2022-03-28-BLUE_ORCA-2021年公共云安全报告_20页_1mb
报告摘要
Orca Security 2021 State of Public Cloud Security Report Summary
Key Findings
- Neglected Workloads: 80.7% of organizations have at least one internet-facing workload running on an unsupported operating system or remaining unpatched for 180 days or more. Of these, 57.9% have unsupported OS workloads, and 49.1% have unpatched web servers.
- Authentication Issues: 23.5% of organizations lack multi-factor authentication for cloud provider root accounts. Additionally, 19.3% have internet-facing assets accessible via non-corporate credentials.
- Security Weaknesses: 43.9% of organizations host workloads containing secrets and credentials (e.g., passwords, API keys), increasing lateral movement risk.
- Internal Vulnerabilities: 77.2% of organizations have more than 10% of their internal workloads in a neglected state, exposing systems to hundreds of known vulnerabilities.
- Misconfigurations: 5.3% have publicly writable storage buckets, and 75.4% had buckets accidentally open to the internet, capable of exposing large amounts of data.
Major Risks
- Attackers exploit neglected workloads and authentication flaws to gain initial access, then move laterally to access sensitive data or cause damage.
- Examples include breaches via unpatched systems or exposed credentials, as seen in Equifax and Capital One cases.
Recommendations
- Ensure 100% coverage of all cloud assets to prevent undetected threats.
- Strengthen basic security hygiene, such as patching and multi-factor authentication.
- Monitor for lateral movement risk in internal systems.
- Implement tools to quickly detect and respond to misconfigurations and errors.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载