Close Menu
The CISO Brief
  • Home
  • Cyberattacks
    • Ransomware
    • Cybercrime
    • Data Breach
  • Emerging Tech
  • Threat Intelligence
    • Vulnerabilities
    • Cyber Risk
  • Expert Insights
  • Careers and Learning
  • Compliance

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Todyl Ranked As A Top 10 Fastest-Growing Private Security company

August 14, 2025

Cyber Cuts Under Trump: Eroding Trust in the Private Sector

August 14, 2025

Unlocking the Future: Blue Report 2025 on Ransomware & Infostealers

August 14, 2025
Facebook X (Twitter) Instagram
The CISO Brief
  • Home
  • Cyberattacks
    • Ransomware
    • Cybercrime
    • Data Breach
  • Emerging Tech
  • Threat Intelligence
    • Vulnerabilities
    • Cyber Risk
  • Expert Insights
  • Careers and Learning
  • Compliance
The CISO Brief
Home » AI, Cloud & Identity Attacks Surge in 2025
Solutions & Tech

AI, Cloud & Identity Attacks Surge in 2025

Staff WriterBy Staff WriterAugust 14, 2025No Comments4 Mins Read0 Views
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email


In 2025, cybercriminals target organizations worldwide with identity attacks, cloud security breaches, and AI-powered cyberattacks. CrowdStrike 2025 Threat Hunting Report indicates that advanced threat actors are leveraging generative AI, cloud misconfiguration, and human identity weakness to perform cross-domain attacks that completely bypass traditional security controls.

Interactive cyber attacks increased 27% year over year, and 81% of attacks were malware-free, showing a trend to more low-profile, high-level techniques. eCrime groups are commonplace, making up 73% of attacks today, and cloud intrusions have increased 136% in the first half of 2025 compared to 2024. Vishing campaigns are increasing as well, breaking earlier yearly records within six months.

Read: Cybersecurity & Infrastructure Security Agency (CISA) on ransomware trends.

Generative AI Becomes a Powerful Tool for Cybercriminals

Generative AI has evolved from a special-purpose tool to a ubiquitous component of cyberattacks. Cybercriminals are using AI to create phishing campaigns, create synthetic identities, and even construct advanced malware. CrowdStrike has found a vulnerability, CVE-2025-3248, in Langflow AI, which is a highly used platform that is used to build AI agents, and was used by attackers for:


Persistence on the exploited systems



Credential access via AI-created phishing and synthetic identities



Malware deployment

North Korea-aligned group FAMOUS CHOLLIMA is one such time-honored case in point, having exploited over 320 organizations, a 220% year-to-date increase, using AI-created resumes, deepfake interviews, and bot-solved coding challenges.

Expert Insight: “Threat actors increasingly view AI as central infrastructure instead of a peripheral technology. Organizations need to keep AI security top of mind in defense,” CrowdStrike experts recommended.

CrowdStrike’s 2025 Threat Hunting Report comprehensively studies potential cyberattacks and shows how advanced attackers specifically target AI, cloud, and identity systems. The report also points to malware-free attacks on the rise, cloud-based attacks on the rise, and the use of generative AI to use for social engineering attacks.

According to CrowdStrike’s 2025 Threat Hunting Report (read the entire report here), threat actors are leveraging cross-domain tactics in order to outmaneuver typical defenses, and the organizations must thus exercise proactive monitoring and protection of identity.

Identity Exploitation Drives Cross-Domain Attacks

Attackers increasingly exploit human and process-based identity weaknesses to gain access across networks. CrowdStrike defines the SCATTERED SPIDER eCrime group as one that:


Uses ransomware within less than 24 hours of initial compromise



Uses vishing and help desk impersonation to bypass MFA



Gains long-lived access to SaaS tools such as IAM, document management, and data warehousing platforms



These identity-driven attacks can enable the attacker to migrate horizontally across domains, remain resident for extended periods, and exfiltrate sensitive information in bulk.

