https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures


cloud security

Cybercriminals Zeroing in on Cloud Data, Resources

  • Written by Edward Gately
  • March 31, 2022

Lacework’s latest quarterly Cloud Threat Report found threat actors are broadening the scope of their efforts to gain illicit access to cloud data and resources.

In addition to increased targeting of cloud platforms beyond AWS, Microsoft Azure and Google Cloud, malicious actors are rapidly adapting new attacks to target organizations in the cloud.

The report highlights vulnerabilities across four areas of cloud security. Those are cloud security posture; vulnerability and software supply chain; runtime threats and linux malware; and proactive defense and intelligence.

Based on anonymized data across the Lacework platform from September 2021 through February 2022, key findings of the report include:

  • Cloud security mistakes are an open door for threat actors. Seventy-two percent of cloud environments monitored had insecure configurations, providing a warm welcome for attackers to gain initial access, establish persistence, escalate privileges and impact protected data across clouds.
  • Your data is not safe in any cloud. Despite being the largest cloud service providers, AWS accounts make up only 16% of overall hosting account resales, while lesser known companies like HostGator and Bluehost make up half. On average, the price of a compromised AWS account is roughly $40, with corporate accounts being offered for as low as $300 and upwards of $30,000.
  • Log4j remains a significant threat, and malware is adapting quickly. Thirty-one percent of malware infections observed by Lacework researchers use Log4j as the initial infection vector. What’s more, Muhstick, the malware family most commonly observed in the wild, can incorporate vulnerabilities like Log4j into their code within 48 hours, reinforcing that this threat will remain an issue over the long term.

James Condon is Lacework’s director of threat research.

“While cloud security isn’t getting worse, our investigations highlighted a marked increase in crimeware involvement in cloud-focused operations and improved capabilities,” he said. “The enhanced business model has extended the offerings of underground markets, allowing for more sharing and reselling of information, access and tooling.”

The security landscape continues to evolve as threat actors become more sophisticated and adept at targeting cloud vulnerabilities in particular, Condon said.

“From Log4j to the escalation in Lapsus$ attacks, high-profile security incidents are heightening security awareness for thousands of enterprises,” he said. “These attacks are a glaring reminder that we cannot overlook the basics of security.”

No security posture is perfect, but there is a lot more companies can be doing to protect themselves, Condon said.

“The latest string of attacks are a good example because they have something in common,” he said. “They leverage user credentials, and abuse those permissions for personal and financial gain. Organizations need to pay attention to two critical things in any security posture: authentication (who are you) and authorization (what can you do). These can seem like basic best practices, but it’s shocking how many organizations aren’t taking these steps. As we see in the latest threat report, attackers are taking advantage of the lack of focus on securing consumer and corporate accounts alike.”

Tags:

Edward Gately

Edward Gately

As news editor, Edward Gately covers cybersecurity, new channel programs and program changes, M&A and other IT channel trends. Prior to Informa, he spent 26 years as a newspaper journalist in Texas, Louisiana and Arizona.

Related Content

  • Dell Latitude 9430
    Dell Optimizer to Enable Simultaneous Network Connections with New Laptops
  • ccaas
    Intelisys Partners Get Access to Google Chrome
  • handshake
    Intel Buying Optimization Software Provider Granulate for Reported $650 Million
  • Images: Aruba Atmosphere Expo Hall Featuring Infosys, Zebra, Inpixon

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Kaseya MSP Survey: Growing Importance of Automation, Cybersecurity Remains Top Challenge

March 30, 2023

Google Cloud Lashes Out at Microsoft, New Hurdle for Broadcom-VMware

March 30, 2023

Dell Adds Apex Managed Device Service to New Commercial PCs

March 30, 2023

Industry Perspectives

View all

AI Spells the End of End User Security

March 30, 2023

Why You Should Include Audiovisual Solutions in Your UC Services

March 28, 2023

Selling Your MSP: Strategic vs. Financial Buyers

March 22, 2023

Webinars

View all

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

Meet the 2023 Channel Futures Channel Influencers

April 13, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Kaseya, Post-Acquisition, Expanding ‘Well-Regarded’ Datto Partner Program

Aryaka ‘Driving Value to the Channel Community’ with Throttle

March 24, 2023

Coffee with Craig and James Episode 121: Hewlett Packard Enterprise

March 23, 2023

Real-Life M&A: Advice for a Successful Channel Deal

March 13, 2023

Twitter

ChannelFutures

.@Dell launches #DellLatitude and OptiPlex PCs, and Precision #workstations, adds Apex Managed Device Service.… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

.@KaseyaCorp #MSP survey shows growing significance of automation, #cybersecurity remains clients' top challenge.… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

.@HP thanks partners, promises to reduce wait times and complexity across organization. #HPAmplify… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

.@Kyndryl #layoffs impacting a percentage of workforce. dlvr.it/SllFbF https://t.co/Bo77KdJMpx

March 30, 2023
ChannelFutures

[email protected] makes #DE&I a priority year-round, not just for @womenshistmonth. “A constant cadence of activism… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

📺 Tune into the latest CFTV episode, brought to you by @HitachiVantara, all about how you can identify your competi… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

“Things that are not possible are possible,” said @Google's @behshad_behzadi at #EnterpriseConnect about generative… twitter.com/i/web/status/1…

March 30, 2023
ChannelFutures

📺 We asked 2023 #ChannelInfluencer @peter_kujawa from Service Leadership what his secret sauce is- his work philoso… twitter.com/i/web/status/1…

March 30, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X