BleepingComputer reports that new third-party software vulnerabilities have been exploited in 44.5% of cloud environment breaches during the second half of 2025, overtaking weak credentials and misconfigurations as a primary access vector, while attack windows have shortened from weeks to days.Threat actors who targeted cloud instances primarily used remote code execution bugs, particularly the React2Shell flaw, tracked as CVE-2025-55182, and the XWiki issue, tracked as CVE-2025-24893, findings from Google Cloud Security's Cloud Threat Horizons Report H1 2026 revealed. Such a trend is believed to have been driven by more extensive account and credential security measures. Additional findings showed that North Korean state-backed threat operations had aggressively targeted cloud systems during the last six months of 2025, with UNC4889 having stolen millions of U.S. dollars worth of cryptocurrency from breached cloud environments.Other attackers were also found to have exploited the GitHub-to-AWS OpenID Connect trust to expose GitHub and npm API keys, while more insiders have tapped legitimate cloud services, including AWS, Microsoft Azure, and Google Cloud, for corporate data heists.
Cloud Security, Supply chain, Vulnerability Management
Third-party software exploits increasingly harnessed in accelerated cloud breaches

An In-Depth Guide to Cloud Security
Get essential knowledge and practical strategies to fortify your cloud security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



