Google: Cloud attacks exploit flaws more than weak credentials
ID: ac48db2d-32cf-53b5-bf49-8dd38faf694e
STIX ID: report--ac48db2d-32cf-53b5-bf49-8dd38faf694e
Feed Name: Bleeping Computer
Google's cloud threat report shows attackers increasingly exploiting newly disclosed third‑party vulnerabilities (primarily RCEs such as React2Shell and an XWiki flaw) to gain fast initial access to cloud environments, with exploitation windows collapsing from weeks to days; state‑sponsored groups (e.g., UNC1549, UNC5221, UNC4899) and financially motivated actors used malware, supply‑chain compromises (s1ngularity), OpenID Connect abuse, and stolen credentials to maintain long persistence, exfiltrate large volumes of data (including ~1 TB and millions in cryptocurrency), and evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
