On this page

Google’s Cloud Threat Report Shows Why Exposure Intelligence Must Move Faster
6 min

Google’s Cloud Threat Report Shows Why Exposure Intelligence Must Move Faster

Google Cloud Security’s latest Cloud Threat Horizons Report highlights an important shift in how attackers are gaining access to cloud environments. For years, credential theft, weak passwords, and misconfigurations were the most common paths into cloud systems. These risks remain serious, but the report shows that attackers are increasingly turning to unpatched third-party software vulnerabilities as their preferred way in. According to Google Cloud, third-party software vulnerabilities accounted for 44.5% of observed Google Cloud initial access incidents in H2 2025, up sharply from 2.9% in H1 2025, overtaking weak or missing credentials as the leading initial access vector.

This is a meaningful change in attacker behavior. It shows that security teams are making progress in some areas, especially around identity protections, secure-by-default cloud controls, and better configuration management. As those easier paths become harder to exploit, attackers are adapting. They are moving toward application-layer weaknesses, exposed third-party tools, known CVEs, and software supply chain paths that sit around the cloud environment. In many cases, the cloud provider itself is not the weakness. The risk comes from the software, services, integrations, and operational decisions layered on top of the cloud infrastructure.

The most important lesson from the report is speed. Google Cloud observed that the window between vulnerability disclosure and active exploitation has collapsed from weeks to days. In one example, threat actors deployed XMRig cryptocurrency miners within approximately 48 hours of public disclosure of CVE-2025-55182. This is a clear warning that traditional patch management cycles are no longer enough. If an organization needs days or weeks to understand whether a vulnerability affects its environment, attackers may already be inside.

AI is likely to make this problem worse. Attackers can use AI to scan large attack surfaces, summarize vulnerability details, generate exploit variations, identify exposed systems, and automate parts of the reconnaissance process. This does not mean every attacker suddenly becomes advanced, but it does mean that the time between disclosure, discovery, targeting, and exploitation can shrink. The operational advantage goes to whoever can move faster. For defenders, that means vulnerability management must become more closely connected to threat intelligence, asset visibility, and real-time exposure monitoring.

The shift toward software exploitation does not make identity less important. In fact, Google’s report also found that identity issues were involved in 83% of compromises across major cloud and SaaS-hosted environments reviewed through Mandiant incident response and threat defense engagements. This reflects the reality of modern intrusions. Attackers often use one weakness to reach another. A software flaw may provide the initial foothold, but the next step is often to steal credentials, access tokens, API keys, OAuth grants, or cloud permissions. The attack path is becoming blended, connecting vulnerability exploitation, identity abuse, SaaS integrations, developer tools, and data theft.

This is especially important for security leaders because many organizations still treat these areas separately. Vulnerability management is handled by one team, identity security by another, cloud posture by another, and threat intelligence by yet another. Attackers do not operate that way. They look for the fastest path to valuable data. That path may begin with an exposed application, continue through a service account, move into a SaaS integration, and end with bulk API-based data exfiltration. Google’s report found that data was targeted in 73% of cloud-related incidents, with silent data exfiltration appearing as the largest threat objective category.

For CISOs, the practical takeaway is that cloud security can no longer stop at securing the cloud account. The real cloud attack surface includes third-party software, open-source packages, internet-facing applications, SaaS integrations, CI/CD pipelines, developer environments, exposed APIs, management interfaces, and non-human identities. Any of these can become the weak link that gives an attacker access. Security teams need a broader and more continuous view of exposure, not only a periodic view of known vulnerabilities.

This is where threat intelligence needs to become more operational. It is not enough to know that a CVE exists. Organizations need to understand whether that vulnerability is actively exploited, whether it affects exposed assets, whether exploit code is circulating, whether threat actors are discussing it, and whether it connects to systems that hold sensitive data. The value comes from prioritization. A vulnerability on an isolated internal system is not the same as a vulnerability on an internet-facing service with access to customer data. A generic severity score cannot tell the full story.

Google’s recommendations point in the same direction. The report calls for automated vulnerability scanning, virtual patching through web application firewalls, tighter controls around public ingress, identity-aware access to administrative interfaces, least privilege, stronger OAuth governance, phishing-resistant MFA, and monitoring for bulk API activity and abnormal data movement. These controls are not theoretical. They are the basic defensive response to an environment where attackers exploit faster, pivot across trusted systems, and use legitimate access paths to avoid detection.

For security teams, the goal should be to reduce the time between external signal and internal action. When a new vulnerability is disclosed, teams should quickly know whether they are exposed, which assets are affected, which business systems are at risk, whether there is active exploitation, and which remediation action matters first. This requires connecting external threat intelligence with internal asset context. Without that connection, teams either waste time chasing every vulnerability equally or miss the few exposures that create real risk.

The broader lesson is that cloud threats are becoming faster, more connected, and more dependent on the ecosystem around the cloud. Attackers are not only stealing passwords or looking for obvious misconfigurations. They are exploiting software flaws, abusing third-party trust, compromising tokens, manipulating SaaS integrations, and moving through developer workflows. Defenders need to match that speed with continuous exposure intelligence and a clear understanding of what attackers are actually targeting.

For Lunar, this report reinforces a core principle: early visibility matters. Whether the threat starts with a stolen credential, a leaked token, a vulnerable service, or chatter around a newly weaponized CVE, organizations need to see risk before it becomes an incident. The companies that combine threat intelligence, external attack surface monitoring, identity context, and cloud exposure management will be better positioned to act before attackers can turn a public vulnerability into a private breach.

Ran Geva
Ran Geva rangeva
linkedin
Spread the news

Check your company's
exposed credentials

Enter your work email to instantly access a free account
and see your company’s exposed credentials.