TENB Tenable Holdings

Tenable Research Finds Pervasive Cloud Misconfigurations Exposing Critical Data and Secrets

Tenable Research Finds Pervasive Cloud Misconfigurations Exposing Critical Data and Secrets

Insecure cloud configurations create widespread risk, highlighting the urgent need for unified cloud exposure management

COLUMBIA, Md., June 18, 2025 (GLOBE NEWSWIRE) -- , the exposure management company, today released its . The research revealed that 9% of publicly accessible cloud storage contains sensitive data, 97% of which is classified as restricted or confidential. These exposures increase the risk of exploitation, particularly when paired with misconfigurations or embedded secrets.

Cloud environments face dramatically increased risk due to exposed sensitive data, misconfigurations, underlying vulnerabilities and poorly stored secrets – such as passwords, API keys and credentials. The 2025 Cloud Security Risk Report provides a deep dive into the most prominent cloud security issues impacting data, identity, workload and AI resources and offers practical mitigation strategies to help organizations proactively reduce risk and close critical gaps.

Key findings from the report include:

  • Secrets found in diverse cloud resources are putting organizations at risk: Over half of organizations (54%) store at least one secret directly in Amazon Web Services (AWS) Elastic Container Service (ECS) task definitions — creating a direct attack path. Similar issues were found among organizations using Google Cloud Platform (GCP) Cloud Run (52%) and Microsoft Azure Logic Apps workflows (31%). Alarmingly, 3.5% of all AWS Elastic Compute Cloud (EC2) instances contain secrets in user data — major risk given how widely EC2 is used.
  • Cloud workload security is improving, but toxic combinations persist: While the number of organizations with a “toxic cloud trilogy” – a workload that is publicly exposed, critically vulnerable, and highly privileged – has decreased from 38% to 29%, this dangerous combination still represents a significant and common risk.
  • Using Identity Providers (IdPs) alone doesn’t eliminate risk: While 83% of AWS organizations are exercising best practices in using IdP services to manage their cloud identities, overly-permissive defaults, excessive entitlements, and standing permissions still expose them to identity-based threats.

“Despite the security incidents we have witnessed over the past few years, organizations continue to leave critical cloud assets, from sensitive data to secrets, exposed through avoidable misconfigurations,” said Ari Eitan, Director of Cloud Security Research, Tenable.

“The path for attackers is often simple: exploit public access, steal embedded secrets or abuse overprivileged identities. To close these gaps, security teams need full visibility across their environments and the ability to prioritize and automate remediation before threats escalate. The cloud demands continuous, proactive risk management, and not reactive patchwork.”

The report reflects findings by the Tenable Cloud Research team based on telemetry from workloads across diverse public cloud and enterprise environments, analyzed from October 2024 through March 2025. To download the report today, please visit:

More information on Tenable Cloud Security is available at: .

About Tenable

Tenable® is the exposure management company, exposing and closing the cybersecurity gaps that erode business value, reputation and trust. The company’s AI-powered exposure management platform radically unifies security visibility, insight and action across the attack surface, equipping modern organizations to protect against attacks from IT infrastructure to cloud environments to critical infrastructure and everywhere in between. By protecting enterprises from security exposure, Tenable reduces business risk for more than 44,000 customers around the globe. Learn more at .

Media Contact:

Tenable



EN
18/06/2025

Underlying

To request access to management, click here to engage with our
partner Phoenix-IR's CorporateAccessNetwork.com

Reports on Tenable Holdings

 PRESS RELEASE

Tenable Research Finds Pervasive Cloud Misconfigurations Exposing Crit...

Tenable Research Finds Pervasive Cloud Misconfigurations Exposing Critical Data and Secrets Insecure cloud configurations create widespread risk, highlighting the urgent need for unified cloud exposure management COLUMBIA, Md., June 18, 2025 (GLOBE NEWSWIRE) -- , the exposure management company, today released its . The research revealed that 9% of publicly accessible cloud storage contains sensitive data, 97% of which is classified as restricted or confidential. These exposures increase the risk of exploitation, particularly when paired with misconfigurations or embedded secrets. Clou...

 PRESS RELEASE

Tenable Recognized for AI Leadership with Globee Award for AI-Powered ...

Tenable Recognized for AI Leadership with Globee Award for AI-Powered Security COLUMBIA, Md., June 16, 2025 (GLOBE NEWSWIRE) -- , the exposure management company, today announced that has been recognized with a prestigious for AI-Powered Vulnerability Management. This latest accolade underscores Tenable's market leadership, delivering advanced exposure management solutions that revolutionize the way organizations identify, prioritize and remediate cyber risk. “This achievement is a testament to Tenable's commitment to innovation and to helping customers secure modern and emerging a...

 PRESS RELEASE

Tenable Announces Intent to Acquire Apex Security to Expand Exposure M...

Tenable Announces Intent to Acquire Apex Security to Expand Exposure Management Across the AI Attack Surface COLUMBIA, Md., May 29, 2025 (GLOBE NEWSWIRE) -- ® Holdings, Inc., the exposure management company, today announced its intent to acquire , Inc., an innovator in securing the rapidly expanding AI attack surface. Tenable believes the acquisition, once completed, will strengthen Tenable’s ability to help organizations identify and reduce cyber risk in a world increasingly shaped by artificial intelligence. Generative AI tools and autonomous systems are rapidly expanding the attack su...

 PRESS RELEASE

Tenable Reveals 2025 Global Partner Award Winners

Tenable Reveals 2025 Global Partner Award Winners Awards celebrate contributions and commitment to customer success in exposure management COLUMBIA, Md., May 20, 2025 (GLOBE NEWSWIRE) -- , the , today announced the recipients of its Global Partner Awards during Tenable AssureWorld — the company’s fifth annual virtual partner conference. Those honored this year include IBM — Global System Integrator of the Year; Siemens Energy — Tenable OT Security Partner of the Year; Telefonica — MSSP Partner of the Year; and AWS — Global Technology Partner of the Year. Tenable also crowned its re...

 PRESS RELEASE

Tenable Powers AI-Driven Exposure Management with Third-Party Data Con...

Tenable Powers AI-Driven Exposure Management with Third-Party Data Connectors and Unified Dashboards Tenable One bridges siloed security tools for faster, smarter, business-aligned security decisions COLUMBIA, Md., May 15, 2025 (GLOBE NEWSWIRE) -- , the exposure management company, today announced powerful new enhancements to its flagship platform, , with the introduction of and customizable risk dashboards. These advancements — powered by Tenable and built on the Tenable Data Fabric — make Tenable One the most advanced exposure management solution available today. With third-party da...

ResearchPool Subscriptions

Get the most out of your insights

Get in touch