TL;DR: Cyber attackers are exploiting AI, ransomware, zero-days, social engineering, and cloud misconfigurations faster than many organisations can adapt, according to INTIGRITI’s cyber threat landscape analysis. The governing problem is no longer isolated threats but the speed at which new attack surface outpaces reactive controls, especially where identity and access are weakly managed.
NHIMG editorial — based on content published by INTIGRITI: The cyber threat landscape part 1: Enhancing cybersecurity strategies
By the numbers:
- In 2024, around 90 zero-day vulnerabilities were exploited, showing how quickly malware operators can weaponize unknown flaws before mitigations are available.
- ENISA reports that 60% of organisations affected by ransomware may have paid ransom demands, underscoring the pressure created by disruption-driven attacks.
- Capital One’s 2019 AWS breach exposed sensitive data of over 100 million customers after a misconfigured cloud instance broadened access.
Questions worth separating out
Q: What breaks when cloud access controls are not tied to asset exposure?
A: When cloud access controls are separated from asset exposure, teams can approve entitlements that still leave data or services publicly reachable.
Q: Why do remote workers and distributed teams increase social engineering risk?
A: Remote teams rely on chat, email, and helpdesk channels that attackers can imitate more easily than in-person verification.
Q: How do security teams know whether active defence is actually working?
A: Active defence is working only if it changes attacker outcomes in testing and in live operations.
Practitioner guidance
- Map exposed resources to identity owners Build an inventory of internet-facing cloud assets, service accounts, and remote access paths, then assign a clear owner for each path that can change permissions or revoke access quickly.
- Reduce trust in remote access workflows Strengthen phishing-resistant authentication, require secondary verification for sensitive requests, and harden helpdesk procedures so attackers cannot social-engineer reset or escalation paths.
- Tie cloud misconfiguration reviews to access governance Review storage exposure, open ports, and over-broad permissions in one workflow so cloud posture checks also surface who can access the resource and why.
What's in the full article
INTIGRITI's full blog post covers the operational detail this post intentionally leaves for the source:
- The article expands on the specific threat categories that are changing fastest, including ransomware, malware, social engineering, and AI-enabled abuse.
- It adds practical examples such as the Mirai botnet and the Capital One cloud breach to illustrate how attack surface becomes exploitable.
- The source text discusses bug bounty as an additional defence layer for teams that need continuous external testing across cloud and mobile assets.
- It closes with a forward look at AI, quantum computing, and blockchain, which gives readers a broader technology-risk view than this analysis.
👉 Read INTIGRITI's analysis of the evolving cyber threat landscape →
AI threat trends and cloud exposure: what security teams need now?
Explore further
Cloud and identity risk are converging into one governance problem. The article treats cloud misconfiguration, remote work, and access control as separate concerns, but practitioners see them converge in the same incident path. When an exposed resource can be reached through overly broad permissions or poorly governed credentials, the problem is no longer just cloud posture. It becomes identity governance, and the practical conclusion is that access review must include runtime exposure, not only entitlement lists.
A question worth separating out:
Q: Who is accountable when a cloud misconfiguration exposes production data?
A: Accountability usually sits across security, platform, and application teams because the exposure is created by an operational decision, not a single technical mistake. Governance needs clear ownership for service accounts, repository controls, and access assumptions so that risky combinations are fixed before they become reachable attack paths.
👉 Read our full editorial: AI-driven threat trends are widening the cybersecurity attack surface