Emerging cybersecurity threats: A threat analyst’s perspective

Discover the emerging cybersecurity threats that are keeping experts awake at night. Learn how to protect your enterprise from identity-based attacks, API attacks, cloud risks, and more.

Close-up of a smiling middle-aged man with short hair wearing a light-striped shirt outdoors.
by
 
Didier Vandenbroek
September 30, 2024
 
 
 
Key Takeaways
  • Identity-based attack techniques including credential stuffing, token theft, session cookie hijacking, Kerberoasting, and API key exfiltration have displaced malware as the primary initial access vector, with CrowdStrike recording a 583% increase in Kerberoasting attacks in 2023 alone.
  • API attack volume increased 20% year-over-year in early 2024, with one in five organizations targeted every week, reflecting the shift to cloud-native architectures where API credentials are the primary system interface.
  • Cloud environment risks including over-privileged IAM roles, public S3 buckets, EC2 metadata exposed via SSRF, and Lambda execution role misconfigurations are all identity access control failures that perimeter tools cannot detect or remediate.
  • Oleria's Trustfusion platform maps IAM permissions, SaaS entitlements, and NHI credentials into a single continuously monitored access graph, enabling misconfiguration and anomalous access detection before they become breach events.

This summary was created with AI and reviewed by an editor.

Thick black downward-pointing chevron arrow with rounded ends.
Media contact
For media inquiries, contact pr@oleria.com

See adaptive, automated
identity security in action