This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Storm Over the Cloud: Meeting the Threats of a New Digital Age

Download resources

About this session

Hossein Hadian Jazi, a senior cyber threat intelligence expert at Fortinet who has tracked and named nation-state groups such as Evasive Panda and LazyScripter, maps how attackers are moving into the cloud and weaponizing AI along the way. He opens with adoption statistics explaining why cloud is now a prime target, then covers rising incident numbers, the underground market for stolen credentials and zero-days, and the growth of cloud-specific MITRE ATT&CK techniques. He groups cloud threats into enablers (misconfiguration, insecure APIs, identity mismanagement), vectors, attack types and outcomes, profiling ransomware groups like BlackCat, Cl0p, Storm-0501 and Scattered Spider. The core of the talk sorts nation-state cloud campaigns into five patterns, on-prem-to-cloud, cloud-native, cloud-to-cloud, edge/IoT-to-cloud and third-party ecosystem, with named actors (APT29, APT41, APT28, Salt Typhoon, Silk Typhoon) and real intrusion examples, plus a section on token forgery used in the SolarWinds and Microsoft signing-key breaches. He closes on how attackers already use generative AI across the kill chain and recommends auditing cloud posture and sharing threat intelligence.

The cloud has become the backbone of modern innovation, driving global business and connecting people everywhere. But with that power comes risk as it is now one of the most sought-after targets in an escalating cyber conflict. Threat groups like Antique Typhoon, Silk Typhoon, and APT29 are relentlessly attacking cloud systems, exploiting weak configurations, stealing credentials, and infiltrating supply chains to cause large-scale disruption. In this session, we will take a closer look at the evolving cloud threat landscape, and the tactics, techniques, and procedures (TTPs) attackers use to bypass defenses around virtual machines, containers, and serverless platforms. You will see how cyber threat actors are leveraging artificial intelligence to scan and map cloud environments almost instantly, deploy adaptive malware that changes its behavior to avoid detection, and launch attacks capable of overwhelming entire networks. Through real-world examples, we will explore different cloud attacks including AI-driven reconnaissance, and automated intrusions that are impacting industries worldwide. More than just a technical challenge, these threats represent a defining moment for how we secure the digital foundations of our world. This session will examine what is at stake, the forces shaping the future of cloud security, and how we can collectively rise to meet this new era of cyber risk.

Key takeaways

  • Prioritize closing misconfigurations and locking down APIs; they remain the two enablers behind most cloud intrusions covered in the talk.
  • Treat identity compromise as a leading indicator: watch for logins from unusual locations, new source IPs on existing accounts and unusual API activity.
  • Map which of the five nation-state cloud attack patterns (on-prem-to-cloud, cloud-native, cloud-to-cloud, edge/IoT, third-party) applies to your architecture and adapt controls per pattern rather than using one generic cloud policy.
  • Assume token forgery is in scope: monitor for forged SAML/JWT tokens and protect signing keys, not just passwords and MFA.
  • Build AI-aware detection now, since adversaries already use LLMs for reconnaissance, phishing generation, malware debugging and evasion research.

Speakers

Hossein Hadian Jazi
Hossein Hadian Jazi
Senior Cyber Threat Intelligence Expert · Fortinet
Hossein Jazi is a Senior Specialist in Offensive Threats at Fortinet, where he plays a key role as an active researcher with expertise in APT tracking, malware analysis, cyber threat intelligence, and AI security. His work focuses on identifying and… Read moreRead less

Hossein Jazi is a Senior Specialist in Offensive Threats at Fortinet, where he plays a key role as an active researcher with expertise in APT tracking, malware analysis, cyber threat intelligence, and AI security. His work focuses on identifying and monitoring APT activities, as well as publishing in-depth analyses of their operations. Hossein was the first to identify and name the Evasive Panda and Lazy Scripter threat actors, and he has authored more than 50 blogs profiling various cyber adversaries. His current initiatives include developing proactive techniques to track threat actors, collaborating with partners to create advanced research tools, and leading efforts to disrupt and dismantle cybercriminal operations. With a master’s degree in computer science and over 14 years of experience specializing in cybersecurity and APT analysis, Hossein continues to push the boundaries of threat research to make the digital world more secure

Resources

Tags

More from GoSec 2025

Also from Hossein Hadian Jazi

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.