logo

Cloud attack trends: What you need to know and how to stay resilient

ID: bfcb3762-8410-5af6-9128-813596f491fc

STIX ID: report--bfcb3762-8410-5af6-9128-813596f491fc

Feed Name: Expel Blog

Threat Score
65/100

Date Published: 2021-05-25

Date Updated: 2026-04-27

Author: Anthony Randazzo

...
...

Expel reviews cloud threat trends observed between March 2020 and March 2021, identifying three primary risks: Business Email Compromise (particularly against O365 due to legacy auth), compromises of cloud identity providers (Okta/SSO) including session/token interception and push fatigue, and control-plane access to cloud infrastructure (exposed keys and excessive IAM privileges). The post emphasizes remediation steps (credential resets, terminating sessions, removing forwarding rules, rotating keys, snapshotting/removing attacker-created infra) and resilience measures (MFA, disable legacy protocols, adaptive/app-level MFA, least-privilege IAM, secret scanning and Security Hub automation).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.