Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Tenable warns of rising cloud risks in Singapore, Southeast Asia

A report released by cybersecurity firm Tenable on June 19, 2025, highlights major cloud security risks in Singapore and Southeast Asia.

The “2025 Cloud Security Risk Report” reveals issues like misconfigured storage systems and embedded secrets in workloads, which may lead to data breaches and regulatory violations.

It found that 9% of cloud storage resources contain sensitive data, and nearly 10% of publicly accessible storage has confidential information due to weak access controls.

The report also shows that 54% of organizations using AWS ECS task definitions have embedded secrets, creating risks of cloud environment takeovers.

Additionally, 3.5% of AWS EC2 instances have embedded credentials, increasing the threat of privilege escalation.

Ari Eitan, Tenable’s director of Cloud Security Research, warned, “Complacency is costly.” He stressed the need to protect sensitive data and credentials.

🔗 Source: Tenable


🧠 Food for thought

1️⃣ Southeast Asia’s data breach history highlights the urgency of cloud security

The cloud vulnerabilities identified by Tenable aren’t theoretical concerns, as they reflect persistent security issues that have already resulted in significant breaches across the region.

In 2019, Sephora suffered a major breach exposing personal data of customers across Singapore, Malaysia, Indonesia, Thailand, the Philippines, Hong Kong, Australia, and New Zealand, including names, birth dates, and encrypted passwords 1.

That same year, Malindo Air disclosed a breach affecting approximately 30 million passengers when former employees of an Indian contractor improperly accessed sensitive data, including passport numbers, home addresses, and phone numbers 2.

These historical incidents demonstrate the very real consequences of cloud security vulnerabilities in Southeast Asia, particularly the risks associated with third-party contractors and misconfigured access controls, which align with the issues highlighted in Tenable’s findings.

The region’s growing digitalization has only increased the attack surface, with cybersecurity firm Palo Alto Networks reporting a nearly fivefold increase in daily cloud-based security alerts by the end of 2024, including a 235% increase in high-severity alerts targeting identity access management tokens 3.

2️⃣ Southeast Asia’s evolving regulatory landscape creates complex compliance challenges

Tenable’s findings on cloud vulnerabilities are particularly concerning given the increasingly stringent and diverse data protection regulations across Southeast Asia.

Recent Tenable developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.