🧔♂️ A friendly human may check it before it goes live. More news here
Tenable warns of rising cloud risks in Singapore, Southeast Asia
A report released by cybersecurity firm Tenable on June 19, 2025, highlights major cloud security risks in Singapore and Southeast Asia.
The “2025 Cloud Security Risk Report” reveals issues like misconfigured storage systems and embedded secrets in workloads, which may lead to data breaches and regulatory violations.
It found that 9% of cloud storage resources contain sensitive data, and nearly 10% of publicly accessible storage has confidential information due to weak access controls.
The report also shows that 54% of organizations using AWS ECS task definitions have embedded secrets, creating risks of cloud environment takeovers.
Additionally, 3.5% of AWS EC2 instances have embedded credentials, increasing the threat of privilege escalation.
Ari Eitan, Tenable’s director of Cloud Security Research, warned, “Complacency is costly.” He stressed the need to protect sensitive data and credentials.
🔗 Source: Tenable
🧠 Food for thought
1️⃣ Southeast Asia’s data breach history highlights the urgency of cloud security
The cloud vulnerabilities identified by Tenable aren’t theoretical concerns, as they reflect persistent security issues that have already resulted in significant breaches across the region.
In 2019, Sephora suffered a major breach exposing personal data of customers across Singapore, Malaysia, Indonesia, Thailand, the Philippines, Hong Kong, Australia, and New Zealand, including names, birth dates, and encrypted passwords 1.
That same year, Malindo Air disclosed a breach affecting approximately 30 million passengers when former employees of an Indian contractor improperly accessed sensitive data, including passport numbers, home addresses, and phone numbers 2.
These historical incidents demonstrate the very real consequences of cloud security vulnerabilities in Southeast Asia, particularly the risks associated with third-party contractors and misconfigured access controls, which align with the issues highlighted in Tenable’s findings.
The region’s growing digitalization has only increased the attack surface, with cybersecurity firm Palo Alto Networks reporting a nearly fivefold increase in daily cloud-based security alerts by the end of 2024, including a 235% increase in high-severity alerts targeting identity access management tokens 3.
2️⃣ Southeast Asia’s evolving regulatory landscape creates complex compliance challenges
Tenable’s findings on cloud vulnerabilities are particularly concerning given the increasingly stringent and diverse data protection regulations across Southeast Asia.
Recent Tenable developments
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




