Article

    Cyber News / Article / Cloud Attacks Retrospective: Evolving Tactics, Familiar Entry Points

    Cloud Attacks Retrospective: Evolving Tactics, Familiar Entry Points
    Wi
    Wiz Threat Research-2025-06-18

    Cloud Attacks Retrospective: Evolving Tactics, Familiar Entry Points

    Let's break down eight attack patterns security teams should be watching in 2025.

    Cloud environments are growing more complex—but attackers aren’t necessarily getting more advanced. Instead, they’re applying creativity to familiar weaknesses: misconfigurations, unpatched systems, and credential misuse.

    That’s the key theme in Wiz’s newly releasedCloud Attack Retrospective: 8 Common Threats to Watch for in 2025,a data-driven analysis of real-world cloud attacks based on detections across thousands of environments. The report maps eight of the most frequently observed MITRE ATT&CK techniques to specific threat campaigns, CVEs, and persistent trends across the cloud ecosystem.

    Here’s a preview of what stood out:

    Following the disclosure ofCVE-2024-0012andCVE-2024-9474in PAN-OS, Wiz observed attackers deploying web shells andSliver implantsjust days after PoCs went public.

    24%of monitored environments contained vulnerable PAN-OS appliances.

    7%were internet-facing and exploitable via unauthenticated RCE.

    These cases show how quickly attackers pivot from disclosure to exploitation—especially when edge infrastructure is exposed.

    TheCPU_HU campaigntargeted weak PostgreSQL configurations, exploiting default or guessable credentials to deploycryptominers.

    90%of cloud environments analyzed use self-managed PostgreSQL.

    Nearlyone-thirdhad at least one instance exposed publicly.

    This underscores how foundational hardening steps—like restricting access and enforcing credential policies—remain critical.

    Phishing remains the top cause of identity-based cloud breaches.

    0ktapusused spoofed SSO portals to harvest credentials.

    Atlas Lionemployed adversary-in-the-middle proxies and smishing to bypass MFA.

    Even with modern defenses, user-targeted phishing continues to yield high success rates in cloud environments.

    Persistence is no longer an afterthought—it’s embedded from the start.

    In Redis and Jenkins environments, attackers usedcron jobsto relaunch cryptominers on reboot.

    Selenium Gridinstances without authentication were abused to execute payloads via browser automation.

    Simple, resilient techniques continue to evade detection—especially when deployed on services with limited monitoring.

    TheCloud Attack Retrospective: 8 Common Threats to Watch for in 2025includes:

    Detailed analysis of thetopMITRE ATT&CKtechniquesabused by actors in the cloud

    Real-world incidents tied to specificCVEs, misconfigurations, and IAM abuse

    Campaigns involvingDiicot,Bapak,0ktapus, and more

    Practical guidance on how to detect and disrupt attack chains in your environment

    Drawing from detection data across thousands of organizations, we highlight eight commonly observed MITRE ATT&CK techniques and offer practical guidance on how Wiz can help to detect and mitigate them.

    How has AI-assisted development impacted secrets leakage? Learn the new patterns and emerging trends.

    Wiz is now included in the NVIDIA Enterprise AI Factory validated design, integrating with NVIDIA AI to help developers securely build and deploy enterprise AI agents at scale.

    As cloud adoption accelerates, security operations teams must rethink their people, processes, and technology to enable effective Cloud Detection and Response (CDR) and secure their evolving cloud attack surface.

    Get a personalized demo

    ©2026Wiz, Inc.

    StatusPrivacy PolicyTerms of UseModern Slavery StatementCookie Settings

    Original source

    Cloud Attacks Retrospective: Evolving Tactics, Familiar… | CVE-DB