GitLab announced the general availability of GitLab Duo with Amazon Q.
It's Not Always Peaceful High in the Clouds
For the past few years, Check Point Research (CPR) has been following the evolution of the cloud threat landscape, as well as the constant increase in cloud infrastructure adoption by corporate environments. As many as 98% of global organizations (link is external) utilize cloud-based services, and approximately 76% of them have multi-cloud environments, featuring services from two or more cloud providers.
Cloud adoption in general has grown rapidly in recent years, and COVID-19 accelerated this transition. With the normalization of remote work, companies needed to be able to support and provide critical services to their off-site workforce. As the adoption of cloud technology grows, so does the need for cloud security. Cloud-based applications and cloud-hosted data must be protected against unauthorized access in accordance with applicable regulations. This year saw a significant example(link is external) of how critical this protection might get, when Thailand's most extensive mobile network, AIS, accidentally left a database of eight billion internet records exposed, leading to one of the most expensive breaches ever recorded, costing the company $58 billion to resolve.
In November, The FBI and CISA revealed in a joint advisory that an unnamed Iranian-backed threat group hacked a Federal Civilian Executive Branch (FCEB) organization to deploy XMRig cryptomining malware. The attackers compromised the federal network after hacking into an unpatched VMware Horizon server using an exploit targeting the Log4Shell (CVE-2021-44228) remote code execution vulnerability.
Growth in the Number of Attacks Against Cloud-Based Networks
When examining the past two years of Cloud-based networks landscape, we see a significant growth of 48% in the number of attacks per organization experienced in 2022, compared to 2021. When examining the growth in number of attacks per organization, according to geographical regions we see that Asia sees the largest increase, Year of year, with 60% growth, followed by Europe that has seen a substantial growth of 50% and North America with 28%.
Newer and Major CVE's Impact Higher in Cloud-Based Networks Compared to On-Prem
Although the current number of attacks on cloud-based networks is still 17% lower than in non-cloud networks, when drilling down to types of attacks, and specifically to Vulnerability Exploits, there is a higher usage of newer CVE's (disclosed 2020-2022) compared to on-prem networks for attempted attacks on cloud-based networks. The difference between the two types of networks can be seen in the visual below.
Percentage of attacks leveraging recent vulnerabilities (disclosed 2020-2022)
Further analysis of specific high profile global vulnerabilities reveals that some major CVE's have had a higher impact on cloud-based networks compared to on-prem. For example, the Text4shell Vulnerability (CVE-2022-42889), which was disclosed in October and was exploited soon after, has shown a 16% higher impact on cloud-based environments compared to its impact against on-prem networks. This vulnerability, based on the Apache Commons Text's functionality, allows attacks over a network without the need for any specific privileges or user interaction.
Additional examples of prominent CVEs disclosed this year that have shown a similar trend:
■ VMware Workspace Remote Code Execution (CVE-2022-22954) - 31% higher impact on cloud-based networks.
■ Microsoft Exchange Server Remote Code Execution (CVE-2022-41082) - 17% higher impact on cloud-based networks.
■ F5 BIG IP (CVE-2022-1388) - 12% higher impact on cloud-based networks.
■ Atlassian Confluence — Remote Code Execution (CVE-2022-26134) - 4% higher impact on cloud-based networks
The statistics and data used in this report present data detected by Check Point's Threat Prevention(link is external) technologies, stored and analyzed in ThreatCloud(link is external).
Industry News
Perforce Software and Liquibase announced a strategic partnership to enhance secure and compliant database change management for DevOps teams.
Spacelift announced the launch of Saturnhead AI — an enterprise-grade AI assistant that slashes DevOps troubleshooting time by transforming complex infrastructure logs into clear, actionable explanations.
CodeSecure and FOSSA announced a strategic partnership and native product integration that enables organizations to eliminate security blindspots associated with both third party and open source code.
Bauplan, a Python-first serverless data platform that transforms complex infrastructure processes into a few lines of code over data lakes, announced its launch with $7.5 million in seed funding.
Perforce Software announced the launch of the Kafka Service Bundle, a new offering that provides enterprises with managed open source Apache Kafka at a fraction of the cost of traditional managed providers.
LambdaTest announced the launch of the HyperExecute MCP Server, an enhancement to its AI-native test orchestration platform, HyperExecute.
Cloudflare announced Workers VPC and Workers VPC Private Link, new solutions that enable developers to build secure, global cross-cloud applications on Cloudflare Workers.
Nutrient announced a significant expansion of its cloud-based services, as well as a series of updates to its SDK products, aimed at enhancing the developer experience by allowing developers to build, scale, and innovate with less friction.
Check Point® Software Technologies Ltd.(link is external) announced that its Infinity Platform has been named the top-ranked AI-powered cyber security platform in the 2025 Miercom Assessment.
Orca Security announced the Orca Bitbucket App, a cloud-native seamless integration for scanning Bitbucket Repositories.
The Live API for Gemini models is now in Preview, enabling developers to start building and testing more robust, scalable applications with significantly higher rate limits.
Backslash Security(link is external) announced significant adoption of the Backslash App Graph, the industry’s first dynamic digital twin for application code.
SmartBear launched API Hub for Test, a new capability within the company’s API Hub, powered by Swagger.
Akamai Technologies introduced App & API Protector Hybrid.