Real-World Measures to Mitigate AI, Cloud, and Identity Threats

CrowdStrike recommends that organizations adopt a multi-layered security approach to counter new cyber threats:


Secure Identity



Utilize phishing-resistant MFA (hardware tokens)



Enforce robust password policies and regular resets



Identify anomalous authentication activity in cloud, SaaS, and on-premises environments

Seal Cross-Domain Visibility Gaps

Organizations must adopt strategies that provide full visibility across endpoints, cloud environments, and identity systems. Threat actors are increasingly moving laterally across domains, exploiting blind spots in monitoring and detection. To address this:


Run XDR and gen-next SIEM tools to correlate endpoint, cloud, and identity platform telemetry



Detect lateral movement sooner and respond automatically



Secure Cloud as Foundation Infrastructure



Use Cloud-Native Application Protection Platforms (CNAPP) with continuous monitoring



Audit APIs, permissions, and configurations in real-time



Enforce least-privilege access



Prepare for AI-Driven Threats



Guard internal AI tools and workflows



Train employees to detect AI-aware social engineering techniques



Detect out-of-band AI usage patterns



Build Incident Readiness



Maintain isolated backups



Conduct regular tabletop exercises



Enable rapid containment and recovery in case of breach



Recommended external source: NIST Cloud Security Guidelines

A Look to the Future: The Future of Cybersecurity

With AI, cloud, and identity platforms more interconnected, cross-domain attacks will only increase. Firms that adopt AI threat monitoring, cloud-native security, and robust identity protection position themselves to compete most effectively. Researchers identify changing to comprehend attacker behavior, using advanced detection tools, and creating a cybersecurity awareness culture as the keys to staying ahead.

Read more: Cybersecurity Ventures: 2025 Global Threat Forecast.

For deeper insights on agentic AI governance, identity controls, and real‑world breach data, visit Cyber Tech Insights.

To participate in our interviews, please write to our CyberTech Media Room at sudipto@intentamplify.com



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCenter for Internet Security Selects Sophos as Premier Partner
Next Article Akamai Teams with Aptum to Accelerate Cloud Migration
Avatar photo
Staff Writer
  • Website

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

Related Posts

Todyl Ranked As A Top 10 Fastest-Growing Private Security company

August 14, 2025

Cayosoft Grows Amid Rising Active Directory Protection Deman

August 14, 2025

Radware, Tet Sign Managed Security Services Deal

August 14, 2025
Leave A Reply Cancel Reply

Latest Posts

Unlocking the Future: Blue Report 2025 on Ransomware & Infostealers

August 14, 20250 Views

CrossC2: Hackers Expand Cobalt Strike Reach to Linux and macOS

August 14, 20250 Views

Critical Flaws in Xerox Print Orchestration Enable Remote Code Execution

August 14, 20250 Views

Canada’s House of Commons Launches Inquiry into Cyberattack Data Breach

August 14, 20250 Views
Don't Miss

Big Risks for Malicious Code, Vulns

By Staff WriterFebruary 14, 2025

Attackers are finding more and more ways to post malicious projects to Hugging Face and…

North Korea’s Kimsuky Attacks Rivals’ Trusted Platforms

February 19, 2025

Deepwatch Acquires Dassana to Boost Cyber Resilience With AI

February 18, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to The CISO Brief, your trusted source for the latest news, expert insights, and developments in the cybersecurity world.

In today’s rapidly evolving digital landscape, staying informed about cyber threats, innovations, and industry trends is critical for professionals and organizations alike. At The CISO Brief, we are committed to providing timely, accurate, and insightful content that helps security leaders navigate the complexities of cybersecurity.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Todyl Ranked As A Top 10 Fastest-Growing Private Security company

August 14, 2025

Cyber Cuts Under Trump: Eroding Trust in the Private Sector

August 14, 2025

Unlocking the Future: Blue Report 2025 on Ransomware & Infostealers

August 14, 2025
Most Popular

Designing and Building Defenses for the Future

February 13, 202516 Views

United Natural Foods Faces Cyberattack Disruption

June 10, 20257 Views

VanHelsing Ransomware Builder Leaked: New Threat Emerges!

May 20, 20255 Views
© 2025 thecisobrief. Designed by thecisobrief.
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.