Cyber News / Article / Cloud Attacks Retrospective: Evolving Tactics, Familiar Entry Points

Cloud Attacks Retrospective: Evolving Tactics, Familiar Entry Points
Let's break down eight attack patterns security teams should be watching in 2025.
Cloud environments are growing more complex—but attackers aren’t necessarily getting more advanced. Instead, they’re applying creativity to familiar weaknesses: misconfigurations, unpatched systems, and credential misuse.
That’s the key theme in Wiz’s newly releasedCloud Attack Retrospective: 8 Common Threats to Watch for in 2025,a data-driven analysis of real-world cloud attacks based on detections across thousands of environments. The report maps eight of the most frequently observed MITRE ATT&CK techniques to specific threat campaigns, CVEs, and persistent trends across the cloud ecosystem.
Here’s a preview of what stood out:
Following the disclosure ofCVE-2024-0012andCVE-2024-9474in PAN-OS, Wiz observed attackers deploying web shells andSliver implantsjust days after PoCs went public.
24%of monitored environments contained vulnerable PAN-OS appliances.
7%were internet-facing and exploitable via unauthenticated RCE.
These cases show how quickly attackers pivot from disclosure to exploitation—especially when edge infrastructure is exposed.
TheCPU_HU campaigntargeted weak PostgreSQL configurations, exploiting default or guessable credentials to deploycryptominers.
90%of cloud environments analyzed use self-managed PostgreSQL.
Nearlyone-thirdhad at least one instance exposed publicly.
This underscores how foundational hardening steps—like restricting access and enforcing credential policies—remain critical.
Phishing remains the top cause of identity-based cloud breaches.
0ktapusused spoofed SSO portals to harvest credentials.
Atlas Lionemployed adversary-in-the-middle proxies and smishing to bypass MFA.
Even with modern defenses, user-targeted phishing continues to yield high success rates in cloud environments.
Persistence is no longer an afterthought—it’s embedded from the start.
In Redis and Jenkins environments, attackers usedcron jobsto relaunch cryptominers on reboot.
Selenium Gridinstances without authentication were abused to execute payloads via browser automation.
Simple, resilient techniques continue to evade detection—especially when deployed on services with limited monitoring.
TheCloud Attack Retrospective: 8 Common Threats to Watch for in 2025includes:
Detailed analysis of thetopMITRE ATT&CKtechniquesabused by actors in the cloud
Real-world incidents tied to specificCVEs, misconfigurations, and IAM abuse
Campaigns involvingDiicot,Bapak,0ktapus, and more
Practical guidance on how to detect and disrupt attack chains in your environment
Drawing from detection data across thousands of organizations, we highlight eight commonly observed MITRE ATT&CK techniques and offer practical guidance on how Wiz can help to detect and mitigate them.
How has AI-assisted development impacted secrets leakage? Learn the new patterns and emerging trends.
Wiz is now included in the NVIDIA Enterprise AI Factory validated design, integrating with NVIDIA AI to help developers securely build and deploy enterprise AI agents at scale.
As cloud adoption accelerates, security operations teams must rethink their people, processes, and technology to enable effective Cloud Detection and Response (CDR) and secure their evolving cloud attack surface.
Get a personalized demo
©2026Wiz, Inc.
StatusPrivacy PolicyTerms of UseModern Slavery StatementCookie Settings
Related articles
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
4 days ago
Your Cloud Security Checklist Doesn't Work the Way You Think It Does
4 days ago
PaperCut Flaws Exploited in AI-Powered Attacks
about 7 hours ago
You might Also like

Russia-Aligned Hackers Use GuardBreaker Prompt Injection to Disrupt AI Malware Analysis

In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

