INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Google Cloud Finds Vulnerability Exploits Outpacing Weak Credentials Attacks
| 2026-03-10 15:30 HIGH HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
In the second half of 2025, threat actors targeting cloud environments increasingly favored exploiting software vulnerabilities over credential-based attacks, with third-party software-based entry accounting for 44.5% of primary entry vectors. This shift was attributed to nation-state threat actors linked to North Korea and China, who exploited critical remote code execution vulnerability CVE-2025-55182 (React2Shell) in React Server Components, compromising data and servers. Attackers were able to exploit the vulnerability within days of its public disclosure, with multiple threats exploiting it just 48 hours after its release, infecting victims with cryptocurrency mining malware.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2025-24893, CVE-2025-55182 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• Pre-compromise (ATT&CK mitigation for Botnet): This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-24893CVE-2025-24893
CVE-2025-55182CVE-2025-55182
Target & Sectors
CN
cryptocurrencycryptocurrency
technologytechnology
Incident Timeline
2026/03/10
Threat actors, including nation-state sponsored and financially-motivated hackers, increasingly prefer using vulnerability exploits over credentials to target cloud services.
Click on any entity below to view its context and source!
infrastructure
44.5
In total, third-party software-based entry accounted for 44.5% of primary entry vectors during the second half of 2025.
Tactical Metrics
Metrics
infrastructure
44.5
Software Version
Click for context!
In total, third-party software-based entry accounted for 44.5% of primary entry vectors during the second half of 2025.
Intelligence Sources
Infosecurity-Magazine
2026-03-10
Cloud Attackers Now Prefer Vulnerability Exploits Over Credentials, Google Cloud Finds
Infosecurity-Magazine
BleepingComputer
2026-03-09
Google: Cloud attacks exploit flaws more than weak credentials
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T11:16
Comprehensive Tactical Telemetry
Highly Correlated Entities
24x
organisation
Identified Entity
React2Shell Top Targeted Vulnerability
entity
7x
tactic
Cyber Operation Type
Remote Code Execution
tactic
6x
general metric
%
44
%
6x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
5x
timeline
Temporal Reference
the second half of 2025
date
3x
source region
Origin Country
Korea, Democratic People's Republic of
country
2x
vulnerability
Exploited CVE
CVE-2025-55182
cve
Contextual Telemetry
Context Block
13 METRICS
source region
Origin Region
DPRK
region
infrastructure
Software Version
44.5
version
general metric
Cloud Office
2,026
cloud office
general metric
Hours
48
hours
target region
Target Country
China
country
industry
Targeted Sector
Government
sector
general metric
Accounts
2,180
accounts
general metric
Repositories
7,200
repositories
general metric
Theft Incidents
1,002
theft incidents
general metric
Incidents
771
incidents
general metric
Insider
255
insider
general metric
Malicious Samples
1,100,000
malicious samples
general metric
Top Techniques
10
top techniques
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.