23 September 2026 / 2 minutes of reading
Cloud projects showed the highest vulnerability density across all tested areas. In 43 cloud projects, we identified 18 critical and 44 high-severity vulnerabilities. As many as 42% of the projects contained at least one critical vulnerability.
In most cases, the cloud platform itself is not the cause. During our tests, vulnerabilities almost always stem from configuration issues. The most common problems include excessive permissions, access keys that are never rotated, and misconfigured storage resources left publicly accessible.
What does this look like in practice? During one cloud security test in 2025, a single access key was enough for us to take over the entire environment. A developer had accidentally left it in a public repository. The key belonged to a service account with excessive permissions, allowing us to access production storage resources and the customer database. We did not exploit a single platform vulnerability. The entire attack chain relied on one misconfigured identity.
Global statistics confirm the same findings. In its Top Threats to Cloud Computing report, the Cloud Security Alliance (CSA) ranks misconfiguration as the biggest cloud security risk, even ahead of zero-day vulnerabilities. Identity and access management (IAM) follows immediately behind.
The 2025 Codefinger campaign demonstrated how this can happen in practice. Attackers encrypted S3 buckets using server-side encryption and stolen AWS keys without exploiting a single platform vulnerability. Compromised credentials were all they needed.
This closely reflects what we often encounter during cloud security tests: a false sense of security. Organisations assume that security audits are sufficient, built-in scanners will detect everything, and cloud services are secure by default. These assumptions create room for misconfigurations that are eventually discovered either by us or by an attacker.
Most cloud security risks originate on the customer side, not with the provider. The priority is no longer simply to “secure the cloud”, but to manage identities effectively, rotate credentials regularly, enforce multi-factor authentication, and systematically remediate configuration issues identified through audits or penetration testing.
All news