logo

The 2020 State of Cloud (In)Security

ID: 6ce2c203-3aab-5e0f-8e18-0b42c4822327

STIX ID: report--6ce2c203-3aab-5e0f-8e18-0b42c4822327

Feed Name: Zscaler Security Research Blog

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ analyzed telemetry from hundreds of thousands of cloud workloads and found pervasive misconfigurations—notably 63% of users lacking MFA, 50% not rotating access keys, 92% of storage buckets without access logging, ~26% of hosts exposing SSH and ~20% exposing RDP—that materially increase compromise risk. The report highlights four primary failure areas (logging/monitoring, excessive permissions, storage/encryption, and network security groups) and recommends pragmatic mitigations such as enabling persistent logging and alerts, enforcing MFA and key rotation, encrypting storage and backups, applying least-privilege access, restricting inbound/outbound network rules, and moving toward ZTNA to eliminate external attack surface.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.