Cloud Attackers Now Prefer Vulnerability Exploits Over Credentials, Google Cloud Finds
ID: dfc4be82-86cd-51d8-a478-0e55f828e4ef
STIX ID: report--dfc4be82-86cd-51d8-a478-0e55f828e4ef
Feed Name: Infosecurity Magazine (News)
Google Cloud's H1 2026 Threat Horizons report warns that in H2 2025 attackers increasingly exploited unpatched third‑party software—accounting for 44.5% of primary entry vectors—rather than relying on weak credentials. The report calls out CVE-2025-55182 (React2Shell), a critical remote code execution in React Server Components, which was rapidly mass-exploited by nation-state-linked actors to deploy crypto-mining malware within 48 hours of disclosure, and recommends automated defenses (WAF patching, centralized identity controls, automated posture enforcement) to mitigate fast-moving exploit campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
