Detecting Cloud SSO Compromise: Entra Sign-In Logs and Sentinel KQL
When an SSO or identity provider is compromised, attackers may use stolen credentials or forged tokens to access connected applications. These detections...
Insights
News, breach teardowns, how-to guides, detections and CIO briefings for Microsoft 365, Entra ID, Azure, AWS and AI agents.
When an SSO or identity provider is compromised, attackers may use stolen credentials or forged tokens to access connected applications. These detections...
The short version: In 2025, a hacker claimed to have stolen login data from Oracle's cloud. Oracle denied it; researchers said the evidence looked real....
The Bybit theft began with a compromised developer machine and stolen AWS session tokens. Here is how to protect developer workstations and limit the value...
Stolen AWS session tokens let attackers act as a legitimate user without signing in. Detection focuses on where and how sessions are used.
The short version: In 2025, North Korean hackers stole about $1.5 billion from crypto exchange Bybit. They didn't attack Bybit directly — they hacked a...
Codefinger ransomware encrypted S3 objects with SSE-C keys only the attacker held. Here is how to block SSE-C and make your S3 data recoverable.
Cloud-native ransomware like Codefinger leaves clear traces in CloudTrail — if you're logging S3 data events and watching for them.
The short version: In early 2025, attackers used stolen AWS keys to lock companies' cloud storage files with encryption keys only the attackers had — using...
On December 30, 2024, the US Treasury Department told Congress that a China state-sponsored actor had accessed some Treasury workstations and unclassified...
API keys for remote support and management tools can provide direct access to your devices. Here is how to inventory them and rotate them safely.
Stolen API keys for remote support tools grant access without user sign-ins. These detections focus on unusual key use and remote sessions.
The short version: At the end of 2024, Chinese state hackers accessed US Treasury computers through BeyondTrust, a company whose software lets IT staff...
At Microsoft Ignite in November 2024, security announcements centered on resilience and exposure. Two stood out: the Windows Resiliency Initiative, a...
Not all vulnerabilities and misconfigurations matter equally. Attack path analysis shows which ones an attacker could chain to reach your critical assets....
Use this checklist to start an exposure management program with Microsoft Defender tools.
The short version: Security teams are drowning in alerts and vulnerability lists. In 2024, Microsoft and other vendors pushed a different approach:...
In November 2024, AWS launched centralized root access management for AWS Organizations. It lets security teams remove root user credentials from member...
AWS centralized root access management lets you delete root credentials in member accounts. Here is how to enable it and lock down root across your...
Use this checklist to lock down the AWS root user across your organization.
The short version: Every AWS account has a "root" login with unlimited power. Companies with many AWS accounts had many of these super-passwords to protect....
Microsoft's mandatory MFA for Azure breaks automation that signs in as a user with a password. Here is how to find and migrate those service accounts.
Use this checklist to confirm your organization is ready for Azure's mandatory MFA.
The short version: Since October 2024, Microsoft requires multi-factor authentication for anyone managing Azure through its web portals, and from 2025 also...
Restricted SharePoint Search and data access governance reports help you control Copilot exposure while you fix oversharing. Here is how to use them.