A Fortinet threat intelligence report shows that cybercriminals have industrialized cloud attacks, converting stolen credentials into full compromise through automated workflows that increasingly outpace human defenders.

Cybercriminals are no longer treating cloud vulnerabilities as problems to be evaluated over days or weeks — they are treating them as inputs to automated pipelines that convert exposure into compromise within hours. That is the central finding of Fortinet’s newly published “2026 Cloud-Native Threat Landscape Report,” which draws on telemetry from the company’s FortiCNAPP cloud security platform.

According to the company, the time between a vulnerability’s public disclosure and its first observed exploitation — the so-called time-to-exploit, or TTE — has collapsed from roughly a week to a consistent window of 24 to 48 hours, with some cases now falling under 24 hours. Fortinet attributes the shift primarily to AI-assisted reconnaissance, exploit development, and automation, which it says now define how adversaries operate at scale rather than through bespoke, manually driven campaigns.

Machine-speed reconnaissance at global scale

Fortinet’s telemetry recorded 150 million reconnaissance events, 2.3 billion brute-force attempts, and 1.7 billion connections from known malicious sources across monitored cloud environments, the company reports. It describes this as evidence of continuous, machine-speed mapping of exposure that runs independently of traditional campaign cycles.

The report identifies identity compromise as the dominant intrusion vector across every region analyzed. Attackers increasingly gain initial access through stolen, leaked, or misused credentials rather than malware or exploits — a technique the company says frequently evades network-centric security controls because the resulting activity blends into legitimate cloud usage.

Fortinet illustrates this with what it calls the top observed cloud attack pattern: credentials-to-resource-hijacking, exemplified by the so-called TruffleNet campaign. In this pattern, attackers first locate leaked access keys through automated scanning of code repositories, validate the credentials via API calls such as GetCallerIdentity, enumerate cloud infrastructure and services, escalate privileges through techniques including AttachUserPolicy and CreateUser, and finally monetize access — commonly through abuse of cloud email services for business email compromise fraud.

A second frequently observed pattern moves from vulnerability exploitation directly to cryptomining: attackers exploit a public-facing application, establish a foothold inside a container, disable security agents, install persistence mechanisms such as cron jobs, and deploy cryptomining payloads including XMRig and H2Miner, according to the report.

Misconfigurations accelerate, rarely originate, compromise

While misconfigurations alone do not typically cause an incident, the report states that they substantially increase attacker velocity once an identity has been compromised. Fortinet lists ten security controls it says are most frequently missing in cloud environments, including infrequent access-key rotation, unrestricted network access-control lists, publicly exposed storage, and root accounts without multi-factor authentication.

Among the vulnerabilities Fortinet observed under active exploitation, the report names three with particularly high severity: a remote code execution flaw affecting React and Next.js applications, a Redis Lua sandbox escape rated at the maximum CVSS severity of 10.0, and an unauthenticated remote code execution vulnerability in the Kubernetes NGINX Ingress controller, popularly referred to as IngressNightmare.

Discovery as an early warning signal

The report characterizes automated reconnaissance — enumeration of cloud resources, mapping of identity permissions, and validation of privilege-escalation paths — as the last meaningful window in which defenders can interrupt an intrusion before privilege escalation and monetization begin. Once that phase concludes, Fortinet notes, investigation typically becomes retrospective rather than preventive, with containment windows collapsing from hours to minutes.

Regionally, Fortinet found identity compromise highest in the Asia-Pacific region, closely followed by the Americas and Latin America, while host-based compromises remained comparatively consistent worldwide, affecting 11 to 13 percent of monitored environments. The company also reports an inverse relationship between the prevalence of proactive penetration testing and successful identity compromise, suggesting that organizations conducting regular red-team exercises experience measurably lower compromise rates. The Americas showed the highest relative prevalence of such testing, followed by EMEA.

Recommendations: shifting to continuous, AI-driven defense

Fortinet argues that defending against an industrialized attack model requires an equally systematic defensive posture. Its recommendations include adopting Continuous Threat Exposure Management to prioritize remediation, integrating security checks directly into code as it is written, enforcing least-privilege access for both human and non-human identities, and deploying AI-driven behavioral detection capable of correlating weak signals into high-fidelity alerts rather than relying solely on static rules and signatures.

The company also points to deception technology as a way to detect intruders before the monetization phase, alongside egress filtering to limit data exfiltration and regular incident-response exercises that incorporate AI-assisted red-teaming.

“Compromise is not an event. It is an operating condition,” the report concludes, arguing that defensive velocity — not sophistication of tools alone — is now the primary determinant of organizational risk in cloud environments.

By Jakob Jung

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM. Contact via Mail: jakob.jung@security-storage-und-channel-germany.de

Leave a Reply

Your email address will not be published. Required fields are marked *

WordPress Cookie Notice by Real Cookie Banner