Misconfigurations remain at the center of cloud security issues, with many the result of poorly written identity and access management (IAM) policies, Palo Alto Networks Unit 42 threat research team warns.
In analyzing more than 680,000 identities across 18,000 cloud accounts from more than 200 different organizations as part of its latest Cloud Threat Report, researchers found that nearly 99% of IAM policies are overly permissive.
Without effective IAM policies in place, “an organization can never expect to be secure in the cloud due to its very nature: dispersed, rapidly evolving, and dynamically fluctuating within an organization,” John Morello, VP of Prisma Cloud at Palo Alto Networks, wrote in the report.
Unit 42 researchers consider a cloud identity that grants permissions that are unused over the past 60 days as overly permissive. And they found that out of all the cloud identities they studied for the report, only 1% of those cloud users, roles, and service accounts were granted least-privileged permissions.
The results showed a huge gap between reality and the principle of least privilege, researchers pointed out. “If compromised, adversaries may leverage these unused permissions to move laterally or vertically and expand the attack radius,” they wrote. “Most known cloud security incidents start with a misconfigured IAM or leaked credential.”
The report also found cloud service provider-managed policies granted 2.5-times more permission than customer-managed policies; 62% of organizations have cloud resources publicly exposed; and 53% of cloud accounts allow weak IAM passwords, while 44% of them allow IAM password reuse.
Unit 42 Names Top 5 Cloud Threat ActorsUnit 42 highlighted top threat actors targeting the cloud, including TeamTNT, WatchDog, Kinsing, Rocke, and 8220. And the team noted those actors performed container-specific or container-escape operations.
Those five threat actors routinely collected credentials for cloud service platforms or container platforms. With those credentials they would be able to move laterally to the cloud service platform, which would allow them to evade siloed container or cloud virtual resource security monitoring tools, according to the report.
Researchers recommend defenders use cloud-native application protection platform (CNAPP) tools that include both cloud security posture management and cloud workload protection services, along with proper configurations to monitor and remediate those operations.
Comments