Site navigation

New Palo Alto Report Exposes Worrying Cloud Security Gaps

Tom Quinn

,

cloud security vulnerabilities
New research from cybersecurity firm Palo Alto Networks reveals that 80% of ransomware and unauthorised login vulnerabilities were detected on cloud-hosted assets.

Unit 42, the threat intelligence arm of Palo Alto Networks, has released its 2023 Attack Surface Threat Report, finding that the rapid adoption of new cloud services is complicating the cybersecurity landscape and adding to high-risk exposures. 

The research found that organisations are introducing over 300 new cloud services each month, contributing to nearly 32% of high or critical cloud exposures in total. 

The data also shows that in any given month, an average of 20% of an organisation’s cloud attack surface was taken offline and replaced with new or updated services. The deployment of these new services was then generally responsible for nearly half of the organisations’ new high or critical cloud exposures.

Additionally, the report reveals that over 85% of organisations analysed had Remote Desktop Protocol (RDP) internet accessible for at least 25% of the month, leaving them open to ransomware attacks or unauthorised login attempts.

The firm warned that the rapid growth of digital services is complicating the cybersecurity landscape, making it harder for businesses and government entities to keep an accurate inventory of their IT assets, which are prime targets for attackers.

Those attackers are now moving even faster to take advantage of vulnerabilities in cloud systems, scanning targets within minutes to test security capabilities. By comparison, Unit 42 found that the organisations themselves often took more than three weeks to investigate and remediate a critical exposure.

To test how quickly these threat actors worked, researchers analysed thirty Common Vulnerabilities and Exposures (CVEs) in cloud-based systems from May 2022 to May 2023 to see how quickly they were exploited following public disclosure. 

Notably, three of the 30 vulnerabilities were exploited within hours of the CVE public disclosure, while a further nineteen were exploited within 12 weeks. 

Furthermore, while testing vulnerabilities used by ransomware operators, the researchers observed threat actors targeting three critical vulnerabilities within hours of disclosure, while another six were exploited within eight weeks of publication.


Recommended reading


Attackers are also making more use of weaknesses in remote access infrastructure, with 20% of exposures beginning this way. These exposures include using services like Secure Shell (SSH), or virtual network computing, which, when compromised, allow attackers to gain unauthorised access to an organisation’s network or systems, potentially leading to financial losses and reputational damage.

Other methods of entry for threat actors included using IT and networking infrastructure vulnerabilities (17%), incidents of file sharing (12%), and database exposures (9%). These security gaps, especially in remote access services, were observed to allow threat actors opportunities to release ransomware and other malicious files into the cloud.  

To combat the threat posed to such systems, the report recommends that organisations maintain complete and up-to-date inventories of assets both on-premises and in the cloud to ensure security policies are followed, as well as continually monitoring remote access points.

Most critical is the ability to match the speed of attackers in patching commonly known vulnerabilities. Quickly understanding risk exposure and using up to date attack surface management tools can provide the security edge that organisations need.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data