Organisations received over five times as many daily cloud-based alerts by the end of 2024 than at the beginning of the year.
The greatest increase in alerts was observed in high-severity alerts, indicating successful targeting of critical cloud resources, including identity and access management, storage, virtual machines, and containers.
IAM tokens and credentials are under threat, with an increase in remote command-line access events, IAM API requests from outside regions, cloud snapshot exports, and suspicious downloads of cloud storage objects.
Throughout 2024, high-severity cloud alerts rose by 235%, with significant increases in August, October, and December. The report recommends implementing cloud detection and response monitoring, limiting cloud service platform regions, and ensuring appropriate IAM service account operations and cloud storage security.