INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Google Cloud Finds Vulnerability Exploits Outpacing Weak Credentials Attacks

| 2026-03-10 15:30 HIGH HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
In the second half of 2025, threat actors targeting cloud environments increasingly favored exploiting software vulnerabilities over credential-based attacks, with third-party software-based entry accounting for 44.5% of primary entry vectors. This shift was attributed to nation-state threat actors linked to North Korea and China, who exploited critical remote code execution vulnerability CVE-2025-55182 (React2Shell) in React Server Components, compromising data and servers. Attackers were able to exploit the vulnerability within days of its public disclosure, with multiple threats exploiting it just 48 hours after its release, infecting victims with cryptocurrency mining malware.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2025-24893, CVE-2025-55182 and treat internet-facing systems that were not patched in time as potentially compromised until verified. • Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc • Pre-compromise (ATT&CK mitigation for Botnet): This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-24893CVE-2025-24893 CVE-2025-55182CVE-2025-55182
Target & Sectors
CN
cryptocurrencycryptocurrency technologytechnology
Incident Timeline
‎2026/03/10
Threat actors, including nation-state sponsored and financially-motivated hackers, increasingly prefer using vulnerability exploits over credentials to target cloud services.
infrastructure 44.5
Tactical Metrics
Metrics
infrastructure
​44.5
Software Version
Intelligence Sources