8 results · ● Live web index news
checkpoint.com article

Top 7 Cloud Vulnerabilities In 2024

https://www.checkpoint.com/cyber-hub/cloud-security/what-is-cloud-security/to…

Insiders can accidentally put an organization’s data and cloud infrastructure at risk via misconfigurations, shadow IT, and negligence. However, an organization also faces the risk that insiders may take deliberate malicious action against the organization. [...] Companies face a variety of security risks in the cloud. However, the majority of cloud data breaches and other security incidents originate from one or more of the following 7 cloud vulnerabilities. ### #1. Misconfiguration [...] ### #5. Access Management Cloud environments lie outside the traditional network perimeter and are accessible via the public Internet. This makes it easier for attackers to gain access to vulnerable cloud infrastructure. One factor that increases these security risks is the fact that many cloud environments have subpar access controls. Some common issues include weak passwords, a failure to use multi-factor authentication (MFA), and granting excessive permissions to cloud users.

Visit
unit42.paloaltonetworks.com article

Cloud Threats on the Rise: Alert Trends Show Intensified Attacker Focus on IAM, Exfiltration

https://unit42.paloaltonetworks.com/2025-cloud-security-alert-trends

The changes we observed in the number of alerts align with our 2024 State of Cloud-Native Security Report, which found that 71% of organizations attribute increased vulnerability exposures to accelerated deployments. Furthermore, 45% of those organizations report a rise in advanced persistent threat (APT) attacks over the last year. [...] We have observed a clear increase in the number of alerts in 2024, correlating with the rise in attacks on cloud environments. High severity cloud alerts increased by 235% throughout 2024. The largest single-month spike (281%) occurred in May, and we noted the most substantial increase in these alerts (204%, 247% and 122%) in August, October and December, as shown in Figure 1. [...] Unlike the end-of-year high severity alert spike, we saw a sustained spike in medium severity alerts mid-2024. This spike included an initial 186% and subsequent 24% increase, before a downward trend through December, as Figure 2 shows.

Visit
sysdig.com article

Top 11 cloud vulnerabilities and how to mitigate them

https://www.sysdig.com/learn-cloud-native/top-cloud-vulnerabilities-and-mitig…

Weak authentication and authorization protocols, and unpatched vulnerabilities, enable attackers to use APIs to steal sensitive data. For example, attackers used an unpatched vulnerability in the 2024 Snowflake data breach to access data and customers’ personally identifiable information (PII). Other attacks involved exploiting Google OAuth APIs for session hijacking, exploiting Docusign APIs to conduct phishing attempts, and inundating APIs with too many requests in a DDoS attack. [...] Among error-based data breaches, about 30% were misconfigurations, according to the 2025 Verizon Data Breach Investigations Report. This includes misconfigurations in software, hardware, and networks. The causes of misconfigurations can usually be traced back to a few reasons, such as human error, inexperienced teams, and complex cloud infrastructure. Something as small as a mistype can lead to a data breach. Common cloud misconfigurations include: [...] Buffer overflow: Attackers input more data than a program can contain, which then overflows into adjacent memory locations enabling attackers to overwrite or corrupt the data stored there.

Visit
wiz.io article

Top 11 Cloud Security Vulnerabilities and How to Fix Them

https://www.wiz.io/academy/cloud-security/common-cloud-vulnerabilities

In 2024, fintech provider Finastra learned that an attacker had accessed a third-party secure file transfer platform (SFTP) that it used for customer file transfers. The stolen data included sensitive customer files, which the attacker put up for sale on the dark web. The vendor shadow IT issue occurred because the SFTP was outside the company’s central security team’s control and monitoring. Because the team wasn’t managing this process, Finastra didn’t detect the breach immediately. [...] Real-life example: In 2024, attackers accessed email addresses, hashed passwords, and other credentials from Dropbox Sign using an access vulnerability within an automated system configuration tool. While the attack exposed users’ credentials, Dropbox was able to automatically mitigate the attack’s effect since it had isolated its Sign infrastructure from its other tools and systems. Basic mitigation steps: Implement least privilege access to cloud resources. [...] Access management vulnerabilities include a lack of MFA, poor password and credential hygiene, misconfigured policies, mushrooming of administrative entitlements, and a lack of standardized, automated identity lifecycles and centralized access management capabilities. Real-life example:

