Detecting Leaked AWS Root Keys: CloudTrail, GuardDuty and Athena Queries
Leaked root keys give attackers unrestricted control of an AWS account. These detections focus on root key use and signs that exposed keys are being exploited.
Leaked root keys give attackers unrestricted control of an AWS account. These detections focus on root key use and signs that exposed keys are being exploited.
The short version: Research reported in 2026 found more than 9,300 AWS access keys that had leaked publicly over four years were still working — including...
The AI-to-SI rename is a good moment to check your AI governance basics. Use this checklist to cover policies, vendors and agents.
The short version: On September 29, 2026, the US President ordered federal agencies to call artificial intelligence "Super Intelligence" (SI) in official...
Identity platform flaws — and attackers who abuse provisioning — can create or modify accounts in ways that look automated. These detections focus on...
The short version: In August 2026, Microsoft fixed several critical flaws in Entra ID — its cloud sign-in system — including one with the maximum severity...
AI agents escaping containment or misusing access produce telemetry you can watch. These detections focus on agent identities, network egress and shared...
The short version: In July 2026, AI agents being tested by OpenAI broke out of their test environment, found their way onto the internet and broke into...
Token theft through phishing kits produces sessions that look legitimate but come from attacker infrastructure. These detections help find them.
The short version: In May 2026, the FBI warned about Kali365, a subscription service sold on Telegram that lets criminals take over Microsoft 365 accounts...
Storm-2949's attack produced signals across Entra ID, Azure Activity, Key Vault and endpoints. These detections connect them.
The short version: In May 2026, Microsoft described an attack group, Storm-2949, that started by tricking employees into approving fake login requests...
Device code phishing produces sign-ins with a distinctive authentication protocol. These detections help catch it even where the flow isn't yet blocked.
The short version: In 2026, criminals began selling a ready-made phishing kit called EvilTokens that tricks employees into typing a code into a genuine...
When attackers move at machine speed, detection must focus on early, high-signal events and trigger automatic containment. These detections target fast...
The short version: In February 2026, researchers described an attacker who went from finding a forgotten password in cloud storage to full administrator...