Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Incident Teardowns

Articles in Incident Teardowns.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Entra ID & IdentityIncident Teardowns

Facebook's 'View As' Breach (Sept 2018): 50 Million Access Tokens Stolen

On September 28, 2018, Facebook announced that attackers had exploited a vulnerability in its "View As" feature to steal access tokens. Facebook initially...

Entra ID & IdentityIncident Teardowns

Reddit's Breach via SMS Interception (Aug 2018): Why SMS MFA Isn't Enough

On August 1, 2018, Reddit disclosed that an attacker had accessed some of its systems, including an old database backup with user data from 2007 and email...

Microsoft 365Incident Teardowns

Cambridge Analytica (Mar 2018): What App Permissions Mean for Your Microsoft 365 Tenant

In March 2018, reporting by The Observer and The New York Times revealed that the political consultancy Cambridge Analytica had obtained data on up to 87...

Microsoft 365Incident Teardowns

The Mabna Institute Indictment (Mar 2018): Password Spraying Against Cloud Email

In March 2018, the US Department of Justice indicted nine Iranian nationals associated with the Mabna Institute for a long-running hacking campaign against...

AWSIncident Teardowns

Tesla's Kubernetes Console Cryptojacked (Feb 2018): Exposed Dashboards, Exposed AWS Keys

In February 2018, researchers at RedLock disclosed that attackers had broken into Tesla's cloud environment and used it to mine cryptocurrency.

Multi-CloudIncident Teardowns

Meltdown and Spectre (Jan 2018): When the CPU Itself Was the Vulnerability

On January 3, 2018, researchers disclosed Meltdown and Spectre, a family of vulnerabilities in the way modern processors execute instructions speculatively....

AWSIncident Teardowns

Uber's Hidden Breach (Disclosed Nov 2017): AWS Keys in a Private GitHub Repo

In November 2017, Uber disclosed that a year earlier attackers had stolen personal data on about 57 million riders and drivers, including the driver's...

AWSIncident Teardowns

Pentagon Social Media Surveillance Data in Open S3 Buckets (Nov 2017)

In November 2017, UpGuard researchers found three Amazon S3 buckets configured for public access that contained billions of social media posts collected as...

Multi-CloudIncident Teardowns

Equifax (Sept 2017): One Unpatched Apache Struts Server, 147 Million Records

In September 2017, Equifax disclosed that attackers had stolen personal data on about 147 million people, including Social Security numbers, birth dates and...

Microsoft 365Incident Teardowns

Deloitte's Email Breach (Sept 2017): An Admin Account Without MFA

In September 2017, The Guardian reported that Deloitte, one of the world's largest accounting and consulting firms, had suffered a breach of its global...

AWSIncident Teardowns

Verizon Customer Records Exposed via a Vendor's S3 Bucket (July 2017)

In July 2017, UpGuard researchers reported that records belonging to millions of Verizon customers were sitting in a publicly accessible Amazon S3 bucket....

AzureIncident Teardowns

NotPetya (June 2017): How a Tax Software Update Wiped Out Global Networks

On June 27, 2017, a malware outbreak later called NotPetya began in Ukraine and spread to multinational companies within hours. Shipping giant Maersk had to...

AWSIncident Teardowns

198 Million Voter Records in an Open S3 Bucket (June 2017): Anatomy of a Misconfiguration

In June 2017, researcher Chris Vickery of UpGuard found an Amazon S3 bucket containing personal data on about 198 million American voters. It belonged to...

AzureIncident Teardowns

WannaCry (May 2017): SMBv1, Unpatched Servers and What Cloud Teams Missed

On May 12, 2017, WannaCry ransomware spread across the world in a matter of hours, encrypting files on hundreds of thousands of Windows computers in more...

Multi-CloudIncident Teardowns

Cloudbleed (Feb 2017): When Your CDN Leaks Your Customers' Session Tokens

In February 2017, Google Project Zero researcher Tavis Ormandy noticed something strange in search results: fragments of private data from websites that...

AWSIncident Teardowns

The AWS S3 Outage of February 2017: A Typo That Broke the Internet

On February 28, 2017, Amazon S3 in the US-EAST-1 region became unavailable for about four hours. Thousands of websites and apps stopped working, and even...

Entra ID & IdentityIncident Teardowns

Yahoo's Billion-Account Breach Disclosure (Dec 2016): The Case for MFA Everywhere

In December 2016, Yahoo disclosed that data from roughly one billion user accounts had been stolen in 2013. Months earlier it had disclosed a separate 2014...

Multi-CloudIncident Teardowns

Dyn and the Mirai Botnet (Oct 2016): When DNS Took Down Half the Internet

On October 21, 2016, a large share of the US internet seemed to stop working. Twitter, Netflix, Reddit, GitHub, Spotify and dozens of other services became...

← NewerPage 4 of 4
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.