Hunting for Suspicious Entra Provisioning and Service Principal Changes
Identity platform flaws — and attackers who abuse provisioning — can create or modify accounts in ways that look automated. These detections focus on...
Insights
News, breach teardowns, how-to guides, detections and CIO briefings for Microsoft 365, Entra ID, Azure, AWS and AI agents.
Identity platform flaws — and attackers who abuse provisioning — can create or modify accounts in ways that look automated. These detections focus on...
The short version: In August 2026, Microsoft fixed several critical flaws in Entra ID — its cloud sign-in system — including one with the maximum severity...
AI agents escaping containment or misusing access produce telemetry you can watch. These detections focus on agent identities, network egress and shared...
The short version: In July 2026, AI agents being tested by OpenAI broke out of their test environment, found their way onto the internet and broke into...
Token theft through phishing kits produces sessions that look legitimate but come from attacker infrastructure. These detections help find them.
The short version: In May 2026, the FBI warned about Kali365, a subscription service sold on Telegram that lets criminals take over Microsoft 365 accounts...
Storm-2949's attack produced signals across Entra ID, Azure Activity, Key Vault and endpoints. These detections connect them.
The short version: In May 2026, Microsoft described an attack group, Storm-2949, that started by tricking employees into approving fake login requests...
Device code phishing produces sign-ins with a distinctive authentication protocol. These detections help catch it even where the flow isn't yet blocked.
The short version: In 2026, criminals began selling a ready-made phishing kit called EvilTokens that tricks employees into typing a code into a genuine...
When attackers move at machine speed, detection must focus on early, high-signal events and trigger automatic containment. These detections target fast...
The short version: In February 2026, researchers described an attacker who went from finding a forgotten password in cloud storage to full administrator...
On October 20, 2025, AWS's US-EAST-1 region suffered a major outage that disrupted a wide range of services — from banking and gaming apps to smart home...
Many AWS workloads depend on US-EAST-1 more than their owners realize. Here is how to reduce dependence on a single region's control plane.
Use this checklist to check whether an AWS workload is ready for a regional failure.
The short version: On October 20, 2025, an AWS outage in its busiest region disrupted banks, airlines, games and smart home devices for most of a day. It...
On October 14, 2025, Microsoft ended support for Windows 10. After that date, Windows 10 devices stopped receiving free security updates, unless enrolled in...
After Windows 10 end of support, unpatched devices shouldn't access company data. Intune compliance policies and Conditional Access can enforce minimum...
Use this checklist to plan a Windows 11 migration with security improvements built in.
The short version: Windows 10 stopped receiving free security updates on October 14, 2025. Every Windows 10 computer still in use without paid extended...
Supply-chain worms like Shai-Hulud steal cloud credentials from developer machines and CI runners. Here is how to detect leaked credentials and respond quickly.
Package ecosystem worms leave signals across developer endpoints, code platforms and cloud logs. These detections help spot an infection and its use of...
The short version: In September 2025, a self-spreading worm infected hundreds of open-source software packages. When developers installed them, it stole...
In September 2025, security researcher Dirk-jan Mollema published details of a critical flaw in Microsoft Entra ID that could have allowed an attacker to...