Security researchers created 320 honeypots to see how quickly cybercriminals would target exposed cloud. The researchers found that 80% were compromised in less than 24 hours.

Cybercriminals are constantly scanning the Internet for exposed servicesthat could be exploited to access internal networks or perform other malicious activity.
See also: School for hackers: Criminals teach lessons on botnets
To monitor the software and services targeted by threat actors, researchers create honeypots that are accessible to anyone. Honeypots are servers that are configured to appear to be running various software and are used as decoys to monitor cybercriminal tactics.
In a new study conducted by Palo Altos Networks, researchers created 320 honeypots and found that 80% of them were compromised by cybercriminals within the first 24 hours.
The researchers created honeypots with remote desktop protocol (RDP), secure shell protocol (SSH), server message block (SMB), and Postgres database services and kept them “alive” from July to August 2021.
These honeypots were deployed all over the world.

How attackers move to exploit exposed services
The time to breach is proportional to how much cybercriminals generally target a particular type of service.
For SSH honeypots , which were the largest targets, the average time to initial breach was three hours and the average time between two consecutive attacks was approximately 2 hours.
See also: Are Russian cybercriminals seeking partnerships with Chinese hackers?
The researchers also observed a criminal who managed to compromise 96% of 80 Postgres honeypots in just 30 seconds.
This finding is very concerning as it can take days (if not weeks) for new security updates to be deployed, while cybercriminals only need a few hours to exploit exposed services.

Do firewalls help?
The vast majority (85%) of attacker IPs were observed for one day, meaning that actors rarely (15%) reuse the same IP in subsequent attacks.
This constant IP change makes 'layer 3' firewall rules ineffective against the majority of threat.
See also: Hackers offer millions for zero-days
According to the researchers, to protect cloud services from cybercriminals, administrators should do the following:
- Creating a guardrail to prevent the opening of privileged ports.
- Create audit rules to monitor all open ports and exposed services.
- Create automated response and remediation rules to automatically correct misconfigurations.
- Use of next-generation firewalls (WFA or VM-Series).
- Install the latest security updates (as soon as they become available), as cybercriminals are quick to exploit new vulnerabilities.
Source: Bleeping Computer
