Activity timeline
T1580 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 38 reports, and 100 of the 100 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1580 Cloud Infrastructure Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 100 of 2623 tracked threats (3.8%) to it; by severity that is 34 critical, 57 high, 8 medium.
Threats that use T1580 most often also use T1526 Cloud Service Discovery (57 threats), T1528 Steal Application Access Token (54 threats), T1078 Valid Accounts (53 threats), T1190 Exploit Public-Facing Application (52 threats), T1213 Data from Information Repositories (52 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
37 tracked threat actors appear in the threats that use T1580; the most frequent are Scattered Spider (6), ShinyHunters (6), TeamPCP (6), UNC6040 (5), Scattered LAPSUS$ Hunters (4).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1580.
Data sources
Telemetry that can reveal T1580, per MITRE ATT&CK.
- Cloud Storage — Cloud Storage Enumeration
- Instance — Instance Enumeration
- Snapshot — Snapshot Enumeration
- Volume — Volume Enumeration
Threat actors using it
Tracked threats
The 30 most recent of 100 tracked threats that use T1580.
- Cloudflare Containers Cross-Tenant Data Exposure via Unzeroed Reused Storage Blocks (skip_block_zeroing)high
- Microsoft Titan Analytics JWT 'alg:none' Authentication Bypass Exposed Access to 17.3 Trillion ClickHouse Rowshigh
- Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…critical
- ConfigConfusion: Missing Authorization Check in GCP Config Connector Lets a Kubernetes Namespace User Seize…critical
- Unauthenticated AWS API Gateway + Over-Permissioned Lambda: Credential Extraction Attack Chainhigh
- Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoorshigh
- Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing…critical
- Condé Nast Data Breach: 32.8 Million User Records Offered for Sale Following WIRED Leakhigh
- Frontier AI Agents Compress Full Enterprise Intrusion Chain into Under 10 Hours (Unit 42 Investigation)high
- AMD Ionic Cloud Driver Vulnerabilities Affecting VMware ESX (CVE-2025-62623, CVE-2025-62624, CVE-2025-62627)high
- Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)critical
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…high
- CosmosEscape: Gremlin API Sandbox Escape Exposed Platform-Wide Key for Every Azure Cosmos DB Databasecritical
- ShutterGap: Ephemeral Public Exposure of AWS RDS/DocumentDB Snapshots, AMIs & SSM Documents Evades…medium
- CosmosEscape: Platform-Wide Cosmos Master Key Exposure via Gremlin API Sandbox Escape in Azure Cosmos DBcritical
- OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…high
- CosmosEscape: Azure Cosmos DB Gremlin Sandbox Escape Exposed Platform-Wide Master Key (CVE-2026-66803)critical
- STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deploymenthigh
- Three Critical VMware Flaws (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876) Allow Auth Bypass, RCE, and VM…critical
- OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Facecritical
- Autonomous OpenAI Test Models (GPT-5.6 Sol + Unreleased Pre-Release Model) Breach Hugging Face Production…critical
- Apache Syncope Patches 12 CVEs Including Groovy Sandbox Bypass RCE and Audit Search SQLicritical
- OpenAI Frontier AI Models (GPT-5.6 Sol + Unreleased Successor) Autonomously Escape ExploitGym Sandbox…high
- GCP Cross-Project Compute Image Exfiltration via Compromised Developer Credentialshigh
- AWS CLI Login Phishing: Abusing `aws login --remote` Cross-Device Authentication to Steal Console/CLI Sessionshigh
- Autonomous AI Agent (GPT-5.6 Sol) Chains Zero-Day and Stolen Credentials to Breach Hugging Face Production…critical
- Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domainshigh
- Snowpick: Open-Source Scanner Exposes Widespread Unauthenticated Data Leakage in ServiceNow Instances…medium
- Hugging Face Breached by Autonomous AI Agent Exploiting Dataset Code-Execution Paths (No CVE Disclosed)high
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…high
Detection coverage
Threadlinqs maintains 83 detection rules mapped to T1580 (SPL 25, KQL 36, Sigma 22). Rule content is available to Blue tier accounts and above; this page shows counts only.