logo

Cloud Decoded (part 2): What attackers don’t want you to know

ID: e3ee5abf-6052-5a29-99fe-80eb161a7f95

STIX ID: report--e3ee5abf-6052-5a29-99fe-80eb161a7f95

Feed Name: Expel Blog

Date Published: 2025-06-27

Date Updated: 2026-04-27

Author: Sarah Crone

...
...

**Executive summary:** This blog post (Part Two of Expel's "Cloud Decoded" series) reviews four common cloud attack vectors—control plane compromises, container/Kubernetes exploits, SaaS account takeovers, and over‑permissioned identities—and describes how Expel's MDR/CDR capabilities ingest cloud telemetry, detect anomalous API/IAM and container activity, correlate identity and SaaS logs, and provide actionable remediation guidance to reduce risk and harden cloud environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.