Blog
/
Cloud
/
December 5, 2024

Protecting Your Hybrid Cloud: The Future of Cloud Security in 2025 and Beyond

In the coming years, cloud security will not only need to adapt to increasingly complex environments as ecosystems become more distributed, but also to rapidly evolving threats like supply chain attacks, advanced misconfiguration exploits, and credential theft. AI-powered cloud security tools can help security teams keep up.
Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Kellie Regan
Director, Product Marketing - Cloud Security
Default blog imageDefault blog imageDefault blog imageDefault blog imageDefault blog imageDefault blog image
05
Dec 2024

Cloud security in 2025

The future of cybersecurity is being shaped by the rapid adoption of cloud technologies.

As Gartner reports, “By 2027, more than 70% of enterprises will use industry cloud platforms to accelerate their business initiatives, up from less than 15% in 2023” [1].

As organizations continue to transition workloads and sensitive data to cloud environments, the complexity of securing distributed infrastructures grows. In 2025, cloud security will need to address increasingly sophisticated threats with innovative approaches to ensure resilience and trust.

Emerging threats in cloud security:

  1. Supply chain attacks in the cloud: Threat actors are targeting vulnerabilities in cloud networks, including third-party integrations and APIs. These attacks can have wide-spanning impacts, jeopardizing data security and possibly even compromising multiple organizations at once. As a result, robust detection and response capabilities are essential to identify and neutralize these attacks before they escalate.
  2. Advanced misconfiguration exploits: Misconfigurations remain a leading cause of cloud security breaches. Attackers are exploiting these vulnerabilities across dynamic infrastructures, underscoring the need for tools that provide continuous compliance validation in the future of cloud computing.
  3. Credential theft with evolving Tactics, Techniques, and Procedures (TTPs): While credential theft can result from phishing attacks, it can also happen through other means like malware, lateral movement, data breaches, weak and reused passwords, and social engineering. Adversarial innovation in carrying out these attacks requires security teams to use proactive defense strategies.
  4. Insider threats and privilege misuse: Inadequate monitoring of Identity and Access Management (IAM) in cloud security increases the risk of insider threats. The adoption of zero-trust architectures is key to mitigating these risks.
  5. Threats exploiting dynamic cloud scaling: Attackers take advantage of the dynamic nature of cloud computing, leveraging ephemeral workloads and autoscaling features to evade detection. This makes adaptive and AI-driven detection and response critical because it can more easily parse behavioral data that would take human security teams longer to investigate.

Where the industry is headed

In 2025, cloud infrastructures will become even more distributed and interconnected. Multi-cloud and hybrid models will dominate, so organizations will have to optimize workloads across platforms. At the same time, the growing adoption of edge computing and containerized applications will decentralize operations further. These trends demand security solutions that are agile, unified, and capable of adapting to rapid changes in cloud environments.

Emerging challenges in securing cloud environments

The transition to highly distributed and dynamic cloud ecosystems introduces the following key challenges:

  1. Limited visibility
    As organizations adopt multiple platforms and services, gaining a unified view of cloud architectures becomes increasingly difficult. This lack of visibility makes it unclear where sensitive data resides, which identities can access it and how, and if there are potential vulnerabilities in configurations and API infrastructure. Without end-to-end monitoring, detecting and mitigating threats in real time becomes nearly impossible.
  2. Complex environments
    The blend of public, private, and hybrid clouds, coupled with diverse service types (SaaS, PaaS, IaaS), creates a security landscape rife with configuration challenges. Each layer adds complexity, increasing the risk of misconfigurations, inconsistent policy enforcement, and gaps in defenses – all of which attackers may exploit.
  3. Dynamic nature of cloud
    Cloud infrastructures are designed to scale resources on demand, but this fluidity poses significant challenges to threat detection and incident response. Changes in configurations, ephemeral workloads, and fluctuating access points mean that on-prem network security mindsets cannot be applied to cloud security and many traditional cloud security approaches still fall short in addressing threats in real time.

Looking forward: Protecting the cloud in 2025 and beyond

Addressing these challenges requires innovation in visibility tools, AI-driven threat detection, and policy automation. The future of cloud security hinges on solutions that adapt to complexity and scale, ensuring organizations can securely navigate the growing demands of cloud-first operations.

