Imperva's Cloud WAF Breach (Aug 2019): A Stolen AWS API Key From an Internal Instance
In August 2019, Imperva, a security company known for its cloud web application firewall (formerly Incapsula), disclosed a data exposure affecting customers...
Insights
Articles in Retrospectives.
In August 2019, Imperva, a security company known for its cloud web application firewall (formerly Incapsula), disclosed a data exposure affecting customers...
Long-lived IAM user access keys are one of the most common causes of AWS breaches. IAM roles and IAM Identity Center provide short-lived credentials...
Stolen AWS API keys are frequently used for reconnaissance, data theft and resource abuse. These detections help you spot misuse quickly.
The short version: In 2019, Imperva — a company that sells security protection — disclosed that customer data was exposed after an attacker stole a cloud...
On July 29, 2019, Capital One disclosed a breach affecting about 100 million people in the US and 6 million in Canada. It became the defining cloud breach...
IMDSv2 protects EC2 instance credentials from server-side request forgery, the technique used in the Capital One breach. Combined with least-privilege...
The Capital One attack path — SSRF to the metadata service, then stolen role credentials used to read data — leaves traces in CloudTrail and GuardDuty if...
The short version: Capital One's 2019 breach exposed data on about 106 million people. It was caused by a misconfigured firewall combined with a server that...
In June 2019, AWS Control Tower became generally available. It automated the creation of a secure multi-account AWS environment — a landing zone — with...
AWS Control Tower sets up a governed multi-account environment with guard rails. Here is how to set it up and choose the right controls.
Control Tower offers hundreds of controls. Use this checklist to choose a practical starting set.
The short version: AWS Control Tower, released in 2019, sets up your AWS cloud as a well-organized group of accounts with security rules built in. It is the...
In May 2019, Microsoft patched CVE-2019-0708, a critical vulnerability in Remote Desktop Services that became known as BlueKeep. It affected older Windows...
Exposed RDP and SSH ports are among the most attacked entry points in the cloud. Azure Bastion and just-in-time (JIT) VM access let administrators reach...
Even with patches, exposed RDP invites brute force, credential stuffing and exploitation. Detecting both the exposure and attacks against it is essential...
The short version: In 2019, Microsoft warned about BlueKeep, a flaw that could let attackers take over older Windows computers through remote desktop...
In April 2019, Microsoft notified some users of its consumer email services — Outlook.com, Hotmail and MSN — that a support agent's credentials had been...
Help desk and support staff can reset passwords, change MFA methods and see user data. Here is how to scope those roles tightly in Microsoft 365 and Entra ID.
A compromised help desk account — or a manipulated help desk agent — can reset credentials across your organization. Detecting unusual support activity...
The short version: In 2019, attackers got into Microsoft's consumer email support systems by compromising a single support agent's account. Help desks are...
In March 2019, Citrix disclosed that the FBI had informed it of a breach of its internal network. The FBI's assessment, according to Citrix, was that...
Entra ID includes two built-in defenses against password spraying: smart lockout and Identity Protection. Here is how to configure both.
Password spray attacks distribute attempts to avoid detection. Combining Entra ID's built-in detections with your own queries gives you the best chance of...
The short version: In 2019, Citrix — a company that sells remote access technology to enterprises — was breached, likely through attackers trying common...