Press release
Evolving Risks, Insecure Defaults, Watering Hole Threats: New Research from Accurics Uncovers Developing Sources of Cloud Risk
Pleasanton, CA, February 22, 2021 – Accurics, the cloud cyber resilience specialist, today unveiled its latest research, “Accurics Cloud Cyber Resilience Report,” which highlights security risks identified in cloud native environments. The findings reveal an increased adoption of managed infrastructure services and the emergence of new cloud watering hole attacks. Of all violations identified, 23 percent correspond to poorly configured managed service offerings – largely the result of default security profiles or configurations that offer excessive permissions.As demonstrated by a recent high-profile hack, attackers increasingly strive to leverage weaknesses that enable them to deliver malware to end users, gain unauthorized access to production environments or their data, or completely compromise a target environment. This strategy is known as a watering hole attack, and Accurics researchers have seen them emerge in cloud environments where they can cause even more damage. This is partly because development processes in the cloud that leverage managed services are not hidden inside the organization as they are in on-premise environments – in fact, they’re largely exposed to the world. When criminals are able to exploit misconfigurations in development pipelines, it can spell disaster not only for the company but also its customers. To address this risk, enterprises should assume the entire development process is easily accessible, and restrict access to only the users who need it.
“Cloud native apps and services are more vital than ever before, and any risk in the infrastructure has critical implications,” said Accurics Co-founder, CTO & CISO Om Moolchandani. “Our research indicates that teams are rapidly adopting managed services, which certainly increase productivity and maintain development velocity. However, these teams unfortunately aren’t keeping up with the associated risks – we see a reliance on using default security profiles and configurations, along with excessive permissions. Messaging services and FaaS are also entering a perilous phase of adoption, just as storage buckets experienced a few years ago. If history is any guide, we’ll start seeing more breaches through insecure configurations around these services.”
On average, the research reveals that the mean time to remediate issues (MTTR) for violations is 25 days across all environments – a luxury for potential attackers. In this report, MTTR is particularly important as it pertains to drift – when configuration changes occur in runtime, causing cloud risk posture to drift from established secure baselines. For drifts from established secure infrastructure postures, the MTTR is 8 days overall.
Even organizations that establish a secure baseline when infrastructure is provisioned will experience drift over time, as happened in another well-publicized breach. While in this case the AWS S3 bucket was configured correctly at the time it was added to the environment in 2015, a configuration change made five months later to fix a problem was not properly reset once the work was complete. This drift went undetected and unaddressed until it was exploited nearly five years later.
The Accurics report also finds that:
● Kubernetes users who try to implement role-based access controls (RBAC) often fail to define roles at the proper granularity. This increases credential reuse and the chance of misuse – in fact, 35% of the organizations evaluated struggle with this problem.
● In Helm charts, 48% of problems came about through insecure defaults. Improper use of the default namespace – where system components run – was the most common mistake, which could give attackers access to the system components or secrets.
● Identity and Access Management defined through Infrastructure as code (IaC) in production environments was seen for the first time, and more than a third (35%) of the IAM drifts detected in this report originate in IaC. This indicates a rapid adoption of IAM as Code, which could lead to risk of misconfigured roles.
● Hardcoded secrets represent almost 10% of violations identified; 23% correspond to poorly configured managed services offerings.
● Of the organizations tested, 10% actually pay for advanced security capabilities that are never enabled.
● While the average time to fix infrastructure misconfigurations was about 25 days, the most critical portions of the infrastructure often take the most time to fix – for example, load-balancing services take an average of 149 days to remedy. Since all user-facing data flows through these resources, they should ideally be fixed the fastest, not the slowest.
Protecting cloud infrastructure requires a fundamentally new approach that embeds security earlier in the development lifecycle and maintains a secure posture throughout. The cloud infrastructure must be continuously monitored in runtime for configuration changes and assessed for risk. In situations where configuration change introduces a risk, the cloud infrastructure must be redeployed based on the secure baseline; this will ensure that any risky changes made accidentally or maliciously are automatically overwritten. With new attacks emerging and ongoing risks continuing to plague organizations, cloud cyber resilience is now more important than ever, and configuration hygiene is critical.
Download a copy of the Accurics Cloud Cyber Resilience Report at http://bit.ly/cloudcyber.
PRESS CONTACT:
CONTOS DUNNE COMMUNICATIONS
+1 408-776-1400 (o)
Paula Dunne +1 408-893-8750 (m)
paula@contosdunne.com
At Accurics™, we envision a world where organizations can innovate in the cloud with confidence. Our mission is to enable cyber resilience through self-healing as organizations embrace cloud native infrastructure. The Accurics platform self-heals cloud native infrastructure by codifying security throughout the development lifecycle. It programmatically detects and resolves risks across Infrastructure as Code before infrastructure is provisioned, and maintains the secure posture in runtime by programmatically mitigating risks from changes. Accurics enables organizations of all sizes to achieve cloud cyber resilience through free cloud-based and open source tools such as Terrascan™.
