Cloud Security, Supply chain, Vulnerability Management

Third-party software exploits increasingly harnessed in accelerated cloud breaches

BleepingComputer reports that new third-party software vulnerabilities have been exploited in 44.5% of cloud environment breaches during the second half of 2025, overtaking weak credentials and misconfigurations as a primary access vector, while attack windows have shortened from weeks to days.

Threat actors who targeted cloud instances primarily used remote code execution bugs, particularly the React2Shell flaw, tracked as CVE-2025-55182, and the XWiki issue, tracked as CVE-2025-24893, findings from Google Cloud Security's Cloud Threat Horizons Report H1 2026 revealed. Such a trend is believed to have been driven by more extensive account and credential security measures. Additional findings showed that North Korean state-backed threat operations had aggressively targeted cloud systems during the last six months of 2025, with UNC4889 having stolen millions of U.S. dollars worth of cryptocurrency from breached cloud environments.

Other attackers were also found to have exploited the GitHub-to-AWS OpenID Connect trust to expose GitHub and npm API keys, while more insiders have tapped legitimate cloud services, including AWS, Microsoft Azure, and Google Cloud, for corporate data heists.

An In-Depth Guide to Cloud Security

Get essential knowledge and practical strategies to fortify your cloud security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds