Copilot Oversharing Remediation Checklist
Use this checklist to remediate oversharing before and during Copilot rollout.
Insights
News, breach teardowns, how-to guides, detections and CIO briefings for Microsoft 365, Entra ID, Azure, AWS and AI agents.
Use this checklist to remediate oversharing before and during Copilot rollout.
The short version: In September 2024, Microsoft expanded Copilot with new features — and new tools to fix the "oversharing" problem that stalled many...
In August 2024, researchers at Palo Alto Networks' Unit 42 described an extortion campaign that started with publicly exposed environment (.env) files on...
Exposed .env files led to an AWS extortion campaign in 2024. Here is how to keep secrets out of web-accessible locations and move them into AWS Secrets Manager.
Credential theft from exposed configuration files leads to predictable AWS activity. These detections target the patterns seen in .env-based extortion...
The short version: In 2024, attackers scanned the internet for websites accidentally publishing their configuration files — which contained cloud passwords...
The CrowdStrike outage showed how hard recovery is when thousands of BitLocker-encrypted devices won't boot. Here is how to prepare for recovering Azure VMs...
Security agents and other kernel-level software can take down entire fleets. Use this checklist to manage the risk of endpoint agent updates.
The short version: On July 19, 2024, a faulty update to CrowdStrike's security software crashed about 8.5 million Windows computers worldwide. Airlines,...
The Snowflake customer breaches happened because SaaS data platforms were accessed with stolen passwords and no MFA. Here is how to enforce SSO and MFA...
Infostealer-sourced credentials are used against SaaS platforms in automated campaigns. These detections help catch SaaS account takeover and data theft.
The short version: In 2024, attackers stole data from about 165 companies' accounts on Snowflake, a cloud data platform — including Ticketmaster and AT&T....
Passkeys in Microsoft Authenticator give users phishing-resistant MFA on their phones. Here is how to roll them out in Entra ID.
Use this checklist to roll out passkeys across your organization.
The short version: Since 2024, Microsoft lets employees use passkeys on their phones to sign in — the strongest common form of authentication, and immune to...
On April 2, 2024, the US Cyber Safety Review Board (CSRB) published its report on the Storm-0558 intrusion, in which Chinese state actors used a stolen...
Cloud provider security failures can affect your data — but your contract often gives you little recourse. Here are security terms to negotiate or verify...
Use this checklist to review each major cloud provider's security each year.
The short version: In April 2024, a US government review board concluded that a Chinese hack of Microsoft's email systems "should never have happened" and...
On March 29, 2024, Microsoft engineer Andres Freund disclosed that he had found a backdoor in XZ Utils, a compression library included in many Linux...
When a compromised package like XZ Utils is discovered, you need to know quickly whether it's in your cloud images and containers. Here is how to scan...
Compromised open-source packages are hard to detect by behavior — they're designed to look legitimate. Detection relies on inventory, threat intelligence...
The short version: In 2024, a hidden backdoor was discovered in XZ Utils, a small but widely used piece of free software in Linux systems. Someone had spent...
Change Healthcare and Colonial Pipeline were both breached through remote access without MFA. Here is how to enforce MFA on every remote access portal.