Unsupervised Machine Learning (ML) enhances cloud security

Unlike supervised ML, which relies on labeled datasets, unsupervised ML identifies patterns and deviations in data without predefined rules, making it particularly effective in dynamic and unpredictable environments like the cloud. By analyzing the baseline behavior in cloud environments, such as typical user activity, network traffic, and resource utilization, unsupervised ML and supporting models can identify behavioral deviations linked to suspicious activity like unusual login times, irregular API calls, or unexpected data transfers, therefore flagging them as potential threats.

Learn more about how multi-layered ML improves real-time cloud detection and response in the data sheet “AI enhances cloud security.

Agent vs. Agentless deployment

The future of cloud security is increasingly focused on combining agent-based and agentless solutions to address the complexities of hybrid and multi-cloud environments.

This integrated approach enables organizations to align security measures with the specific risks and operational needs of their assets, ensuring comprehensive protection.

Agent-based systems provide deep monitoring and active threat mitigation, making them ideal for high-security environments like financial services and healthcare, where compliance and sensitive data require stringent safeguards.

Meanwhile, agentless systems offer broad visibility and scalability, seamlessly covering dynamic cloud resources without the need for extensive deployment efforts.

Together, a combination of these approaches ensures that all parts of the cloud environment are protected according to their unique risk profiles and functional requirements.

The growing adoption of this strategy highlights a shift toward adaptive, scalable, and efficient security solutions, reflecting the priorities of a rapidly evolving cloud landscape.

To learn more about how these technologies are reshaping cloud defenses, read the blog “Agent vs. Agentless Cloud Security: Why Deployment Methods Matter.”

Shifting responsibilities: security teams must get more comfortable with cloud mindsets

Traditionally, many organizations left cloud security to dedicated cloud teams. However, it is becoming more and more common for security teams to take on the responsibilities of securing the cloud. This is also true of organizations undergoing cloud migration and spinning up cloud infrastructure for the first time.

Notably, the usual approaches to other types of cybersecurity can’t be applied the exact same way to the cloud. With the inherent dynamism and flexibility of the cloud, the necessary security mindset differs greatly from those for the network or datacenters, with which security teams may be more familiar.

For example, IAM is both critical and distinct to cloud computing, and the associated policies, rules, and downstream impacts require intentional care. IAM rules not only govern people, but also non-human entities like service accounts, API keys, and OAuth tokens. These considerations are unique to cloud security, and established teams may need to learn new skills to reduce security gaps in the cloud.

Discover more about the teams that impact modern cloud security in the blog "Cloud Security Evolution: Why Security Teams are Taking the Lead."

The importance of visibility: The future of network security in the cloud

As organizations transition to cloud environments, they still have much of their data in on-premises networks, meaning that maintaining visibility across both on-premises and cloud environments is essential for securing critical assets and ensuring seamless operations. Without a unified security strategy, gaps between these infrastructures and the teams which manage them can leave organizations vulnerable to cyber-attacks.

Shared visibility across both on-premises and cloud environments unifies SecOps and DevOps teams, enabling them to generate actionable insights and develop a cohesive approach. This alignment helps confidently mitigate risks across the cloud and network while streamlining workflows and accelerating the cloud migration journey—all without compromising security or operational continuity.

Read more about the importance of end-to-end visibility in the modern threat landscape in the blog "Breaking Silos: Why Unified Security is Critical in Hybrid World."

Cloud security ciso's guide screenshot

Ready to transform your cloud security approach? Download the CISO's Guide to Cloud Security now!

References:

[1] Gartner, June 5, 2024, “The Expanding Enterprise Investment in Cloud Security,” Available at: https://www.gartner.com/en/newsroom/press-releases/2024-06-05-the-expanding-enterprise-investment-in-cloud-security

Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Kellie Regan
Director, Product Marketing - Cloud Security

More in this series

No items found.

Blog

/

AI

/

March 2, 2026

What the Darktrace Annual Threat Report 2026 Means for Security Leaders

Image of the Earth from spaceDefault blog imageDefault blog image

The challenge for today’s CISOs

At the broadest level, the defining characteristic of cybersecurity in 2026 is the sheer pace of change shaping the environments we protect. Organizations are operating in ecosystems that are larger, more interconnected, and more automated than ever before – spanning cloud platforms, distributed identities, AI-driven systems, and continuous digital workflows.  

