logo

Cloud Attackers Now Prefer Vulnerability Exploits Over Credentials, Google Cloud Finds

ID: dfc4be82-86cd-51d8-a478-0e55f828e4ef

STIX ID: report--dfc4be82-86cd-51d8-a478-0e55f828e4ef

Feed Name: Infosecurity Magazine (News)

Threat Score
80/100

Date Published: 2026-03-10

Date Updated: 2026-04-22

...
...

Google Cloud's H1 2026 Threat Horizons report warns that in H2 2025 attackers increasingly exploited unpatched third‑party software—accounting for 44.5% of primary entry vectors—rather than relying on weak credentials. The report calls out CVE-2025-55182 (React2Shell), a critical remote code execution in React Server Components, which was rapidly mass-exploited by nation-state-linked actors to deploy crypto-mining malware within 48 hours of disclosure, and recommends automated defenses (WAF patching, centralized identity controls, automated posture enforcement) to mitigate fast-moving exploit campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.