Cloud environments are configured, not built — which means most cloud security issues are misconfigurations, not vulnerabilities in the traditional sense. A few show up so often they’re almost predictable:
Over-permissioned IAM roles granted for convenience during initial setup and never scoped down. Storage buckets with public read access left over from a one-time file share. Cross-account trust relationships nobody remembers granting, often from a decommissioned integration. Default security group rules left wide open on a ‘temporary’ test instance. And logging that’s enabled but never actually reviewed by anyone.
None of these require a zero-day to exploit — they just require someone to look, which is exactly what a cloud assessment is for.