Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Multi-Cloud

Articles in Multi-Cloud.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Multi-CloudIncident Teardowns

Log4Shell (Dec 2021): The Vulnerability in Everything

On December 9, 2021, a critical vulnerability in Apache Log4j 2 — a Java logging library used in countless applications — became public. Tracked as...

Multi-CloudHow-To & Hardening

How to Find Vulnerable Libraries in Azure and AWS Workloads

When a library vulnerability like Log4Shell hits, the first question is "where are we affected?" Here is how to answer it across Azure and AWS workloads.

Multi-CloudDetection & Response

Detecting Log4j Exploitation: Sentinel and GuardDuty Detections

Log4Shell exploitation attempts appear in web logs and network traffic, and successful exploitation often produces outbound connections and unusual processes.

Multi-CloudCIO Briefings

CIO Brief: Software Bills of Materials After Log4Shell

The short version: In December 2021, a flaw was found in Log4j, a small piece of free software used inside thousands of products. Companies spent weeks just...

Multi-CloudIncident Teardowns

Kaseya VSA (July 2021): Ransomware Delivered Through an MSP Tool

On July 2, 2021 — the start of a US holiday weekend — the REvil ransomware group exploited a zero-day vulnerability in Kaseya VSA, a remote monitoring and...

Multi-CloudHow-To & Hardening

How to Restrict and Monitor MSP Access to Your Microsoft 365 Tenant

Managed service providers often have broad administrative access to customer Microsoft 365 tenants. Here is how to restrict and monitor that access.

Multi-CloudDetection & Response

Detecting MSP Supply Chain Attack: Sentinel and GuardDuty Detections

MSP supply-chain attacks use legitimate management tools and access. Detection focuses on unusual use of those tools and partner accounts.

Multi-CloudCIO Briefings

CIO Brief: Your MSP Has Admin Rights — Are You Watching?

The short version: In 2021, ransomware spread through Kaseya — software that IT service providers use to manage their clients' computers — reaching up to...

Multi-CloudIncident Teardowns

Colonial Pipeline (May 2021): One Legacy VPN Password Without MFA

On May 7, 2021, Colonial Pipeline — which carries a large share of the fuel supply for the US East Coast — shut down its pipeline operations after a...

Multi-CloudHow-To & Hardening

How to Find Remote Access Accounts That Bypass MFA

Colonial Pipeline and Change Healthcare were both breached through remote access accounts without MFA. Here is how to find accounts and access paths that...

Multi-CloudDetection & Response

Detecting VPN Logins Without MFA: Sentinel and GuardDuty Detections

Sign-ins without MFA to remote access systems are a leading ransomware entry point. These detections highlight them.

Multi-CloudCIO Briefings

CIO Brief: Colonial Pipeline and the Business Case for MFA on Everything

The short version: In 2021, Colonial Pipeline shut down fuel deliveries across the US East Coast after ransomware. The attackers got in through one old...

Multi-CloudPlatform Changes

Executive Order 14028 (May 2021): Zero Trust Becomes US Federal Policy

On May 12, 2021, President Biden signed Executive Order 14028, Improving the Nation's Cybersecurity, in response to SolarWinds, Microsoft Exchange...

Multi-CloudHow-To & Hardening

How to Build a Zero Trust Roadmap Using Microsoft and AWS Controls

"Zero trust" can sound abstract. In practice, it means verifying every access request based on identity, device and context — and limiting what each request...

Multi-CloudHow-To & Hardening

Zero Trust Maturity Self-Assessment Checklist

Use this self-assessment to estimate your zero trust maturity across five pillars. Score each item: 0 = not started, 1 = partial, 2 = complete.

Multi-CloudCIO Briefings

CIO Brief: What the Federal Zero Trust Mandate Means for Private Companies

The short version: In 2021, a US executive order made "zero trust" official federal policy and required multi-factor authentication, encryption and better...

Multi-CloudIncident Teardowns

Verkada Camera Breach (Mar 2021): A Super Admin Credential Left Exposed

In March 2021, a group of hackers gained access to Verkada, a cloud-based security camera company, and viewed live feeds from roughly 150,000 cameras at...

Multi-CloudHow-To & Hardening

How to Find and Vault Hardcoded Credentials Across Cloud Services

Hardcoded credentials in scripts, configuration files and repositories are one of the easiest ways for attackers to escalate. Here is how to find them...

Multi-CloudDetection & Response

Detecting Exposed Super Admin Credentials: Sentinel and GuardDuty Detections

Exposed administrator credentials are often used soon after discovery. Detecting both the exposure and the misuse helps you respond before damage spreads.

Multi-CloudCIO Briefings

CIO Brief: IoT and SaaS Admin Access — The Overlooked Privilege

The short version: In 2021, hackers accessed about 150,000 security cameras — in hospitals, schools and factories — by finding a single "super admin"...

Multi-CloudIncident Teardowns

Blackbaud Ransomware (July 2020): When Your SaaS Provider Pays the Ransom

In July 2020, Blackbaud — a cloud software provider widely used by nonprofits, universities and healthcare organizations for fundraising and donor...

Multi-CloudHow-To & Hardening

How to Assess SaaS Vendors' Security Before You Sign

SaaS vendors hold your data, and their security directly affects yours. Here is a practical approach to assessing SaaS vendors before you sign —...

Multi-CloudDetection & Response

Monitoring Third-Party SaaS Risk Signals and Breach Notifications

You can't monitor a SaaS vendor's internal systems, but you can monitor signals that indicate rising risk — and your own exposure if something goes wrong.

Multi-CloudCIO Briefings

CIO Brief: Third-Party Ransomware and Your Disclosure Obligations

The short version: In 2020, Blackbaud — software used by thousands of charities and schools — was hit by ransomware and paid the attackers. Its customers...

← NewerPage 3 of 5Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.