This release was published on openPR.
Permanent link to this press release:
Copy
Please set a link in the press area of your homepage to this press release on openPR. openPR disclaims liability for any content contained in this release.
You can edit or delete your press release Evolving Risks, Insecure Defaults, Watering Hole Threats: New Research from Accurics Uncovers Developing Sources of Cloud Risk here
News-ID: 2246662 • Views: …
More Releases from Accurics

Accurics Unveils GitLab Static Analysis Integration To Contextualize Risk Across …
Integration supports misconfiguration and vulnerability correlation, reducing noise and empowering developers to fix riskiest threats first
PLEASANTON, Calif. – June 14, 2021 – Accurics, the cloud cyber resilience specialist, today announced a technology partnership with GitLab, a single application for the DevOps lifecycle, as well as the general availability of its integration with GitLab's Static Application Security Testing (SAST) solution. Accurics leverages the integration with GitLab to provide DevSecOps teams with…

Accurics updates open source Terrascan to help orgs detect and fix risks in Kube …
Terrascan extends Policy as Code to Kubernetes
September 16, 2020
Accurics is excited to announce Terrascan v1.1.0, with Kubernetes (k8s) support! Cloud native apps and infrastructure are notoriously complex and difficult to secure with traditional tools, and kubernetes adds automation and orchestration that escalate those problems to another level. Practically speaking, security automation is mandatory because it’s not realistic to expect humans to comprehend such complex, dynamic environments.
Terrascan is an…
More Releases for Cloud
Government Service Cloud Market SWOT Analysis by Leading Key Players: Google Clo …
HTF MI just released the Global Government Service Cloud Market Study, a comprehensive analysis of the market that spans more than 143+ pages and describes the product and industry scope as well as the market prognosis and status for 2025-2032. The marketization process is being accelerated by the market study's segmentation by important regions. The market is currently expanding its reach.
Major companies profiled in Government Service Cloud Market are:
Amazon Web…
Cloud Model Hosting Platform Market Size, Status, Global Outlook 2025 To 2033 | …
New Jersey, United States: The latest research study by Infinity Business Insights, titled 'Global Cloud Model Hosting Platform Market,' 118 analysis on business strategies adopted by key and emerging industry players. It provides insights into current market developments, trends, technologies, drivers, opportunities, and overall market outlook. Understanding various segments is crucial for identifying the factors that drive market growth. Some of the major companies featured in this report include Amazon Web…
AI Supercomputing Cloud Market to Witness Huge Growth by 2029 | AWS, Oracle, Mic …
The AI Supercomputing Cloud Market a detailed study added to provide most recent insights about critical reports of the Global AI Supercomputing Cloud market. This report provides a detailed overview of key factors in the AI Supercomputing Cloud Market and factors such as driver, limitation, past and current trends, guiding scenarios, and technology development. In addition, AI Supercomputing Cloud Market attractiveness according to country, end-user, and other measures is also…
Open Cloud Services Market Size in 2023 To 2029 | Google Cloud - T-Systems - IBM …
The Open Cloud Services market report includes market-driving factors, major obstacles, and restraining factors impeding market growth. The report assists existing manufacturers and start-ups in developing strategies to combat challenges and capitalize on lucrative opportunities to gain a foothold in the global market. Moreover, the report provides thorough information about prime end-users and annual forecast during an estimated period.
𝐃𝐨𝐰𝐧𝐥𝐨𝐚𝐝 𝐅𝐫𝐞𝐞 𝐏𝐃𝐅 𝐒𝐚𝐦𝐩𝐥𝐞 𝐑𝐞𝐩𝐨𝐫𝐭 + 𝐃𝐞𝐭𝐚𝐢𝐥𝐞𝐝 𝐓𝐎𝐂 ➡️ https://www.reportsnreports.com/contacts/requestsample.aspx?name=6778415
𝐋𝐞𝐚𝐝𝐢𝐧𝐠 𝐩𝐥𝐚𝐲𝐞𝐫𝐬 𝐩𝐫𝐨𝐟𝐢𝐥𝐞𝐝…
Mini Program Development Services Market Size in 2023 To 2029 | Tencent Cloud, A …
The Mini Program Development Services market report provides valuable insights for new entrants and stakeholders, offering a comprehensive understanding of market dynamics. It analyzes the competitive landscape and future market scenarios using tools like Porter's five forces and parent/peer market analysis. The report evaluates the product portfolios and services of key market players in detail. It also examines the impact of government regulations during the Covid-19 pandemic and provides market…
Customized Cloud Service Market May See a Big Move | IBM Cloud, Oracle Cloud, Al …
Global Customized Cloud Service Market Growth (Status and Outlook) 2023-2029 is the latest research study released by HTF MI evaluating the market risk side analysis, highlighting opportunities, and leveraging with strategic and tactical decision-making support. The report provides information on market trends and development, growth drivers, technologies, and the changing investment structure of the Global Customized Cloud Service Market. Some of the key players profiled in the study are Google…