Cloud Threats on the Rise: Alert Trends Show Intensified Attacker Focus on IAM, Exfiltration
ID: c81eaf55-7cf2-5d82-a115-8a6b53fca1ae
STIX ID: report--c81eaf55-7cf2-5d82-a115-8a6b53fca1ae
Feed Name: Palo Alto Networks Unit 42
This Unit 42 report analyzes 2024 cloud alert trends, noting a 388% increase in total alerts and a 235% rise in high-severity events, driven by identity-centric runtime activity such as remote command-line usage of serverless IAM tokens, suspicious multi-object storage downloads (+305%), snapshot exports (+45%), impossible travel (+116%), and out-of-region compute API calls (+60%). Emphasizing identity as the cloud perimeter, it observes attackers increasingly harvesting and abusing IAM and service account credentials to enable lateral movement, data theft, and extortion, and cites CTAG activity as context. The report urges combining CSPM with runtime Cloud Detection and Response, deploying agents on critical endpoints, enabling comprehensive audit logging, restricting regions, enforcing least privilege for service accounts, and ensuring storage versioning and encryption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
