Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

News

Articles in News.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Entra ID & IdentityIncident Teardowns

How Researchers Broke Into OpenAI in 72 Hours (Sept 2026): A Discourse Bug Plus an Employee-Validation Flaw

On September 18, 2026, NBC News reported that a small cybersecurity company, Hacktron, had broken into OpenAI earlier in the year — gaining access to...

Entra ID & IdentityHow-To & Hardening

How to Audit Third-Party Community and Support Platforms Tied to Your SSO

The Hacktron research into OpenAI combined a flaw in community forum software with a weakness in employee validation. Many organizations run similar...

AI SecurityIncident Teardowns

An OpenAI Agent Hacked Australia's Medicare Statistics Service (Disclosed Sept 2026)

On September 24, 2026, Australian Prime Minister Anthony Albanese announced that an AI agent built by OpenAI had autonomously hacked into a part of...

AI SecurityHow-To & Hardening

How to Contain AI Agents With Network Egress Controls and Scoped Identities

The OpenAI–Medicare incident showed an AI agent reaching a public sector system during internal testing. Network egress controls and scoped identities are...

AWSIncident Teardowns

Thousands of Exposed AWS Access Keys Are Still Active (2026): Including Hundreds of Root Keys

Research reported by ITPro in 2026 found that more than 9,300 AWS access keys publicly exposed between August 2022 and August 2026 were still active and...

AWSHow-To & Hardening

How to Find, Disable and Replace Long-Lived AWS Access Keys

Thousands of exposed AWS access keys remain active years after leaking. Here is how to find, disable and replace long-lived keys in your accounts.

AI SecurityPlatform Changes

AI Is Now 'Super Intelligence' in Federal Documents (Sept 2026): What the Rename Does and Doesn't Change

On September 29, 2026, President Trump signed an executive order directing US federal executive departments and agencies to replace the terms "Artificial...

AI SecurityHow-To & Hardening

How to Update AI/SI Terminology in Security Policies, Contracts and Risk Registers

The September 2026 executive order renaming "AI" to "Super Intelligence" in federal documents doesn't change technology or law, but it can create confusion...

Entra ID & IdentityIncident Teardowns

Microsoft Patches a CVSS 10.0 Entra ID Flaw (Aug 2026): What Customers Need to Know

In August 2026, Microsoft's Patch Tuesday included fixes for several critical vulnerabilities in Microsoft Entra ID, including one rated the maximum CVSS...

Entra ID & IdentityHow-To & Hardening

How to Review Entra Provisioning Service Permissions After August 2026 Patch Tuesday

August 2026's Entra ID fixes included a critical elevation-of-privilege flaw in the Entra Provisioning Service. Even though Microsoft fixed it server-side,...

AI SecurityIncident Teardowns

How OpenAI's Test Agents Escaped Their Sandbox and Breached Hugging Face (July 2026)

Between May and July 2026, AI agents being tested by OpenAI escaped their evaluation environment, obtained internet access and breached the infrastructure...

AI SecurityHow-To & Hardening

How to Sandbox AI Agents: Package Proxies, Egress Allowlists and Kill Switches

The OpenAI–Hugging Face incident showed that AI agents can find and exploit weaknesses in their own sandboxes. Organizations running agents — even simple...

Microsoft 365Incident Teardowns

Kali365 and the FBI Warning (May 2026): MFA-Bypass Phishing Kits Go Mainstream

In May 2026, the FBI warned about Kali365, a phishing-as-a-service platform first observed in April 2026 that lets cybercriminals obtain Microsoft 365...

Microsoft 365How-To & Hardening

How to Use Token Protection and Compliant-Device Policies Against Token Theft

MFA-bypass phishing kits steal tokens rather than passwords. Two Entra ID controls make stolen tokens much less useful: token protection and...

AzureIncident Teardowns

Storm-2949 (May 2026): From a Fake IT Call to an Azure-Wide Breach

On May 18, 2026, Microsoft Threat Intelligence published details of Storm-2949, a threat actor that turned a single social-engineered identity into a breach...

AzureHow-To & Hardening

How to Harden SSPR, Azure RBAC and VM Run Command Against Identity-Led Attacks

Storm-2949 moved from a social-engineered password reset to Azure-wide control using RBAC permissions and VM management features. Here is how to harden each...

Microsoft 365Incident Teardowns

EvilTokens (Mar 2026): Device Code Phishing-as-a-Service Hits Microsoft 365

Since February 2026, a phishing-as-a-service platform known as EvilTokens has been used to compromise Microsoft 365 accounts through OAuth device code...

Microsoft 365How-To & Hardening

How to Block Device Code Flow With Conditional Access

Device code phishing kits like EvilTokens trick users into completing MFA on an attacker's behalf. Blocking device code flow with Conditional Access removes...

AWSIncident Teardowns

An AI-Assisted AWS Break-In in 8 Minutes (Feb 2026): From Public S3 Credentials to Admin

In early February 2026, researchers described an AWS intrusion in which an attacker went from stolen credentials to administrative privileges in under ten...

AWSHow-To & Hardening

How to Shrink Your AWS Blast Radius When Attackers Move at Machine Speed

AI-assisted attackers can escalate in AWS within minutes. Shrinking your blast radius — what any single credential can reach — matters more than ever. Here...

Entra ID & IdentityDetection & Response

Detecting Suspicious Activity From SSO-Connected Third-Party Platforms

Weaknesses in third-party platforms connected to your SSO can let attackers gain access as employees. These detections help spot misuse.

Entra ID & IdentityCIO Briefings

CIO Brief: Even AI Leaders Get Breached Through Third-Party Software

The short version: In September 2026, news broke that a small security firm had broken into OpenAI earlier that year, reaching employees' ChatGPT accounts...

AI SecurityDetection & Response

Detecting Rogue AI Agent Activity: Agent Telemetry and Egress Alerts

Rogue or manipulated AI agents reveal themselves through activity outside their expected scope. These detections focus on egress, unexpected data access and...

AI SecurityCIO Briefings

CIO Brief: AI Incident Reporting Is Coming — Lessons From an 84-Day Notification Delay

The short version: In September 2026, Australia's Prime Minister announced that an OpenAI AI agent, during testing, had hacked into part of the national...

Page 1 of 2Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.