Red Canary Research Reveals Sharp Rise in Cloud and Identity Threats, Exposing Critical Cybersecurity Risks
Zscaler's (NYSE:ZS) Red Canary division has released its midyear 2025 Threat Detection Report, revealing significant cybersecurity trends. The report highlights a dramatic 500% increase in Cloud Account detections compared to 2024, driven by expanded identity-based threat detection capabilities.
Key findings include two new cloud techniques entering the top 10 detected threats: Data from Cloud Storage and Disable or Modify Cloud Firewall. Analysis of phishing emails revealed that only 16% of suspected phishing emails were actually malicious. The report also details the evolution of the Scarlet Goldfinch threat group, which has shifted to using fake CAPTCHA paste-and-run techniques.
La divisione Red Canary di Zscaler (NYSE:ZS) ha pubblicato il suo Rapporto di Rilevamento delle Minacce di metà anno 2025, rivelando importanti tendenze nella sicurezza informatica. Il rapporto evidenzia un incremento drammatico del 500% nelle rilevazioni di account cloud rispetto al 2024, grazie all'ampliamento delle capacità di rilevamento delle minacce basate sull'identità.
Tra le principali scoperte figurano due nuove tecniche cloud che entrano nella top 10 delle minacce più rilevate: dati da archiviazione cloud e disabilitazione o modifica del firewall cloud. L'analisi delle email di phishing ha mostrato che solo il 16% delle email sospette di phishing erano effettivamente dannose. Il rapporto descrive inoltre l'evoluzione del gruppo di minacce Scarlet Goldfinch, che ha adottato tecniche di CAPTCHA falso basate su incolla-e-fuggi.
La división Red Canary de Zscaler (NYSE:ZS) ha publicado su Informe de Detección de Amenazas de mitad de año 2025, revelando tendencias significativas en ciberseguridad. El informe destaca un incremento dramático del 500% en detecciones de cuentas en la nube en comparación con 2024, impulsado por capacidades ampliadas de detección de amenazas basadas en la identidad.
Los hallazgos clave incluyen dos nuevas técnicas en la nube que entran en el top 10 de amenazas detectadas: datos de almacenamiento en la nube y deshabilitar o modificar el firewall en la nube. El análisis de correos electrónicos de phishing reveló que solo el 16% de los correos sospechosos de phishing eran realmente maliciosos. El informe también detalla la evolución del grupo de amenazas Scarlet Goldfinch, que ha cambiado a usar técnicas falsas de CAPTCHA de copiar y pegar rápido.
Zscaler(NYSE:ZS)의 Red Canary 부서가 2025년 중간 위협 탐지 보고서를 발표하며 중요한 사이버보안 동향을 공개했습니다. 보고서는 2024년 대비 클라우드 계정 탐지 건수가 500% 급증했으며, 이는 신원 기반 위협 탐지 기능 확장에 기인한다고 밝혔습니다.
주요 발견 사항으로는 새롭게 클라우드 내 상위 10위 탐지 위협에 진입한 두 가지 기법, 즉 클라우드 저장소 데이터 및 클라우드 방화벽 비활성화 또는 수정이 포함됩니다. 피싱 이메일 분석 결과, 의심되는 피싱 이메일 중 실제 악성은 16%에 불과했습니다. 또한 보고서는 Scarlet Goldfinch 위협 그룹의 진화를 다루며, 이들이 가짜 CAPTCHA 붙여넣기 및 빠른 실행 기법으로 전환했다고 설명합니다.
La division Red Canary de Zscaler (NYSE:ZS) a publié son Rapport de Détection des Menaces à mi-année 2025, révélant des tendances majeures en cybersécurité. Le rapport souligne une augmentation spectaculaire de 500 % des détections de comptes cloud par rapport à 2024, grâce à l'élargissement des capacités de détection des menaces basées sur l'identité.
Parmi les principales conclusions figurent deux nouvelles techniques cloud entrant dans le top 10 des menaces détectées : données issues du stockage cloud et désactivation ou modification du pare-feu cloud. L'analyse des emails de phishing a révélé que seulement 16 % des emails suspects étaient réellement malveillants. Le rapport détaille également l'évolution du groupe de menaces Scarlet Goldfinch, qui a adopté des techniques de CAPTCHA factices de type copier-coller rapide.
Die Red Canary-Abteilung von Zscaler (NYSE:ZS) hat ihren Bedrohungserkennungsbericht für Mitte 2025 veröffentlicht und dabei bedeutende Cybersicherheitstrends aufgezeigt. Der Bericht hebt einen dramatischen Anstieg der Cloud-Konto-Erkennungen um 500 % im Vergleich zu 2024 hervor, bedingt durch erweiterte identitätsbasierte Bedrohungserkennungsfunktionen.
Wesentliche Erkenntnisse umfassen zwei neue Cloud-Techniken, die in die Top 10 der erkannten Bedrohungen eingestiegen sind: Daten aus Cloud-Speicher und Deaktivieren oder Ändern der Cloud-Firewall. Die Analyse von Phishing-E-Mails ergab, dass nur 16 % der verdächtigen Phishing-E-Mails tatsächlich bösartig waren. Der Bericht beschreibt zudem die Entwicklung der Bedrohungsgruppe Scarlet Goldfinch, die auf gefälschte CAPTCHA-Paste-and-Run-Techniken umgestiegen ist.
