re:Invent 2018: AWS Security Hub and Control Tower Previews Change Multi-Account Security
At re:Invent in November 2018, AWS announced previews of two services that reshaped multi-account security: AWS Security Hub and AWS Control Tower.
Insights
News, breach teardowns, how-to guides, detections and CIO briefings for Microsoft 365, Entra ID, Azure, AWS and AI agents.
At re:Invent in November 2018, AWS announced previews of two services that reshaped multi-account security: AWS Security Hub and AWS Control Tower.
A multi-account AWS landing zone separates workloads, centralizes security tools and protects logs. Here is how to design one using AWS's own reference...
AWS Security Hub can produce hundreds of failed controls on day one. This checklist helps you triage them without drowning.
The short version: AWS recommends running your cloud as many separate accounts — one per application or environment — instead of one big account. In 2018,...
On November 19, 2018, Azure Active Directory's multi-factor authentication service suffered a major outage. For much of a working day, many users in Europe,...
Emergency access accounts — often called break-glass accounts — let you regain administrative access to Entra ID and Microsoft 365 when normal sign-in...
When your identity provider or MFA service fails, every minute of confusion costs productivity. This runbook outlines what to do.
The short version: In 2018, Microsoft's multi-factor authentication service had a major outage, and many organizations couldn't sign in to their email and...
On November 30, 2018, Marriott International announced that attackers had accessed the guest reservation database of its Starwood brands. The intrusion had...
When you acquire a company, you acquire its cloud environments, identities and possibly its attackers. Here is how to run a cloud security due diligence...
Marriott's attackers stayed inside Starwood's network for about four years. Long-dwell intruders are quiet by design. Hunting for them means looking for...
The short version: When Marriott bought Starwood in 2016, it also bought a hacker who had been inside Starwood's systems since 2014. The breach wasn't...
On September 28, 2018, Facebook announced that attackers had exploited a vulnerability in its "View As" feature to steal access tokens. Facebook initially...
Stolen tokens let attackers bypass passwords and MFA. Conditional Access session controls limit how long tokens stay useful and when users must...
Token theft lets an attacker act as a user without their password or MFA. Detection focuses on tokens being used in ways that don't match the device and...
The short version: In 2018, a Facebook bug let attackers steal the digital "keys" that keep users signed in, giving access to millions of accounts without...
At Microsoft Ignite in September 2018, Microsoft made identity and threat protection central themes. Two announcements stood out: passwordless sign-in for...
Passwordless sign-in removes the most attacked credential and improves user experience. Here is a practical rollout plan using Windows Hello for Business,...
Use this checklist to check whether your organization is ready to roll out passwordless sign-in.
The short version: In 2018, Microsoft started pushing businesses toward signing in without passwords, using phones, fingerprints and security keys instead....
On August 1, 2018, Reddit disclosed that an attacker had accessed some of its systems, including an old database backup with user data from 2007 and email...
SMS and voice codes are the weakest forms of MFA. Here is how to migrate Microsoft 365 users to the Microsoft Authenticator app and, for higher-risk users,...
SMS codes can be intercepted through SIM swaps and phishing. You often can't see the interception itself, but you can detect what happens next: a sign-in...
The short version: In 2018, Reddit was breached even though its employees used two-factor authentication — the attacker intercepted text message codes. All...