Expel Quarterly Threat Report, Q1 2025: Cloud infrastructure trends
ID: de1a3246-dcc2-5488-80e4-f00093f82b03
STIX ID: report--de1a3246-dcc2-5488-80e4-f00093f82b03
Feed Name: Expel Blog
This Q1 2025 Quarterly Threat Report (part four) analyzes cloud infrastructure as an attack surface, noting lower volume but meaningful incidents driven by secret/key exposure, misconfigurations, and server-side vulnerabilities; common outcomes include rapid cryptominer deployment and increasing cases of S3 bucket ransomware leveraging exposed AWS keys. The report highlights attacker use of publicly-available secret-finding tools like Trufflehog, emphasizes the monetization limits of cloud compromise, and recommends proactive secret scanning, short-lived credentials, least privilege, and improved monitoring and logging.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
