logo

Lateral movement risks in the cloud and how to prevent them – Part 1: the network layer (VPC)

ID: cd5ba6f1-a79e-50cb-a473-9a2c7de55c9c

STIX ID: report--cd5ba6f1-a79e-50cb-a473-9a2c7de55c9c

Feed Name: Wiz Blog

Date Published: 2022-10-13

Date Updated: 2026-05-01

...
...

Wiz Research outlines how adversaries conduct lateral movement within and across cloud VPCs by abusing remote services (SSH/RDP), worms, valid cloud/IAM accounts and keys, VPC peering, and exploitable vulnerabilities/misconfigurations; it contrasts cloud vs. on‑prem (IAM, rapid deployments, and visibility challenges), cites findings that 58% of environments have publicly exposed workloads with cleartext long-term cloud keys, and recommends five network best practices—strict security groups/ACLs, removal of cleartext keys via least-privileged roles and managed access, fast remediation of critical vulnerabilities, VPC-based isolation, and using private link over broad peering—to reduce attack surface and blast radius.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.