Identity and Cloud Misconfigurations Drive Threats
SYDNEY — A recent report by Google Cloud’s Mandiant has highlighted rising cyber risks in Australia and New Zealand, driven by identity compromises and cloud misconfigurations. The report, released this week, underscores the challenges facing organisations in the region as they combat financially motivated cyber threats.
According to the Mandiant M-Trends report, attackers are increasingly leveraging stolen credentials to infiltrate systems, marking a shift from traditional network attacks. The report indicates that this trend is supported by the proliferation of infostealer malware and phishing campaigns, a concern echoed by the Australian Cyber Security Centre (ACSC).
The report also emphasises the vulnerability of cloud environments, as organisations rapidly adopt these technologies. Misconfigured cloud settings and inadequate access controls are key issues, with limited visibility in hybrid and multi-cloud setups compounding the problem.
Growing Threat Landscape
Mandiant’s analysis reveals that financial motives are the primary driver behind over half of all observed cyber incidents, including ransomware and extortion. This trend is evident across various sectors in ANZ, particularly affecting organisations with limited security measures.
Despite the increasing complexity of attacks, Mandiant points out that many breaches exploit basic security gaps like poor credential management and lack of multi-factor authentication. This highlights the need for stronger identity management and improved cloud security practices.
The report concludes that organisations must shift their focus from solely preventing breaches to building resilience against cyber incidents. This includes enhancing identity protection, continuous monitoring, and rapid response capabilities to effectively manage the evolving threat landscape. The collaboration between public and private sectors is emphasised as crucial for sharing intelligence and developing robust defence strategies. Mandiant suggests that proactive threat hunting and regular security assessments are vital in identifying and mitigating potential risks before they can be exploited by malicious actors.
Source: newshub.medianet.com.au
Last updated: 29 June 2026, 12:39 pm





