Three threats to today’s cloud environment
The cloud has become a vital component to an organisation’s infrastructure. It allows companies to improve operational inefficiencies while also allowing them to innovate and experiment with advanced technologies like artificial intelligence (AI), machine learning (ML) and Web3. This, however, has made navigating the world of cloud security more complex and has expanded the threat

Three threats to today’s cloud environment
The cloud has become a vital component to an organisation’s infrastructure. It allows companies to improve operational inefficiencies while also allowing them to innovate and experiment with advanced technologies like artificial intelligence (AI), machine learning (ML) and Web3.
This, however, has made navigating the world of cloud security more complex and has expanded the threat landscape significantly. And with so much of today’s digital world so reliant on the cloud, the stakes have never been higher. Business leaders find themselves at a crossroads, balancing foresight with operational resilience, all while navigating the treacherous terrain of cloud security.
Staying ahead of risk is vital and the need for a robust security strategy has never been more critical. Our latest research shows that enterprises need to look beyond their routine malware and vulnerability scans. Cybercriminals are testing new vectors and seeking out unique vulnerabilities from worms and training data to APIs.
Tackling tailor-made worms
From Trend Micro’s latest security research, we’re seeing cloud environments being turned into a playground for tailor-made worms that are designed to exploit cloud technologies and misconfigurations serving as entry points for attackers. These worms have the ability to propagate rapidly in cloud environments and take advantage of the interconnectivity within a company’s infrastructure.
Often the purpose of these worms is to seek out computing resources for mining cryptocurrency. This can either put a strain on a system’s resources or hijack it entirely. Tell-tale signs can include peaks in system utilisation and traffic, as well as cybercriminals making their presence known through a data breach or ransom.
Just like any attack, these worms can have financial, operational and reputational implications. Operational infrastructure can be impacted as the worm takes over computing resources. The costs of such a breach can increase over time as a company’s productivity takes a hit, while other financial burdens can include a regulatory fine. And then of course, if the attack is made public, companies can suffer reputational damage.
There are a variety of precautions businesses can take. Going back to basics and ensuring staff are practicing good digital hygiene is important. This includes using strong passwords and enabling multi-factor authentication (MFA) – especially across critical systems. These access control measures can prevent the spread of an attack. Security teams will also support a resilient security response through patching, while monitoring tools can help with detection and protection.
Damaging data poisoning
With the recent proliferation of AI and ML models, organisations are looking at ways in which these latest advances in technology can help them innovate, increase productivity and add business value. Trend Micro’s research found that 69% of IT leaders considerML integration a top priority for operations. However, as with all new technology, there is a need to consider its risks and vulnerabilities.
ML models are only as effective as the data they are trained on. These models need data to be as unbiased as possible in order to achieve the outputs companies are looking for. Data poisoning ML models is a fairly new development in cybersecurity and one for which organisations need to be prepared. This type of attack is a result of cybercriminals polluting and manipulating datasets in their favour. A compromised ML model has the potential to open the floodgates to possibly divulging confidential data for extraction, writing malicious instructions and providing biased content that could lead to user dissatisfaction or legal repercussions.
This is a very subtle style of attack that can be easily overlooked. Combatting it will require businesses to ensure that the data being used to train their ML models is validated and authenticated. From there, security teams will need to regularly test systems to ensure that the ML model is not compromised.
Assessing and addressing APIs
The backbone of our digital world are application programming interfaces (APIs) and they are increasingly under siege. APIs are the middlemen that perform actions between applications and servers. They facilitate the interconnected communication between two parties and are incredibly important.
APIs that aren’t secure are akin to leaving a home’s front door ajar. They can grant access to unwanted guests into an organisation’s environment. Due to the centralised nature of APIs, they can be an Achilles’ heel if compromised and can disrupt both cloud and on-premises operations.
There are a number of different ways an organisation can secure its APIs with the first being strong authentication and encryption in the form of passwords and MFA. Granular controls is better than all access, so segmenting a database rather than sharing it completely is safer. Regular security testing can help find vulnerabilities and ensure API gateways are impervious to attacks. And finally, monitoring for anomalies can alert a security team to an attempted breach.
The security challenges around hybrid and cloud environments demand a proactive and layered approach to respond and adapt to evolving threats. Platform security offers enterprises a set of solutions that support protection, risk management, and multi-cloud detection and response to secure a continuously evolving environment. It’s through this unified approach that organisations can navigate the cloud more securely and with improved resilience.
This article was written by Russell Young, Cloud Solution Architect at Trend Micro
Main Image: TrendMicro



