[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f0UsMS6VzdT8hGJXslPtyml64Q_Syr9U6bQ-Ag8yWoL8":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"509c0f81-566e-4993-a5e2-fb90cb1a64a9","Your Cloud Security Checklist Doesn't Work the Way You Think It Does","your-cloud-security-checklist-doesn-t-work-the-way-you-think-it-does-c09a5e","If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Here’s what the data looks like. How risk differs across cloud providers","A 2026 Cloud Security Index report by Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud. The findings reveal that risk profiles and common misconfigurations differ substantially between the major cloud providers, with weak IAM and missing logging being near-universal issues. However, exposed services, permissive firewalls, weak encryption, and misconfigured services show significant divergence, suggesting that cloud security checklists need to be tailored to each provider.","Cloud misconfiguration risks vary significantly across AWS, Azure, and Google Cloud.","Your Cloud Security Checklist Doesn't Work the Way You Think It Does The Hacker NewsSep 07, 2026Cloud Security \u002F Data Security If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Here’s what the data looks like. How risk differs across cloud providers Intruder grouped every misconfiguration into one of six categories: weak identity and access management (IAM), missing logging, misconfigured services, permissive firewalls, exposed services, and weak encryption. For each category, they compared how many accounts had at least one issue in it across the three providers. Weak IAM controls and missing logging are near-universal, affecting between 80% and 98% of accounts regardless of provider. The other four categories are where things diverge: Exposed services: AWS (76%), Azure (64%), Google Cloud (8%) Permissive firewalls: AWS (83%), Azure (45%), Google Cloud (34%) Weak encryption: AWS (49%), Azure (35%), Google Cloud (8%) Misconfigured services: AWS (68%), Azure (80%), Google Cloud (37%) The biggest gap is exposed services, at 76% on AWS versus 8% on Google Cloud. Permissive firewalls and weak encryption follow the same pattern with AWS highest and Google Cloud lowest. Misconfigured services is the exception to that pattern: Azure leads at 80%, with Google Cloud lowest at 37%. One explanation for AWS leading in prevalence across five of the six categories is that it's the largest provider by range of services. More services means more configuration options, and more opportunity for misconfiguration. Google Cloud has the lowest prevalence across five categories - it also offers the fewest services. The lower prevalence could also be explained by the different approach to shared responsibility, with a Shared Fate model that ships more secure defaults out of the box - particularly around network exposure and encryption. Here's what those categories look like as actual misconfigurations on each platform. AWS: firewalls and encryption Where AWS accounts go wrong most often: S3 Does Not Enforce HTTPS — 87% Permissive Ingress to Sensitive Ports (via ACL) — 84% Overly Permissive Network ACL — 83% IAM Policy Allows Privilege Escalation — 83% VPC Endpoint Not Enabled for EC2 — 82% S3 buckets that don't enforce HTTPS is the issue that affects most AWS accounts. S3 is one of the most widely used cloud storage services, and while man-in-the-middle attacks against it are rare, there's little reason to leave plain HTTP available. IAM policies that allow privilege escalation affect 83% of accounts. AWS IAM is notoriously complex, and a managed policy that looks safe can still grant broader permissions than intended. In one recent incident, an attacker went from exposed credentials to administrative privileges in under 10 minutes, compromising 19 AWS principals. Azure: storage and identity The most common misconfigurations on Azure accounts: Storage Account Key Rotation Not Enabled — 67% Storage Account Access Keys Enabled — 66% Storage Account Public Network Access Enabled — 61% Entra User Without MFA — 55% Trusted Launch Not Enabled — 45% The top three issues all relate to Azure Storage Accounts, which frequently hold sensitive data like personally identifiable information (PII). All three affect a similar share of accounts, which suggests that where storage accounts aren't hardened, several controls tend to be missing at once. More than half of accounts also have Entra ID users without multi-factor authentication (MFA). That's worth noting because Entra ID governs access beyond just cloud resources - it covers Microsoft 365, third-party SaaS apps, and on-premises systems. The 2024 Midnight Blizzard breach of Microsoft's own network began with a password spray attack against a legacy test account without MFA. Google Cloud: IAM Almost every top issue on Google Cloud comes down to identity and access management: OS Login MFA Not Enabled — 77% OS Login Not Enabled — 76% Unused Service Account — 75% Overly Permissive Service Account — 53% Permissive Ingress to Sensitive Ports — 34% More than three-quarters of accounts are missing OS Login controls, which provide a more secure alternative to traditional SSH. How organization size changes the picture For most categories, prevalence drops as organizations grow. Larger enterprises are less likely to have permissive firewalls, exposed services, or weak encryption. The exception is IAM. Weak IAM controls affect 87% of SMEs (under 250 employees), 95% of midmarket organizations (251–10K employees), and 98% of large enterprises (10K-100K+ employees). This is significant as a single overprivileged identity is often all it takes to bypass controls that have been hardened elsewhere. Midmarket organizations also take the longest to remediate cloud issues, at 35 days on average, compared to 8-16 for smaller businesses and 10 for large enterprises. It suggests midmarket teams are managing enterprise-level cloud complexity without the dedicated resources to match. What this means for security teams For teams managing multiple providers, the hard part is understanding which risks matter most across the whole estate so that limited time and resources go to the right places. Security teams need a consistent way to assess posture across providers, while keeping the platform-specific detail needed to actually fix things. The full report, including the top 10 misconfigurations per platform and cloud security posture by organization size, is in Intruder’s 2026 Cloud Security Index. Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Cloud security, data security, Identity and Access Management, network security ⚡ Top Stories This Week Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Learn How to Build Security Operations Ready for AI-Powered Attacks Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows Frontier AI: Vulnerability Management's Systemic Revolution Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals Why Threat Intelligence Ne","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fyour-cloud-security-checklist-doesnt.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEhAkHa8CDEfDzL0HknvyLE5eRK8r91iyhgzpCS1GmG3HRtriZYYFzCTP9_H433YsqJ80SAppgs9g6rOhsTWIzHPh_CFcZJS18DIj5ANgzFwSU0vfcyJofTEqEvjGGjNcqZdHU_54PENNzxawWHCZ2r_1K-A63x3P8CbuIiu8OHASjQV3OoglWTefAF2dZw\u002Fs1600\u002Fintruder.jpg","2026-09-07T11:45:00+00:00","2026-09-07T14:00:26.720364+00:00",7,[18,21,23,25,27,29],{"name":19,"type":20},"AWS","product",{"name":22,"type":20},"Azure",{"name":24,"type":20},"Google Cloud",{"name":26,"type":20},"S3",{"name":28,"type":20},"Entra ID",{"name":30,"type":31},"Intruder","vendor","c70f3a41-2f0c-4608-870d-b8cbcd8be076",{"id":32,"icon":34,"name":35,"slug":36},null,"Cloud Security","cloud-security",[38,43,45],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",{"category":44},{"id":32,"icon":34,"name":35,"slug":36},{"category":46},{"id":47,"icon":34,"name":48,"slug":49},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]