Why Cloud Misconfigurations Remain A Top Cause Of Data Breaches


It’s 2025, and the industry has built some of the most advanced cloud environments ever seen—automated deployments, real-time threat detection and infrastructure that scales with just a few lines of code.

Yet, data breaches aren’t slowing down—why? Because a single misconfiguration—often as simple as an overly permissive IAM role or an exposed storage bucket—can wreck everything. In fact, cloud misconfigurations are often termed as a “technical oversight.” But they’re a systemic failure—a gap between how we build, secure and perceive risk in the cloud.

Read more…
Source: Forbes News


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Siloscape: First Known Malware Targeting Windows Containers to Compromise Cloud Environments

    June 7, 2021

    In March 2021, I uncovered the first known malware targeting Windows containers, a development that is not surprising given the massive surge in cloud adoption over the past few years. I named the malware Siloscape (sounds like silo escape) because its primary goal is to escape the container, and in Windows this is implemented mainly ...

  • TeamTNT Actively Enumerating Cloud Environments to Infiltrate Organizations

    June 4, 2021

    TeamTNT has been evolving their cloud-focused cryptojacking operations for some time now. TeamTNT operations have targeted and, after compromise, exfiltrated AWS credentials, targeted Kubernetes clusters and created new malware called Black-T that integrates open source cloud native tools to assist in their cryptojacking operations. TeamTNT operations are now using compromised AWS credentials to enumerate AWS cloud ...

  • HTTPS over HTTP: A Supply Chain Attack on Azure DevOps Server 2020

    April 13, 2021

    The need for data encryption during transmission has paved the way for organizations to rely on TLS — not just for sending data through the internet, but even within trusted corporate environments. Without the use of TLS or SSL, the authenticity of transmitted data and the identity of endpoint can’t be verified. In this blog, we ...

  • Cloud-Based Storage Misconfigurations – Understanding the Security Risks and Responses

    March 1, 2021

    Misconfigurations remain one of the most common risks in the technology world. Simply telling organisations to “fix” this problem, however, is not as easy as it might first seem because there’s a myriad of technologies at play in modern infrastructure deployments. All of this results in a complicated mix of hardening approaches for each system. What ...

  • Microsoft: SolarWinds Attackers Downloaded Azure, Exchange Code

    February 19, 2021

    Threat actors downloaded some Microsoft Exchange and Azure code repositories during the sprawling SolarWinds supply-chain attack but did not use the company’s internal systems or products to attack other victims. That’s the final verdict this week by the tech giant now that it’s completed a comprehensive investigation into the attack, which was discovered in December and ...

  • Cybersecurity Risks of Connected Cars

    February 16, 2021

    As the use of connected cars becomes more common, the technologies that power or support these vehicles continue to evolve. This provides a host of benefits, but just like any other technology, this new territory comes with some risks. In our paper, we add some substantial information to our research from last year, in order ...