Cyber Attackers Exploit Cloud APIs with Advanced Phishing Tactics

ReliaQuest’s recently published report reveals disturbing methods employed by cyber attackers to exploit cloud environments, shedding light on some sophisticated tactics they use to bypass security measures. Analyzing true-positive alerts from December 2023 to September 2024, the report particularly focuses on how initial access and discovery commands are executed against public-facing cloud APIs. Notably, 28% of these alerts originated from self-service password reset requests, signaling determined attempts to gain administrator privileges. Within Kubernetes environments, the GetVersion command emerged in 31% of alerts, indicating active probing for software vulnerabilities.

A significant revelation from the report points to the extensive use of known malicious IP addresses in over half of the analyzed attacks, illustrating frequent scanning for exploitable vulnerabilities. A novel phishing technique has also come to light, involving the use of cloud-storage SaaS platforms like OneNote through SharePoint or Google Drive to host malicious links. Attackers skillfully employ phishing emails to direct recipients to these legitimate platforms, which complicates detection efforts for traditional security systems.

The Evolution of Phishing Tactics

Phishing, constituting 71.1% of the observed techniques in 2023, exploits users’ trust in familiar platforms such as Google Drive or Dropbox. Traditional email filtering systems may not consistently recognize these emails as malicious, permitting them to evade initial lines of defense. Recognizing this, ReliaQuest has developed detection rule libraries and GreyMatter containment and response playbooks to bolster security measures, operating independently of standard email tools.

The report underscores the menace of cloud environment hijacking, which could lead to misuse for activities like cryptocurrency mining or launching additional phishing schemes utilizing compromised resources. To counter these threats, strict monitoring and effective management of API keys are imperative. Implementing API gateways equipped with SSL certificates is recommended for added layers of identity verification, providing a more secure shield against potential intrusions.

Strategic Security Enhancements

ReliaQuest’s latest report uncovers alarming methods cyber attackers use to compromise cloud environments, highlighting sophisticated tactics to bypass security defenses. Analyzing true-positive alerts from December 2023 to September 2024, the report emphasizes the strategies used in initial access and discovery commands targeting public-facing cloud APIs. Strikingly, 28% of these alerts stemmed from self-service password reset requests, suggesting determined efforts to acquire administrator privileges. In Kubernetes systems, the GetVersion command appeared in 31% of alerts, signifying active probing for software weaknesses.

The report also highlights the pervasive use of known malicious IP addresses in over half of the analyzed attacks, underscoring frequent scans for vulnerabilities. Additionally, a new phishing technique has emerged, leveraging cloud-storage SaaS platforms like OneNote via SharePoint or Google Drive to host malicious links. Attackers craft phishing emails directing victims to these legitimate platforms, complicating detection for traditional security systems. This evolving threat landscape underscores the need for enhanced security measures to protect cloud environments.

Explore more

Global AI Adoption Hits Eighty-One Percent in Finance Sector

The global financial landscape has reached a definitive tipping point where artificial intelligence is no longer a peripheral innovation but the very bedrock of institutional infrastructure and competitive strategy. According to the comprehensive 2026 Global AI in Financial Services Report, an unprecedented 81% of financial organizations have now integrated AI into their core operations, marking the end of the experimental

Anthropic and Perplexity Launch AI Agents for Finance

The traditional image of a weary junior analyst hunched over a flickering terminal at three in the morning is rapidly fading into the annals of financial history as a new digital workforce takes the helm. This evolution represents a fundamental pivot in the capabilities of artificial intelligence, moving from the reactive nature of generative text to the proactive execution of

Can AI-Driven Robots Finally Solve the Industrial Dexterity Gap?

The global manufacturing landscape remains tethered to an unexpected limitation: the sophisticated machinery capable of lifting tons of steel often fails when asked to plug in a simple ribbon cable or snap a plastic clip into place. This “industrial dexterity gap” represents a multi-billion-dollar bottleneck where the sheer strength of automation meets the insurmountable finesse of human fingers. While high-speed

VNYX Raises €1M to Automate Fashion Resale With AI

While the global fashion industry has spent decades perfecting the speed of production, the logistical nightmare of bringing a used garment back to the shelf remains a multibillion-dollar friction point. For years, the dirty secret of the circular economy was that it simply cost too much to be sustainable. Amsterdam-based startup VNYX is rewriting this narrative by securing over €1

How Can the Fail Fast Model Secure Robotics Success?

When a precision-engineered robotic arm collides with a steel gantry at full velocity, the resulting sound is not just the crunch of metal but the audible evaporation of hundreds of thousands of dollars in capital investment and months of planning. In the high-stakes environment of industrial automation, the margin for error is razor-thin, yet the traditional development cycle often pushes