logo

Top Cloud Native Threats and Vulnerabilities of 2024

ID: 70cde8b7-95fe-50af-88b1-baa18e250621

STIX ID: report--70cde8b7-95fe-50af-88b1-baa18e250621

Feed Name: Aqua Security Blog

Threat Score
80/100

Date Published: 2025-02-23

Date Updated: 2026-04-26

...
...

**Executive Summary:** This report summarizes seven prominent cloud-native threats and vulnerabilities from 2024 — including perfctl (cryptojacking malware exploiting Polkit), Bucket Monopoly (AWS "shadow resource" vulnerabilities enabling account compromise), Snap Trap (Ubuntu package-suggestion abuse), Hadooken (WebLogic-targeting malware), GitHub repository secret exposures, a critical CUPS RCE, and the Lucifer campaign targeting Hadoop/Druid — and provides mitigation recommendations such as network segmentation, secrets scanning, removing or restricting vulnerable services, and enforcing runtime policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.