October 10, 2017 By Mark Samuels 2 min read

Businesses are neglecting cloud security policies and leaving themselves open to exposure from vulnerabilities, according to recent research.

RedLock’s “Cloud Security Trends” report suggested that enterprise information leaks are rising due to slack vulnerability management, limited compliance with standards and unintentionally exposed databases. The researchers revealed that 38 percent of businesses have users whose accounts might have been compromised.

This research provides further evidence that cloud threats are top of mind in the digital age. IT and line-of-business managers should take note of the research and find ways to address the outlined concerns.

Lack of Compliance Increases Risk of Compromise

According to the study, which analyzed threats to RedLock customer environments as well as public cloud vulnerabilities between June and September 2017, the number of data exposures are increasing due to a lack of security policies.

More than half (53 percent) of businesses using cloud storage have unintentionally exposed one or more of these services to the public. This figure has risen significantly since the last survey in May, when it stood at 40 percent.

Meanwhile, 81 percent of businesses do not manage host vulnerabilities in the cloud. While firms are spending more on vulnerability scanning systems, they are also struggling to map the data they receive to the context of use. Since IP addresses constantly change in the cloud, businesses could find themselves open to compromise.

Such findings prompted the researchers to measure business compliance against industry standards. RedLock found that 45 percent of firms fail checks by the Center for Internet Security (CIS), with 46 percent of contraventions considered “high severity.” Almost half of companies failed Payment Card Industry (PCI) checks, with 19 percent of violations seen as high-severity issues.

Poor Security Policies Cause Problems

Poor security practices also extend to database management. More than one-third of databases accept inbound connection requests directly from the internet, and 7 percent of these databases take requests from suspect IP addresses. Since almost two-thirds of databases are not encrypted, researchers believe the risk of exposure is high.

The survey reported that 250 organizations, including blue-chip businesses, are leaking cloud computing access keys to internet-facing web servers. Researchers discovered that hundreds of companies are revealing sensitive details through misconfigured services, such as the open source deployment systems Kubernetes and Jenkins.

Researchers attributed this errant account activity to a broad range of issues, most notably users who change their activities, which accounts for 89 percent of compromises.

Managing the Cloud Security Conundrum

Cloud security remains a key concern for IT managers and business users. Earlier research from the Cloud Security Alliance found that 73 percent of executives have serious concerns that are holding their organizations back from adopting cloud computing. Experts have also suggested that cloud security risks are complex because multiple third parties typically have their hands in an organization’s data.

When it comes to reducing the risk of data exposure, RedLock suggested several best practices, including automatically discovering resources as they are created in the cloud, monitoring configurations to ensure they adhere to industry standards and considering auto-remediation workflows to resolve issues quickly.

More from

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

4 ways to bring cybersecurity into your community

4 min read - It’s easy to focus on technology when talking about cybersecurity. However, the best prevention measures rely on the education of those who use technology. Organizations training their employees is the first step. But the industry needs to expand the concept of a culture of cybersecurity and take it from where it currently stands as an organizational responsibility to a global perspective.When every person who uses technology — for work, personal use and school — views cybersecurity as their responsibility, it…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today