The velocity of this expansion has outstripped the slower, predictable patterns security teams once relied on. What used to be a stable backdrop is now a living, shifting landscape where technology, risk, and business operations evolve simultaneously. From this vantage point, the central challenge for security leaders isn’t reacting to individual threats, but maintaining strategic control and clarity as the entire environment accelerates around them.

Strategic takeaways from the Annual Threat Report

The Darktrace Annual Threat Report 2026 reinforces a reality every CISO feels: the center of gravity isn’t the perimeter, vulnerability management, or malware, but trust abused via identity. For example, our analysis found that nearly 70% of incidents in the Americas region begin with stolen or misused accounts, reflecting the global shift toward identity‑led intrusions.

Mass adoption of AI agents, cloud-native applications, and machine decision-making means CISOs now oversee systems that act on their own. This creates an entirely new responsibility: ensuring those systems remain safe, predictable, and aligned to business intent, even under adversarial pressure.

Attackers increasingly exploit trust boundaries, not firewalls – leveraging cloud entitlements, SaaS identity transitions, supply-chain connectivity, and automation frameworks. The rise of non-human identities intensifies this: credentials, tokens, and agent permissions now form the backbone of operational risk.

Boards are now evaluating CISOs on business continuity, operational recovery, and whether AI systems and cloud workloads can fail safely without cascading or causing catastrophic impact.

In this environment, detection accuracy, autonomous response, and blast radius minimization matter far more than traditional control coverage or policy checklists.

Every organization will face setbacks; resilience is measured by how quickly security teams can rise, respond, and resume momentum. In 2026, success will belong to those that adapt fastest.

Managing business security in the age of AI

CISO accountability in 2026 has expanded far beyond controls and tooling. Whether we asked for it or not, we now own outcomes tied to business resilience, AI trust, cloud assurance, and continuous availability. The role is less about certainty and more about recovering control in an environment that keeps accelerating.

Every major 2026 initiative – AI agents, third-party risk, cloud, or comms protection – connects to a single board-level question: Are we still in control as complexity and automation scale faster than humans?

Attackers are not just getting more sophisticated; they are becoming more automated. AI changes the economics of attack, lowering cost and increasing speed. That asymmetry is what CISOs are being measured against.

CISOs are no longer evaluated on tool coverage, but on the ability to assure outcomes – trust in AI adoption, resilience across cloud and identity, and being able to respond to unknown and unforeseen threats.

Boards are now explicitly asking whether we can defend against AI-driven threats. No one can predict every new behavior – survival depends on detecting malicious deviations from normal fast and responding autonomously.  

Agents introduce decision-making at machine speed. Governance, CI/CD scanning, posture management, red teaming, and runtime detection are no longer differentiators but the baseline.

Cloud security is no longer architectural, it is operational. Identity, control planes, and SaaS exposure now sit firmly with the CISO.

AI-speed threats already reshaping security in 2026

We’re already seeing clear examples of how quickly the threat landscape has shifted in 2026. Darktrace’s work on React2Shell exposed just how unforgiving the new tempo is: a honeypot stood up with an exposed React was hit in under two minutes. There was no recon phase, no gradual probing – just immediate, automated exploitation the moment the code appeared publicly. Exposure now equals compromise unless defenses can detect, interpret, and act at machine speed. Traditional operational rhythms simply don’t map to this reality.

We’re also facing the first wave of AI-authored malware, where LLMs generate code that mutates on demand. This removes the historic friction from the attacker side: no skill barrier, no time cost, no limit on iteration. Malware families can regenerate themselves, shift structure, and evade static controls without a human operator behind the keyboard. This forces CISOs to treat adversarial automation as a core operational risk and ensure that autonomous systems inside the business remain predictable under pressure.

The CVE-2026-1731 BeyondTrust exploitation wave reinforced the same pattern. The gap between disclosure and active, global exploitation compressed into hours. Automated scanning, automated payload deployment, coordinated exploitation campaigns, all spinning up faster than most organizations can push an emergency patch through change control. The vulnerability-to-exploit window has effectively collapsed, making runtime visibility, anomaly detection, and autonomous containment far more consequential than patching speed alone.

These cases aren’t edge scenarios; they represent the emerging norm. Complexity and automation have outpaced human-scale processes, and attackers are weaponizing that asymmetry.  

The real differentiator for CISOs in 2026 is less about knowing everything and more about knowing immediately when something shifts – and having systems that can respond at the same speed.

