Detecting SaaS Credential Stuffing: Sentinel and GuardDuty Detections
Infostealer-sourced credentials are used against SaaS platforms in automated campaigns. These detections help catch SaaS account takeover and data theft.
Insights
Articles in Multi-Cloud.
Infostealer-sourced credentials are used against SaaS platforms in automated campaigns. These detections help catch SaaS account takeover and data theft.
The short version: In 2024, attackers stole data from about 165 companies' accounts on Snowflake, a cloud data platform — including Ticketmaster and AT&T....
On March 29, 2024, Microsoft engineer Andres Freund disclosed that he had found a backdoor in XZ Utils, a compression library included in many Linux...
When a compromised package like XZ Utils is discovered, you need to know quickly whether it's in your cloud images and containers. Here is how to scan...
Compromised open-source packages are hard to detect by behavior — they're designed to look legitimate. Detection relies on inventory, threat intelligence...
The short version: In 2024, a hidden backdoor was discovered in XZ Utils, a small but widely used piece of free software in Linux systems. Someone had spent...
Change Healthcare and Colonial Pipeline were both breached through remote access without MFA. Here is how to enforce MFA on every remote access portal.
Remote access without MFA is a top ransomware entry point. These detections look for single-factor access and the activity that typically follows.
The short version: In February 2024, ransomware shut down Change Healthcare, disrupting pharmacies and medical billing across the US for weeks. The...
Attackers repeatedly target internet-facing file transfer, integration and remote access services. Here is how to inventory them so you can patch, restrict...
Mass exploitation of file transfer products typically targets web interfaces and ends with bulk data downloads. These detections help catch both stages.
The short version: In 2023, a ransomware gang exploited a flaw in MOVEit, a file transfer product, stealing data from over 2,000 organizations — many of...
On January 4, 2023, CircleCI, a widely used continuous integration and delivery platform, told customers to rotate all secrets stored in its platform...
When a provider tells you to rotate everything, the hardest part is knowing what "everything" is. A rotation fire drill — practiced in advance — makes it...
After a CI/CD provider breach, attackers use stolen secrets to access your cloud. Detecting that use — and use of secrets after rotation — tells you whether...
The short version: In January 2023, CircleCI — a service many companies use to build and deploy software — told every customer to change every password and...
In August 2022, password manager LastPass disclosed that an attacker had accessed its development environment. In December 2022, it revealed that the...
In the LastPass breach, attackers stole backups from cloud storage using credentials taken from an engineer's home computer. Backups need their own...
Attackers increasingly target backups — to steal data or to delete it before ransomware. These detections watch for unusual backup access and changes.
The short version: In 2022, attackers stole encrypted copies of LastPass customers' password vaults by hacking an engineer's home computer and using it to...
In April 2022, GitHub disclosed that an attacker had used stolen OAuth user tokens issued to two third-party integrators — Heroku and Travis CI — to...
Stored cloud credentials in CI/CD systems are a prime target. OIDC federation lets pipelines get short-lived credentials from AWS or Azure on demand — with...
Stolen OAuth tokens let attackers act as a trusted app without passwords or MFA. Detection focuses on token use that doesn't fit the app's normal behavior.
The short version: In 2022, attackers stole the digital access passes that Heroku and Travis CI used to connect to customers' GitHub code repositories, and...