Back to Insights Cloud Security

How many vulnerabilities are in your cloud environment—and do you even know about all of them?

Current Status: An Emerging Risk in the Cloud – Escalating Vulnerabilities
In a world where more and more organizations are adopting cloud services, one of the primary issues is the neglect of cloud asset security. A study by Orca Security found that cloud assets contain an average of 115 security vulnerabilities, many of which have persisted for years. The focus on cloud infrastructures, which are often maintained negligently, has made the cloud a prime target for disaster; hackers, including state-sponsored espionage groups, view it as a highly attractive objective. Data reveals that more than half of organizations utilize assets with vulnerabilities residing in legacy systems that have remained unpatched for over 180 days. This occurs as the race to adopt AI technologies increases the pressure to deploy solutions rapidly, while ignoring the risks created by gaps in security maintenance.

Exploiting Vulnerabilities: A Worrying Increase in Attacks
Vulnerability-based attacks are becoming increasingly popular, as seen in the 2025 Verizon report. These attacks have become the second most common entry point into corporate systems, following data breaches caused by the insecure use of credentials. The combination of physical and cloud assets in organizations often creates “gateways” through which attackers can move laterally within the organization’s systems. The use of hybrid environments—a mix of cloud and on-premises assets—creates new challenges for organizations. More than two-thirds of organizations have exposed cloud assets to the internet, providing attackers with easier access to those systems.

Impacts of Unpatched Vulnerabilities: Vulnerable Data and Attack Paths
One of the central issues identified was the exposure of sensitive data, particularly when organizations failed to address vulnerabilities in source code or in active platform versions. This is a severe problem, as more than a third of organizations found themselves with “leaks” of sensitive data accessible to the public. The research highlights the urgent need to improve approaches to data security, especially given the growing demand for data in the AI era. The risk is not limited to isolated vulnerabilities; it involves complex “attack paths” that allow attackers to execute multi-stage attacks. Orca found that more than half of organizations exposed at least one attack path that could lead to the exposure of sensitive data or expanded access to corporate systems.

Recommendations from IPV Security Information Security Experts:
* Strengthen Patch Management: Ensure all cloud assets are updated with the latest patches and that maintenance is continuous.
* Enforce Principle of Least Privilege (PoLP): Grant minimal access permissions to users and ensure no unnecessary privileges are assigned.
* Avoid Legacy Systems: Avoid using unsupported legacy systems, especially if they no longer receive security updates.
* Protect Data: Take measures to ensure sensitive data is not at risk through encryption and specific focus on access blocking issues.
* Conduct Regular Security Audits: It is recommended to perform periodic security reviews for all cloud assets, keeping in mind that attackers always seek the path of least resistance.

In Conclusion
In an era where the use of cloud and AI is increasing, information security has become a critical issue. Organizations must be diligent in patching old vulnerabilities, enhancing identity and access management, and ensuring that data remains protected.

For more information: [CSO Online Link]

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation