. [...] Among error-based data breaches, about 30% were misconfigurations, according to the 2025 Verizon Data Breach Investigations Report. This includes misconfigurations in software, hardware, and networks.
The causes of misconfigurations can usually be traced back to a few reasons, such as human error, inexperienced teams, and complex cloud infrastructure. Something as small as a mistype can lead to a data breach.
Common cloud misconfigurations include: [...] Buffer overflow: Attackers input more data than a program can contain, which then overflows into adjacent memory locations enabling attackers to overwrite or corrupt the data stored there.
W
wiz.io
article
https://www.wiz.io/academy/cloud-security/common-cloud-vulnerabilities
In 2024, fintech provider Finastra learned that an attacker had accessed a third-party secure file transfer platform (SFTP) that it used for customer file transfers. The stolen data included sensitive customer files, which the attacker put up for sale on the dark web. The vendor shadow IT issue occurred because the SFTP was outside the company’s central security team’s control and monitoring. Because the team wasn’t managing this process, Finastra didn’t detect the breach immediately. [...] Real-life example:
In 2024, attackers accessed email addresses, hashed passwords, and other credentials from Dropbox Sign using an access vulnerability within an automated system configuration tool. While the attack exposed users’ credentials, Dropbox was able to automatically mitigate the attack’s effect since it had isolated its Sign infrastructure from its other tools and systems.
Basic mitigation steps:
Implement least privilege access to cloud resources. [...] Access management vulnerabilities include a lack of MFA, poor password and credential hygiene, misconfigured policies, mushrooming of administrative entitlements, and a lack of standardized, automated identity lifecycles and centralized access management capabilities.
Real-life example:
C
cloudsecurityalliance.org
article
https://cloudsecurityalliance.org/artifacts/top-threats-to-cloud-computing-2024
Misconfiguration and inadequate change control
Identity and Access Management
Insecure interfaces and APIs
Inadequate selection/implementation of cloud security strategy
Insecure third-party resources
Insecure software development
Accidental cloud disclosure
System vulnerabilities
Limited cloud visibility/observability
Unauthenticated resource sharing
Advanced Persistent Threats
Topics:
Enhancing cloud security strategyTop Threats
[]( Threats to Cloud Computing 2024&url= [...] The CSA Top Threats Report aims to raise awareness of current cloud security risks, threats, and vulnerabilities. In this 2024 installment, we surveyed over 500 industry experts on the cloud security issues they’re facing. Respondents identified 11 top threats. The CSA Top Threats Working Group has analyzed the results and provided a description of each cloud security threat, including the business impact, key takeaways, examples, and relevant security controls.
Top Threats Covered: [...] Join Anthropic, AWS, Google Cloud, Microsoft, SANS, and more this August at the SANS Cloud Security Exchange Summit →
# Top Threats to Cloud Computing 2024
Released: 08/05/2024
Top Threats to Cloud Computing 2024
Home
Publications
Top Threats to Cloud Computing 2024
O
orca.security
article
https://orca.security/resources/blog/biggest-cloud-security-threats-to-watch-…
1. Theft of Sensitive Data – AI models rely heavily on training data. Just like in any data storage in the cloud, organizations can unintentionally or intentionally store sensitive information, such as personally identifiable information (PII), payment card information (PCI), private health information (PHI) as well as dev keys, secrets, and tokens. The Orca research team found that 54% of organizations store PII in databases, while 21% of organizations using AWS storage have at least one [...] Using secure key management systems, typically provided by cloud service providers, to store and manage encryption keys adds an extra layer of security. Utilize a secure, centralized vault that supports robust access controls. This ensures that only authorized users and applications have the necessary permissions to access the API keys. [...] The Orca Cloud Security Platform identifies, prioritizes, and remediates risks and compliance issues across your cloud estate spanning AWS, Azure, Google Cloud, Alibaba Cloud, and Kubernetes. Leveraging its patented agentless SideScanning technology, Orca offers comprehensive cloud security coverage detecting vulnerabilities, misconfigurations, lateral movement, API risks, sensitive data at risk, anomalous events and behaviors, and overly permissive identities. Instead of layering multiple
S
sentinelone.com
article
https://www.sentinelone.com/cybersecurity-101/cloud-security/cloud-security-s…
Public clouds take more hits than private ones. 27% of organizations using public clouds faced security incidents in 2024—that’s up 10% from the year before and includes an average of 43 misconfigurations per account.
Private clouds perform better with only 19% experiencing incidents, mainly because you have more control over configurations. However, private clouds still face vendor-related risks and third-party integration problems that can cause trouble. [...] 4. The year-over-year surge in significant cloud breaches reached 154%, with 61% of organizations reporting major incidents in 2024 compared to 24% in 2023. This acceleration indicates both increased attack volume and improving attacker techniques specifically targeting cloud infrastructure.
C
crowdstrike.com
article
https://www.crowdstrike.com/en-us/cybersecurity-101/cloud-security/cloud-vuln…
As companies increase their use of cloud hosting for storage and computing, the risk of an attack on their cloud services increases because the cloud presents a highly dynamic and distributed landscape. As noted in the CrowdStrike 2024 Global Threat Report, there was a 75% increase in cloud environment intrusions in 2023. The report also revealed a 110% spike in cases involving cloud-conscious threat actors, which are threat actors that are aware of the ability to compromise cloud workloads and [...] CrowdStrike Logo
CrowdStrike Logo
Search Icon
Upcoming events
Conference
CrowdTour
Find a city near you
Summit
Day Zero 2026
Las Vegas, NV
Login
cart icon
cart icon
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
# Top 8 Cloud Vulnerabilities
Karishma Asthana - November 26, 2024
## Understand CNAPPs with Our Guide
## Understand CNAPPs with Our Guide
## What are cloud vulnerabilities? [...] The top eight cloud vulnerabilities include:
Cloud misconfigurations
Insecure APIs
Lack of visibility
Shadow IT
Poor access management
Malicious insiders
Zero-day vulnerabilities
Human error
## #1: Cloud misconfigurations