The Honeymoon for Cloud Services Is Over


The cloud services you rely on are no longer as secure as they used to be. Once seemingly a safe haven for data and applications, attackers are increasingly leveraging cloud services for command and control—and the Symantec Threat Hunter Team predicts an unnerving upshoot in 2025.

The Microsoft breach by Russian nation-state actors is one instance of many that show how even widely trusted cloud service providers (CSPs) can fall victim to targeted attacks. The implications of this rising trend are great, both for CSPs and for the SaaS systems and apps they host. Recent breaches, like those impacting Ticketmaster and Santander, underscore the fact that organizations are exposed to cascading risks in digital supply chains.

Read more…
Source: Symantec


Sign up for our Newsletter


Related:

  • Healthcare data breach exposes 3.75M patient records

    August 30, 2026

    Hackers stole medical records, Social Security numbers, government IDs and financial data from millions of CareCloud patients You can be careful with your passwords and still get caught in a breach at a company you may have never heard of. That is one of the frustrating parts of the CareCloud data breach. More than 3.75 million ...

  • McDonald’s, Vodafone, TCS, Kyndryl, and others named as researchers point to compromised credentials

    August 17, 2026

    A cybercrook claims to have siphoned millions of employee records from the Microsoft Azure environments of major companies including McDonald’s, Vodafone, Kyndryl, and Tata Consultancy Services. The alleged haul spans nine organizations and is being advertised for sale by a threat actor using the name “TheHatman,” according to research published by Hudson Rock. McDonald’s accounts for the largest ...

  • How legitimate cloud platforms enable phishers to bypass MFA

    August 4, 2026

    Threat actors are increasingly exploiting legitimate cloud services to evade detection and streamline the deployment of their scam infrastructure. Cloud hosting services and decentralized networks have become primary platforms for hosting phishing pages and sites. Throughout 2025 and 2026, Kaspersky researchers have observed phishing operators steadily migrate toward platforms like Cloudflare Workers, Vercel, Netlify, GitHub ...

  • Rental giant Carla leaks user names, emails, and phone numbers ahead of summer holiday break

    July 22, 2026

    Car rental comparison and booking platform Carla kept a database with sensitive customer information unlocked on the open internet, freely available to anyone who knew where to look. Cybersecurity researchers from Cybernews reported finding an exposed Amazon Web Services (AWS) bucket with approximately 48,000 PDF files. These files, which was later determined belonged to Carla, contained car rental details ...

  • CAI cloud worm gives competitors’ malware the boot, then steals secrets and mines for coin

    July 7, 2026

    There’s no honor among thieves as a new worm steals from other infectious software. It pilfers “multiple” victims’ credentials and mines for cryptocurrency while killing competitors’ processes, including similar secret-harvesting malware. It’s called Cloud AI Infrastructure Attack Framework (CAI), and it’s a centralized botnet that targets cloud-native developer tools like Docker, Kubernetes, Redis, etcd, Kubelet, and ...

  • Confidential computing’s core trust mechanism is broken. The fix may not exist

    July 4, 2026

    Vendors are trying to position “confidential computing” as the technical backbone of Europe’s sovereign cloud ambitions. But new research shows that a security protocol used to prove cryptographic trust in the system may have a fundamental architectural flaw. Confidential computing rests on a mechanism called remote attestation, in which a server cryptographically proves to a client ...