Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AzureIncident Teardowns

WannaCry (May 2017): SMBv1, Unpatched Servers and What Cloud Teams Missed

On May 12, 2017, WannaCry ransomware spread across the world in a matter of hours, encrypting files on hundreds of thousands of Windows computers in more...

AzureHow-To & Hardening

How to Disable SMBv1 and Enforce Patch Compliance on Azure VMs

SMBv1 is a decades-old file-sharing protocol with known critical flaws, and it was the doorway for WannaCry and NotPetya. Here is how to remove it from...

AzureDetection & Response

Detecting SMBv1 Exploitation: Defender for Cloud and Sentinel KQL

WannaCry and its successors exploited SMB flaws to spread across networks. Even with SMBv1 removed, detecting suspicious SMB activity is a valuable early...

AzureCIO Briefings

CIO Brief: Why Patch Management Is a Board-Level Issue After WannaCry

The short version: In 2017, WannaCry ransomware infected hundreds of thousands of computers worldwide using a Windows flaw that had been patched two months...

Multi-CloudIncident Teardowns

Cloudbleed (Feb 2017): When Your CDN Leaks Your Customers' Session Tokens

In February 2017, Google Project Zero researcher Tavis Ormandy noticed something strange in search results: fragments of private data from websites that...

Multi-CloudHow-To & Hardening

How to Rotate Sessions and Secrets After a Third-Party Provider Leak

When a provider you depend on — a CDN, identity platform, CI/CD service or SaaS tool — announces that tokens or secrets may have leaked, speed matters more...

Multi-CloudDetection & Response

Detecting Leaked Session Tokens: Sentinel and GuardDuty Detections

When a provider leaks session tokens, the question is whether anyone used them. Detection focuses on sessions that look valid but behave differently from...

Multi-CloudCIO Briefings

CIO Brief: Managing Risk When a Core Internet Provider Has a Bug

The short version: In 2017, a bug at Cloudflare, a major internet provider, leaked private data from customer websites, including login sessions. The...

AWSIncident Teardowns

The AWS S3 Outage of February 2017: A Typo That Broke the Internet

On February 28, 2017, Amazon S3 in the US-EAST-1 region became unavailable for about four hours. Thousands of websites and apps stopped working, and even...

AWSHow-To & Hardening

How to Architect S3 Workloads for Multi-Region Resilience

Amazon S3 is extremely durable, but a single region can still become unavailable. Here is how to design S3-backed workloads to keep running — or at least...

AWSHow-To & Hardening

Running a Cloud Outage Tabletop Exercise for Your IT Team

Outages are rare enough that teams forget how to handle them. A tabletop exercise — a structured discussion of a realistic scenario — is the cheapest way to...

AWSCIO Briefings

CIO Brief: Availability Is Security — Building Outage Risk Into Your Cloud Strategy

The short version: In 2017, a mistyped command at Amazon took down a core storage service in one region for about four hours, and thousands of websites went...

AWSPlatform Changes

AWS Shield Launches at re:Invent 2016: Free DDoS Protection Becomes the Default

At AWS re:Invent in late 2016, Amazon announced AWS Shield, its managed DDoS protection service. The headline was simple: every AWS customer would get...

AWSHow-To & Hardening

How to Configure AWS Shield Advanced and AWS WAF Rate-Based Rules

AWS Shield Standard protects every AWS account against common network-layer DDoS attacks automatically. Application-layer attacks need more work. Here is...

AWSHow-To & Hardening

DDoS Readiness Checklist for AWS-Hosted Applications

Use this checklist to check whether an AWS-hosted application is ready for a denial-of-service attack. Each "no" is a gap to plan for.

AWSCIO Briefings

CIO Brief: Shield Standard vs. Advanced — Is Paid DDoS Protection Worth It?

The short version: Every AWS customer gets Shield Standard free, and it handles the most common DDoS attacks. Shield Advanced is a paid upgrade that adds...

Entra ID & IdentityIncident Teardowns

Yahoo's Billion-Account Breach Disclosure (Dec 2016): The Case for MFA Everywhere

In December 2016, Yahoo disclosed that data from roughly one billion user accounts had been stolen in 2013. Months earlier it had disclosed a separate 2014...

Entra ID & IdentityHow-To & Hardening

How to Roll Out MFA to Every Microsoft 365 User Without a Help Desk Meltdown

Turning on multi-factor authentication for every Microsoft 365 user is the single most effective identity control you can deploy. It is also the change most...

Entra ID & IdentityDetection & Response

Detecting Credential Stuffing Attacks: Entra Sign-In Logs and Sentinel KQL

Credential stuffing uses username and password pairs leaked from other breaches to try to sign in to your Microsoft 365 tenant. Detection is about spotting...

Entra ID & IdentityCIO Briefings

CIO Brief: Credential Breaches at Other Companies Are Your Problem Too

The short version: When a big company like Yahoo loses billions of passwords, your company is also at risk. Your employees reuse passwords, and attackers...

Multi-CloudIncident Teardowns

Dyn and the Mirai Botnet (Oct 2016): When DNS Took Down Half the Internet

On October 21, 2016, a large share of the US internet seemed to stop working. Twitter, Netflix, Reddit, GitHub, Spotify and dozens of other services became...

Multi-CloudHow-To & Hardening

How to Design Multi-Provider DNS and DDoS Protection for Azure and AWS Workloads

The 2016 Dyn attack proved that DNS can take a healthy application offline. Here is a practical way to design DNS and DDoS protection for workloads running...

Multi-CloudDetection & Response

Detecting DNS DDoS Attacks: Sentinel and GuardDuty Detections

DDoS attacks against DNS and web front ends are noisy, which makes them easy to notice and hard to diagnose quickly. The goal of detection is speed: confirm...

Multi-CloudCIO Briefings

CIO Brief: What the Dyn Outage Taught Us About Single Points of Failure in the Cloud

The short version: In October 2016, an attack on one DNS company, Dyn, made major websites unreachable for hours. The websites were fine. A supplier they...

← NewerPage 20 of 20
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.