Identity Compromises Drive Surge in Cloud Attacks in Q3 2025
Article Content
Browse articles
A report from ReliaQuest reveals that 44% of true-positive alerts in Q3 2025 were linked to identity-related weaknesses, such as excessive permissions and credential abuse. As organizations migrate assets to cloud platforms, identity management has become a critical security focus, with attackers increasingly exploiting valid credentials. The findings indicate that traditional security measures may not be sufficient against these identity-driven threats.
Ask AI about this cluster
Answers cite the sources they use
Updated 183d ago How this analysis works
More articles in this cluster (6)
Following this threat?
Track Scattered Spider, Ebury and Google in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Social Engineering Campaign Hijacks Microsoft 365 Accounts via Passkey Alerts A social engineering campaign impersonating IT support staff is actively hijacking Microsoft 365 accounts. The attackers use passkey-themed lures to trick users into providing credentials, leading to unauthorized access and data exfiltration. Microsoft Security Research has tracked these intrusions since May 2026…
Knight Office Phishing Kit Targets Microsoft 365 Accounts via Session Hijacking A new phishing kit named 'Knight Office' has been identified, targeting Microsoft 365 accounts by stealing active login sessions instead of passwords. Discovered by Huntress during an investigation of suspicious sign-in activity in August 2026, the kit uses a sophisticated dashboard to manage victims and harvested…