Visit
cloudsecurityalliance.org article

Top Threats to Cloud Computing 2024 | CSA

https://cloudsecurityalliance.org/artifacts/top-threats-to-cloud-computing-2024

Misconfiguration and inadequate change control Identity and Access Management Insecure interfaces and APIs Inadequate selection/implementation of cloud security strategy Insecure third-party resources Insecure software development Accidental cloud disclosure System vulnerabilities Limited cloud visibility/observability Unauthenticated resource sharing Advanced Persistent Threats Topics: Enhancing cloud security strategyTop Threats []( Threats to Cloud Computing 2024&url= [...] The CSA Top Threats Report aims to raise awareness of current cloud security risks, threats, and vulnerabilities. In this 2024 installment, we surveyed over 500 industry experts on the cloud security issues they’re facing. Respondents identified 11 top threats. The CSA Top Threats Working Group has analyzed the results and provided a description of each cloud security threat, including the business impact, key takeaways, examples, and relevant security controls. Top Threats Covered: [...] Join Anthropic, AWS, Google Cloud, Microsoft, SANS, and more this August at the SANS Cloud Security Exchange Summit → # Top Threats to Cloud Computing 2024 Released: 08/05/2024 Top Threats to Cloud Computing 2024 Home Publications Top Threats to Cloud Computing 2024

Visit
orca.security article

Biggest Cloud Security Threats in 2024 | Orca Security

https://orca.security/resources/blog/biggest-cloud-security-threats-to-watch-…

1. Theft of Sensitive Data – AI models rely heavily on training data. Just like in any data storage in the cloud, organizations can unintentionally or intentionally store sensitive information, such as personally identifiable information (PII), payment card information (PCI), private health information (PHI) as well as dev keys, secrets, and tokens. The Orca research team found that 54% of organizations store PII in databases, while 21% of organizations using AWS storage have at least one [...] Using secure key management systems, typically provided by cloud service providers, to store and manage encryption keys adds an extra layer of security. Utilize a secure, centralized vault that supports robust access controls. This ensures that only authorized users and applications have the necessary permissions to access the API keys. [...] The Orca Cloud Security Platform identifies, prioritizes, and remediates risks and compliance issues across your cloud estate spanning AWS, Azure, Google Cloud, Alibaba Cloud, and Kubernetes. Leveraging its patented agentless SideScanning technology, Orca offers comprehensive cloud security coverage detecting vulnerabilities, misconfigurations, lateral movement, API risks, sensitive data at risk, anomalous events and behaviors, and overly permissive identities. Instead of layering multiple

Visit
sentinelone.com article

50+ Cloud Security Statistics in 2026

https://www.sentinelone.com/cybersecurity-101/cloud-security/cloud-security-s…

Public clouds take more hits than private ones. 27% of organizations using public clouds faced security incidents in 2024—that’s up 10% from the year before and includes an average of 43 misconfigurations per account. Private clouds perform better with only 19% experiencing incidents, mainly because you have more control over configurations. However, private clouds still face vendor-related risks and third-party integration problems that can cause trouble. [...] 4. The year-over-year surge in significant cloud breaches reached 154%, with 61% of organizations reporting major incidents in 2024 compared to 24% in 2023. This acceleration indicates both increased attack volume and improving attacker techniques specifically targeting cloud infrastructure.

Visit
crowdstrike.com article

Top 8 Cloud Vulnerabilities

https://www.crowdstrike.com/en-us/cybersecurity-101/cloud-security/cloud-vuln…

As companies increase their use of cloud hosting for storage and computing, the risk of an attack on their cloud services increases because the cloud presents a highly dynamic and distributed landscape. As noted in the CrowdStrike 2024 Global Threat Report, there was a 75% increase in cloud environment intrusions in 2023. The report also revealed a 110% spike in cases involving cloud-conscious threat actors, which are threat actors that are aware of the ability to compromise cloud workloads and [...] CrowdStrike Logo CrowdStrike Logo Search Icon Upcoming events Conference CrowdTour Find a city near you Summit Day Zero 2026 Las Vegas, NV Login cart icon cart icon Your Cart Added to Cart There's nothing in your cart per endpoint / per year per endpoint / per month # Top 8 Cloud Vulnerabilities Karishma Asthana - November 26, 2024 ## Understand CNAPPs with Our Guide ## Understand CNAPPs with Our Guide ## What are cloud vulnerabilities? [...] The top eight cloud vulnerabilities include: Cloud misconfigurations Insecure APIs Lack of visibility Shadow IT Poor access management Malicious insiders Zero-day vulnerabilities Human error ## #1: Cloud misconfigurations

Visit