- Enhanced detection capabilities with AI agents for identifying unusual login patterns
- Expanded identity detection coverage improving threat identification
- Comprehensive analysis of phishing threats leading to better threat assessment
- 500% increase in Cloud Account security threats compared to 2024
- Rising risks from misconfigured AWS S3 storage buckets and open ingress ports
- Evolution of sophisticated attack methods using legitimate services to bypass security
Insights
Red Canary's report reveals 500% surge in cloud threats, validating Zscaler's strategic positioning in identity-based security solutions.
The midyear update to Red Canary's 2025 Threat Detection Report reveals dramatic shifts in the cybersecurity landscape that strengthen Zscaler's market position. The nearly
Two cloud-related techniques have entered Red Canary's top 10 detected techniques for the first time - Data from Cloud Storage and Disable or Modify Cloud Firewall - signaling an evolution in threat vectors that aligns perfectly with Zscaler's zero trust architecture approach. This shift toward identity and cloud-based threats represents a fundamental market transition from traditional endpoint security to more comprehensive cloud security platforms.
The report's findings on phishing attempts are particularly notable for their sophistication: despite only
The comprehensive recommendations in the report - from multi-factor authentication to cloud misconfiguration management - mirror Zscaler's product strategy of providing unified security controls across identity, cloud infrastructure, and user behavior. This report effectively serves as market validation for Zscaler's strategic direction in providing integrated cloud security platforms rather than point solutions.
Midyear update to the 2025 Threat Detection Report identifies rapid emergence of new cloud techniques and evolution in phishing tactics
Key Findings:
- Cloud Account detections increased nearly
500% compared to the entirety of 2024, driven largely by expanded detection capabilities in identity-based threats. - Two new cloud-related techniques – Data from Cloud Storage and Disable or Modify Cloud Firewall – have broken into Red Canary's top 10 techniques for the first time.
- Phishing remains prevalent but nuanced: analysis revealed that only
16% of suspected phishing emails were genuinely malicious.
"As organizations increasingly adopt cloud-based identity providers, infrastructure, and applications, our midyear update highlights the impact on threat detection. Security teams are evolving their endpoint-focused strategies to approaches that recognize more nuanced risks across dispersed environments," said Keith McCammon, Co-founder of Red Canary. "Unlike endpoint, where most of the data and context required for threat detection and response stems from a single source, identity and cloud threat detection requires visibility and correlation across disparate systems, coupled with a platform and team capable of performing timely investigations."
Cloud Account detections blur the lines between threat and risk
Red Canary observed an almost
New cloud techniques expose emerging risks
For the first time, two cloud-related techniques – Data from Cloud Storage and Disable or Modify Cloud Firewall – entered Red Canary's top 10 detected techniques. These techniques represent a growing focus not just on explicit threats but on risky behaviors that can be the precursors to potential breaches. Organizations face significant risks from misconfigured AWS S3 storage buckets and open ingress ports, due to both adversaries using harvested credentials to deliberately expose them and legitimate changes by trusted employees.
Phishing emails are not always what they seem
Red Canary analyzed tens of thousands of user-reported phishing emails, revealing that only
Scarlet Goldfinch evolves with fake CAPTCHA
Scarlet Goldfinch, an established initial access threat known for delivering remote management and monitoring (RMM) tools, made a significant operational shift this year. Previously relying on fake browser updates, the group has pivoted to using fake CAPTCHA paste-and-run techniques to entice victims into executing malicious code. This evolution highlights adversaries' agility in adapting the latest social engineering tactics to remain effective and evade existing defenses.
Defending against emerging threats and risks
As threats evolve, organizations must bolster their defenses by implementing the following strategies:
- Identity security controls: Enforce multi-factor authentication (MFA) and conditional access policies (CAP) to reduce unauthorized identity usage.
- Cloud misconfiguration management: Regularly audit and secure cloud infrastructure configurations, ensuring public access settings and firewall rules adhere to strict policies in line with the principles of zero trust.
- Phishing awareness: Implement robust user training to improve identification of sophisticated phishing and social engineering attempts.
- VPN and RMM monitoring: Limit and closely monitor VPN usage and remote management tools, using behavioral analytics to detect anomalous activity indicative of malicious intent.
By proactively adopting these measures, organizations can significantly enhance their cybersecurity posture, mitigating the risk and impact of the latest adversary tactics.
Methodology
The midyear update to the 2025 Threat Detection Report provides in-depth analysis of the confirmed threats detected from the petabytes of telemetry collected from Red Canary customers' endpoints, networks, cloud infrastructure, identities, and SaaS applications in the first six months of 2025.
The Threat Detection Report sets itself apart from other annual reports with its unique data and insights derived from a combination of expansive detection coverage and expert, human-led investigation, and confirmation of threats.
About Red Canary, a Zscaler Company
Red Canary is a leader in managed detection and response (MDR). We serve companies of every size and industry, focusing on finding and stopping threats before they can have a negative impact. As the security ally for nearly 1,000 organizations, we provide MDR across our customers' cloud workloads, identities, SaaS applications, networks, and endpoints. For more information about Red Canary, visit: https://www.redcanary.com.
About Zscaler
Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across more than 150 data centers globally, the SASE-based Zero Trust Exchange™ is the world's largest in-line cloud security platform.
View original content to download multimedia:https://www.prnewswire.com/news-releases/red-canary-research-reveals-sharp-rise-in-cloud-and-identity-threats-exposing-critical-cybersecurity-risks-302521309.html
SOURCE Red Canary