Cloud Threat Landscape
A Candid Perspective on the Cloud Threat Landscape: What’s Real, What’s Not, and What Should Change
What's a threat landscape
It's a view of current threats, real incidents, adversary behaviors and trends.
What's the problem with cloud? It's fragmented, underdeveloped and hard to find things.
Key Observations
- Identity and Standing Access Exploitation
- SaaS is the new data plane
-
Pipeline platform and supply chain integrity
-
The good: The big part of reports include detections and security considerations
- The bad: Not a lot of reports include threat actors. Not a lot of mapping on MITRE ATTACK.
- The ugly: The big cloud vendors don't report on cloud specific threats