Threat actors are recruiting the people who hold cloud logins
ID: a539f8e6-dff5-5caf-ac3f-3788b39165de
STIX ID: report--a539f8e6-dff5-5caf-ac3f-3788b39165de
Feed Name: Help Net Security
Intel 471 outlines rising cloud-centric insider risk through three categories (negligent, manipulated, malicious), documenting active credential theft and resale via info-stealers (Vidar, Stealc_v2, ACR), adversary-in-the-middle and reverse-proxy phishing kits targeting Okta/Google Workspace, and underground recruitment/auctions for insider access; recommended mitigations include least-privilege permissions reviews, centralized third-party app inventories, immediate offboarding, SaaS usage monitoring, and enforcement of phishing-resistant MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
