• Tech News
    • Games
    • Pc & Laptop
    • Mobile Tech
    • Ar & Vr
    • Security
  • Startup
    • Fintech
  • Reviews
  • How To
What's Hot

Elementor #32036

January 24, 2025

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

April 18, 2024

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

April 16, 2024
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
    1. Games
    2. Pc & Laptop
    3. Mobile Tech
    4. Ar & Vr
    5. Security
    6. View All

    Bring Elden Ring to the table with the upcoming board game adaptation

    September 19, 2022

    ONI: Road to be the Mightiest Oni reveals its opening movie

    September 19, 2022

    GTA 6 images and footage allegedly leak

    September 19, 2022

    Wild west adventure Card Cowboy turns cards into weird and silly stories

    September 18, 2022

    7 Reasons Why You Should Study PHP Programming Language

    October 19, 2022

    Logitech MX Master 3S and MX Keys Combo for Business Gen 2 Review

    October 9, 2022

    Lenovo ThinkPad X1 Carbon Gen10 Review

    September 18, 2022

    Lenovo IdeaPad 5i Chromebook, 16-inch+120Hz

    September 3, 2022

    It’s 2023 and Spotify Still Can’t Say When AirPlay 2 Support Will Arrive

    April 4, 2023

    YouTube adds very convenient iPhone homescreen widgets

    October 15, 2022

    Google finishes iOS 16 Lock Screen widgets rollout w/ Maps

    October 14, 2022

    Is Apple actually turning iMessage into AIM or is this sketchy redesign rumor for laughs?

    October 14, 2022

    MeetKai launches AI-powered metaverse, starting with a billboard in Times Square

    August 10, 2022

    The DeanBeat: RP1 simulates putting 4,000 people together in a single metaverse plaza

    August 10, 2022

    Improving the customer experience with virtual and augmented reality

    August 10, 2022

    Why the metaverse won’t fall to Clubhouse’s fate

    August 10, 2022

    How Apple privacy changes have forced social media marketing to evolve

    October 16, 2022

    Microsoft Patch Tuesday October Fixed 85 Vulnerabilities – Latest Hacking News

    October 16, 2022

    Decentralization and KYC compliance: Critical concepts in sovereign policy

    October 15, 2022

    What Thoma Bravo’s latest acquisition reveals about identity management

    October 14, 2022

    What is a Service Robot? The vision of an intelligent service application is possible.

    November 7, 2022

    Tom Brady just chucked another Microsoft Surface tablet

    September 18, 2022

    The best AIO coolers for your PC in 2022

    September 18, 2022

    YC’s Michael Seibel clarifies some misconceptions about the accelerator • DailyTech

    September 18, 2022
  • Startup
    • Fintech
  • Reviews
  • How To
Behind The ScreenBehind The Screen
Home»Tech News»Cloud compromise a doddle for threat actors as victims attest
Tech News

Cloud compromise a doddle for threat actors as victims attest

September 13, 2022No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Cloud compromise a doddle for threat actors as victims attest
Share
Facebook Twitter LinkedIn Pinterest Email

It takes an average of just three steps for a threat actor to infiltrate a target cloud environment and get to its “crown jewel” assets, and as a result, vast numbers of organisations are now experiencing cloud security incidents, with at least 80% reporting a “severe” incident in the past 12 months.

This is according to two different reports on the state of cloud security released today by sector specialists Orca Security and Snyk, both of which reveal fresh insight into the cyber risks and challenges brought to the fore by widespread cloud adoption, and how security teams are grappling with them.

Orca’s report, compiled by its aptly named Research Pod, analyses workload and configuration data captured from billions of assets on AWS, Azure and Google Cloud in the first seven months of 2022, to identify where gaps exist and what security teams can do to fill them in.

Besides the concerning idea that a threat actor needs only to chain three connected and exploitable weaknesses in a cloud environment to wreak potentially terminal havoc, Orca found the vast majority (78%) of these attack paths began with a known common vulnerability or exposure (CVE) as the initial vector, suggesting organisations are, as ever, failing to patch appropriately.

It also found that organisations continue to leave their cloud storage assets, such as AWS S3 Buckets and Azure Blobs, completely exposed to the public internet, and are not implementing basic security measures such as multi-factor authentication (MFA), encryption and port scanning.

In addition, Orca found that organisations tend to overlook cloud-native services, likely because even though they are easy to spin up, they need regular oversight and configuration.

See also  MI5, FBI chiefs warn of Chinese cyber espionage threat

Some 58% of organisations have serverless functions with unsupported runtimes, and 70% have a publicly accessible Kubernetes API.

Avi Shua, CEO and co-founder of Orca, said: “The security of the public cloud not only depends on cloud platforms providing a safe cloud infrastructure, but also very much on the state of an organisation’s workloads, configurations and identities in the cloud.

”There is still much work to be done in this area, from unpatched vulnerabilities and overly permissive identities, to storage assets being left wide open. It is important to remember, however, that organisations can never fix all risks in their environment. They simply don’t have the manpower to do this. Instead, organisations should work strategically and ensure that the risks that endanger the organisation’s most critical assets are always patched first.”

Besides its headline statistic – that four-fifths of organisations have experienced a severe cloud security incident – be that a data breach, leak, or intrusion – in the past 12 months, Snyk’s report also found that 58% of respondents felt cloud-based risk was likely to grow in the next 12 months, and 25% were worried they had recently suffered a cloud data breach but were unaware of it.

Snyk also found evidence of some scepticism about cloud-native approaches, with 41% saying they introduced more complexity and complication to their efforts around security, particularly in terms of training and collaboration, and access to engineering resources.

However, where respondents had worked to improve their cloud security, they found multiple benefits, including increased collaboration, enhanced productivity and faster innovation.

See also  U.S CFTC charges South African company over $1.7 billion bitcoin ponzi scheme – DailyTech

“This new research should serve as a wake-up call that our collective cloud security risk is universal and will only continue to grow if we double down on outdated approaches and legacy tools,” said Josh Stella, vice-president and chief architect at Snyk.

“The outlook is not entirely dire, however, as the data also clearly reveals that shifting cloud security left and embracing DevSecOps collaboration can allow global organisations to continue their current pace of innovation more securely.”

Snyk’s report was based on a study of more than 400 cloud engineering and security practitioners, as well as leaders from various organisation types and industries.

Source link

actors attest Cloud compromise doddle threat victims
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

What Parents Of Young Actors Should Know About The SAG-AFTRA Strike

August 21, 2023

How to Help and Donate to Wildfire Victims in Hawaii

August 20, 2023

The Cloud Is a Prison. Can the Local-First Software Movement Set Us Free?

August 6, 2023

Logitech G Cloud review

July 20, 2023
Add A Comment

Comments are closed.

Editors Picks

When the Big One Hits Portland, Cargo Bikers Will Save You

September 13, 2022

The Valiant gets overview trailer showing off more crusader adventures

August 13, 2022

Ghost voyeur game The Future You’ve Been Dreaming Of launches for PC in July

June 26, 2022

Monster Hunter Rise: Sunbreak Title Update 2 releasing at the end of September, adds Flaming Espinas

August 27, 2022

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Elementor #32036

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2025 behindthescreen.uk - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.