thehackernews.com 7 Sept 2026, 11:45 UTC

AWS Misconfigurations Outpace Azure and Google Cloud Risks

CyberSIXT Evidence Panel Source marked as original reporting

A recent analysis of misconfigurations across three major cloud providers—AWS, Azure, and Google Cloud—found that risk profiles vary significantly by platform. Intruder’s 2026 Cloud Security Index grouped misconfigurations into six categories: weak IAM, missing logging, misconfigured services, permissive firewalls, exposed services, and weak encryption.

Across the board, weak IAM controls and missing logging affect the vast majority of accounts (roughly 80%–98%) regardless of provider, but the prevalence of the other categories diverges sharply: exposed services are most common on AWS (76%), far less on Azure (64%) and Google Cloud (8%); permissive firewalls follow a similar pattern (AWS 83%, Azure 45%, Google Cloud 34%); weak

encryption shows AWS at 49%, Azure 35%, and Google Cloud 8%; and misconfigured services occur in 68% of AWS accounts, 80% of Azure, and 37% of Google Cloud.

The report suggests that the scale and breadth of services on AWS contribute to higher misconfiguration rates in several categories, while Google Cloud’s lower prevalence may reflect both fewer services and a philosophy of more secure defaults. Azure’s figures show storage and identity as common fault areas, with storage account misconfigurations and Entra ID MFA gaps highlighted.

The analysis also notes that organisation size affects risk: larger enterprises tend to have fewer permissive firewalls, exposed services, or weak encryption, but weak IAM controls remain a persistent issue across all scales. Security teams managing multi‑provider estates are urged to adopt a consistent posture assessment approach that preserves necessary provider‑specific detail for remediation.

View full article

Article by CyberSIXT