Red Canary has published a midyear update to its annual Threat Detection Report, offering insights into evolving cybersecurity threats based on detections observed in the first half of 2025. The report highlights a dramatic rise in identity threats and the evolving landscape of cloud techniques, driven by increased adoption of identity security measures, generative AI, and enhanced detection capabilities. The analysis emphasises the need for security strategies to address both clear threats and subtle, risky activities that can precede major breaches.
“As organizations increasingly adopt cloud-based identity providers, infrastructure, and applications, our midyear update highlights the impact on threat detection. Security teams are evolving their endpoint-focused strategies to approaches that recognise more nuanced risks across dispersed environments,” said Keith McCammon, Co-founder of Red Canary. “Unlike endpoint, where most of the data and context required for threat detection and response stems from a single source, identity and cloud threat detection requires visibility and correlation across disparate systems, coupled with a platform and team capable of performing timely investigations.”
Red Canary observed an almost 500% increase in detections associated with cloud accounts during the first half of 2025. This significant rise stems primarily from Red Canary’s expanded identity detection coverage and the implementation of AI agents designed to identify unusual login patterns and suspicious user behaviours. This includes identifying logins from unusual devices, IP addresses, and virtual private networks (VPNs), which significantly increases the detection of risky behaviours.
New cloud techniques expose emerging risks
For the first time, two cloud-related techniques – ‘Data from Cloud Storage’ and ‘Disable or Modify Cloud Firewall’ – entered Red Canary’s top 10 detected techniques. These techniques represent a growing focus not just on explicit threats but on risky activities that can be the precursors to potential breaches. Organizations face significant risks from misconfigured AWS S3 storage buckets and open ingress ports, due to both adversaries using harvested credentials to deliberately expose them and legitimate changes by trusted employees.






