logo

Google: Cloud attacks exploit flaws more than weak credentials

ID: ac48db2d-32cf-53b5-bf49-8dd38faf694e

STIX ID: report--ac48db2d-32cf-53b5-bf49-8dd38faf694e

Feed Name: Bleeping Computer

Threat Score
86/100

Date Published: 2026-03-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Google's cloud threat report shows attackers increasingly exploiting newly disclosed third‑party vulnerabilities (primarily RCEs such as React2Shell and an XWiki flaw) to gain fast initial access to cloud environments, with exploitation windows collapsing from weeks to days; state‑sponsored groups (e.g., UNC1549, UNC5221, UNC4899) and financially motivated actors used malware, supply‑chain compromises (s1ngularity), OpenID Connect abuse, and stolen credentials to maintain long persistence, exfiltrate large volumes of data (including ~1 TB and millions in cryptocurrency), and evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.