Article

    Cyber News / Article / Cloud Threats Retrospective 2026: What AI Changed (and What It Didn’t)

    Cloud Threats Retrospective 2026: What AI Changed (and What It Didn’t)
    Wi
    Wiz Threat Research-2026-04-09

    Cloud Threats Retrospective 2026: What AI Changed (and What It Didn’t)

    Insights from public incidents, cloud telemetry, and investigations into how cloud risk evolved in 2025

    In our latestCloud Threats Retrospective, we analyzed publicly documented cloud incidents alongside cloud telemetry and hands-on investigations. The findings show thatmany of the risks driving attacker activity remained familiar, even as the environments and conditions around them changed.

    Across the cloud incidents analyzed in 2025,the majority of initial access stemmed from well-known weaknesses, including vulnerabilities, exposed secrests, and misconfigurations. These entry points were not novel, but they remained highly effective, accounting for roughly80% of documented cloud intrusions.

    What changed was not the existence of these risks, but the environments in which they appeared and the speed at which they could be exploited.

    Several of the most consequential incidents of the year showed howsystemic weaknesses can amplify impact far beyond a single environment. When attackers gained access through shared infrastructure, trusted integrations, or widely used components, a single weakness could cascade across many organizations.

    These incidents reinforced an important shift: understanding cloud risk now requires looking beyond individual assets to therelationships and dependenciesthat connect them.

    AI did not appear to introduce an entirely new class of cloud risk in 2025, but itexpanded the cloud attack surface in meaningful ways. New AI services, pipelines, identities, and data paths increased the number of places where familiar issues such as misconfigurations or exposed credentials could emerge, often closer to sensitive data and high-value workloads.

    As AI adoption accelerated, many organizations found themselves managing new components faster than security practices could fully adapt.

    In incidents analyzed by Wiz Research, AI was most often observedsupporting and accelerating existing attacker behaviors, such as reconnaissance, automation, and post-access activity. These capabilities reduced friction and effort in certain stages of an intrusion, but they largely built on techniques defenders already recognize.

    The takeaway from 2025 is not that everything stayed the same. Rather,familiar risks, when combined with scale, shared trust, and AI-driven environments, can lead to dramatic security outcomes.

    Security teams that maintain visibility into exposure, identities, and how risk propagates across cloud, development, and AI systems are better positioned to detect and disrupt attacker activity before it escalates.

    Wiz research deep dives into cloud intrusions in 2025 to explore how systemic weaknesses and AI amplified the impact of proven cloud threats.

    Wiz and cybersecurity thought leader and practitioner, Chris Hughes, break down the most significant cloud threat trends of 2025 and explore how security leaders should respond.

    Giving developers and security teams a shared view of application risk as it evolves.

    After hackerbot-claw, another AI-powered campaign exploiting pull_request_target confirms the threat is here to stay. We trace the attacker back to three weeks before anyone noticed.

    A compromised axios maintainer account led to malicious npm releases that propagated across environments. Learn how to assess impact, detect compromise, and secure your development workflows.

    Get a personalized demo

    ©2026Wiz, Inc.

    StatusPrivacy PolicyTerms of UseModern Slavery StatementCookie Settings

    Original source