Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AzureIncident Teardowns

BlueBleed (Oct 2022): Misconfigured Azure Blob Storage Exposes Microsoft Customer Data

In October 2022, threat intelligence company SOCRadar reported a data leak it called BlueBleed: a misconfigured Microsoft-owned Azure Blob Storage container...

AzureHow-To & Hardening

How to Audit Azure Storage Accounts for Public Access and Shared Keys

Azure Storage accounts can be exposed through anonymous blob access, overly permissive shared keys and SAS tokens, or public network endpoints. Here is how...

AzureDetection & Response

Detecting Azure Blob Public Access: Defender for Cloud and Sentinel KQL

Public Azure Blob access is often discovered by outsiders scanning for open containers. Detecting both the configuration and anonymous access helps you find...

AzureCIO Briefings

CIO Brief: Storage Misconfiguration Is a Cloud-Agnostic Problem

The short version: In 2022, researchers reported that a misconfigured Microsoft storage location exposed business documents involving Microsoft's customers....

Entra ID & IdentityIncident Teardowns

Uber Breached via MFA Fatigue (Sept 2022): A Contractor, a Push Storm and Hardcoded Admin Secrets

On September 15, 2022, Uber disclosed a network security incident. An attacker had gained access to internal systems including its Slack workspace, cloud...

Entra ID & IdentityHow-To & Hardening

How to Write Conditional Access Policies for Contractors and Guests

Contractors and guests often have less oversight than employees but similar access. Conditional Access lets you apply consistent — or stricter — controls....

Entra ID & IdentityDetection & Response

Detecting MFA Push Bombing: Entra Sign-In Logs and Sentinel KQL

MFA push bombing generates bursts of MFA requests. Even with number matching, attackers try variations. These detections help catch attempts early.

Entra ID & IdentityCIO Briefings

CIO Brief: Contractors Need the Same Security as Employees

The short version: In 2022, Uber was breached through a contractor whose password had been stolen and who eventually approved one of many login prompts....

Microsoft 365Incident Teardowns

ProxyNotShell (Sept 2022): The Third Major Exchange Zero-Day Wave

On September 29, 2022, Microsoft confirmed two zero-day vulnerabilities in on-premises Microsoft Exchange Server being exploited in limited, targeted...

Microsoft 365How-To & Hardening

How to Decommission the Last Exchange Server in a Hybrid Deployment

Many organizations moved all mailboxes to Exchange Online but kept one Exchange server for recipient management. Microsoft now supports removing it in many...

Microsoft 365Detection & Response

Detecting Exchange Zero-Day: Defender XDR and Sentinel Hunting Queries

Even after patching, exploited Exchange servers may still be compromised. These detections focus on post-exploitation behaviors common to ProxyNotShell and...

Microsoft 365CIO Briefings

CIO Brief: When to Finally Leave On-Prem Exchange

The short version: In late 2022, a third major wave of attacks hit company-run Microsoft Exchange email servers. Microsoft took about six weeks to release...

Entra ID & IdentityIncident Teardowns

0ktapus and the Twilio Breach (Aug 2022): SMS Phishing Against 130+ Companies

In August 2022, researchers at Group-IB described a phishing campaign they named 0ktapus. It targeted employees of more than 130 organizations — many of...

Entra ID & IdentityHow-To & Hardening

How to Deploy FIDO2 Security Keys for High-Risk Users

FIDO2 security keys provide phishing-resistant MFA: they won't authenticate to a fake site. Here is how to deploy them in Entra ID for high-risk users.

Entra ID & IdentityDetection & Response

Detecting SMS Phishing Credential Harvesting: Entra Sign-In Logs and Sentinel KQL

SMS phishing campaigns like 0ktapus harvest credentials and MFA codes through fake sign-in pages. Detection focuses on the sign-ins that follow.

Entra ID & IdentityCIO Briefings

CIO Brief: The Case for Hardware Security Keys

The short version: In 2022, attackers sent text messages to employees at more than 130 companies, tricking them into entering passwords and MFA codes on...

Microsoft 365Incident Teardowns

Adversary-in-the-Middle Phishing Hits 10,000 Organizations (July 2022): MFA Bypassed at Scale

On July 12, 2022, Microsoft published research on a large-scale adversary-in-the-middle (AiTM) phishing campaign that had targeted more than 10,000...

Microsoft 365How-To & Hardening

How to Defeat AiTM Phishing With Compliant-Device and Phishing-Resistant MFA Policies

Adversary-in-the-middle phishing steals session cookies after users complete MFA. Two controls stop it: phishing-resistant authentication and...

Microsoft 365Detection & Response

Detecting AiTM Session Cookie Theft: Defender XDR and Sentinel Hunting Queries

AiTM phishing produces a valid session from an attacker's infrastructure. Detection focuses on session anomalies and the business email compromise that...

Microsoft 365CIO Briefings

CIO Brief: Why Standard MFA No Longer Stops Phishing

The short version: In 2022, Microsoft reported a phishing campaign that hit more than 10,000 organizations and got past multi-factor authentication by...

Microsoft 365Incident Teardowns

Follina (May–June 2022): Office Documents That Ran Code Without Macros

In late May 2022, researchers identified a malicious Word document that executed code without macros. The vulnerability it exploited, nicknamed Follina...

Microsoft 365How-To & Hardening

How to Configure Attack Surface Reduction Rules in Defender for Endpoint

Attack surface reduction (ASR) rules in Microsoft Defender for Endpoint block behaviors commonly used by malware — such as Office apps launching child...

Microsoft 365Detection & Response

Detecting Office Document Exploitation: Defender XDR and Sentinel Hunting Queries

Malicious Office documents remain a top initial access method. Detecting Office applications launching unusual processes catches many techniques, from...

Microsoft 365CIO Briefings

CIO Brief: Attackers Adapt When You Block Macros

The short version: For years, the main defense against malicious Office documents was blocking macros. In 2022, attackers used a new flaw, Follina, to run...

← NewerPage 8 of 20Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.