[related-resource]

Continue reading
About the author
Mike Beck
Global CISO

Blog

/

Network

/

March 2, 2026

CVE-2026-1731: How Darktrace Sees the BeyondTrust Exploitation Wave Unfolding

Default blog imageDefault blog image

Note: Darktrace's Threat Research team is publishing now to help defenders. We will continue updating this blog as our investigations unfold.

Background

On February 6, 2026, the Identity & Access Management solution BeyondTrust announced patches for a vulnerability, CVE-2026-1731, which enables unauthenticated remote code execution using specially crafted requests.  This vulnerability affects BeyondTrust Remote Support (RS) and particular older versions of Privileged Remote Access (PRA) [1].

A Proof of Concept (PoC) exploit for this vulnerability was released publicly on February 10, and open-source intelligence (OSINT) reported exploitation attempts within 24 hours [2].

Previous intrusions against Beyond Trust technology have been cited as being affiliated with nation-state attacks, including a 2024 breach targeting the U.S. Treasury Department. This incident led to subsequent emergency directives from  the Cybersecurity and Infrastructure Security Agency (CISA) and later showed attackers had chained previously unknown vulnerabilities to achieve their goals [3].

Additionally, there appears to be infrastructure overlap with React2Shell mass exploitation previously observed by Darktrace, with command-and-control (C2) domain  avg.domaininfo[.]top seen in potential post-exploitation activity for BeyondTrust, as well as in a React2Shell exploitation case involving possible EtherRAT deployment.

Darktrace Detections

Darktrace’s Threat Research team has identified highly anomalous activity across several customers that may relate to exploitation of BeyondTrust since February 10, 2026. Observed activities include:

Outbound connections and DNS requests for endpoints associated with Out-of-Band Application Security Testing; these services are commonly abused by threat actors for exploit validation.  Associated Darktrace models include:

  • Compromise / Possible Tunnelling to Bin Services

Suspicious executable file downloads. Associated Darktrace models include:

  • Anomalous File / EXE from Rare External Location

Outbound beaconing to rare domains. Associated Darktrace models include:

  • Compromise / Agent Beacon (Medium Period)
  • Compromise / Agent Beacon (Long Period)
  • Compromise / Sustained TCP Beaconing Activity To Rare Endpoint
  • Compromise / Beacon to Young Endpoint
  • Anomalous Server Activity / Rare External from Server
  • Compromise / SSL Beaconing to Rare Destination

Unusual cryptocurrency mining activity. Associated Darktrace models include:

  • Compromise / Monero Mining
  • Compromise / High Priority Crypto Currency Mining

And model alerts for:

  • Compromise / Rare Domain Pointing to Internal IP

IT Defenders: As part of best practices, we highly recommend employing an automated containment solution in your environment. For Darktrace customers, please ensure that Autonomous Response is configured correctly. More guidance regarding this activity and suggested actions can be found in the Darktrace Customer Portal.  

Appendices

Potential indicators of post-exploitation behavior:

·      217.76.57[.]78 – IP address - Likely C2 server

·      hXXp://217.76.57[.]78:8009/index.js - URL -  Likely payload

·      b6a15e1f2f3e1f651a5ad4a18ce39d411d385ac7  - SHA1 - Likely payload

·      195.154.119[.]194 – IP address – Likely C2 server

·      hXXp://195.154.119[.]194/index.js - URL – Likely payload

·      avg.domaininfo[.]top – Hostname – Likely C2 server

·      104.234.174[.]5 – IP address - Possible C2 server

·      35da45aeca4701764eb49185b11ef23432f7162a – SHA1 – Possible payload

·      hXXp://134.122.13[.]34:8979/c - URL – Possible payload

·      134.122.13[.]34 – IP address – Possible C2 server

·      28df16894a6732919c650cc5a3de94e434a81d80 - SHA1 - Possible payload

References:

1.        https://nvd.nist.gov/vuln/detail/CVE-2026-1731

2.        https://www.securityweek.com/beyondtrust-vulnerability-targeted-by-hackers-within-24-hours-of-poc-release/

3.        https://www.rapid7.com/blog/post/etr-cve-2026-1731-critical-unauthenticated-remote-code-execution-rce-beyondtrust-remote-support-rs-privileged-remote-access-pra/

Continue reading
About the author
Emma Foulger
Global Threat Research Operations Lead
Your data. Our AI.
Elevate your network security with Darktrace AI