CircleCI Secrets Breach (Jan 2023): Rotate Everything
On January 4, 2023, CircleCI, a widely used continuous integration and delivery platform, told customers to rotate all secrets stored in its platform...
Insights
News, breach teardowns, how-to guides, detections and CIO briefings for Microsoft 365, Entra ID, Azure, AWS and AI agents.
On January 4, 2023, CircleCI, a widely used continuous integration and delivery platform, told customers to rotate all secrets stored in its platform...
When a provider tells you to rotate everything, the hardest part is knowing what "everything" is. A rotation fire drill — practiced in advance — makes it...
After a CI/CD provider breach, attackers use stolen secrets to access your cloud. Detecting that use — and use of secrets after rotation — tells you whether...
The short version: In January 2023, CircleCI — a service many companies use to build and deploy software — told every customer to change every password and...
In August 2022, password manager LastPass disclosed that an attacker had accessed its development environment. In December 2022, it revealed that the...
In the LastPass breach, attackers stole backups from cloud storage using credentials taken from an engineer's home computer. Backups need their own...
Attackers increasingly target backups — to steal data or to delete it before ransomware. These detections watch for unusual backup access and changes.
The short version: In 2022, attackers stole encrypted copies of LastPass customers' password vaults by hacking an engineer's home computer and using it to...
At AWS re:Invent in November 2022, AWS announced previews of Amazon Security Lake and AWS Verified Access, alongside other security updates.
Amazon Security Lake centralizes and normalizes security logs from AWS and other sources into OCSF format in your own S3 buckets. Here is how to set it up.
Use this checklist to plan which data goes into Amazon Security Lake and how long you keep it.
The short version: In 2022, AWS introduced Security Lake, which stores your security logs in your own cloud account, in a standard format any security tool...
Beginning October 1, 2022, Microsoft started permanently disabling Basic Authentication in Exchange Online for Exchange ActiveSync, POP, IMAP, Remote...
Microsoft retired Basic Authentication for most Exchange Online protocols in 2022, but legacy authentication can still appear through SMTP AUTH, other...
After Basic Authentication was turned off in Exchange Online, many organizations found lingering dependencies. Use this checklist to clean up.
The short version: In October 2022, Microsoft permanently turned off older sign-in methods for its cloud email after a three-year warning. Some printers,...
In October 2022, threat intelligence company SOCRadar reported a data leak it called BlueBleed: a misconfigured Microsoft-owned Azure Blob Storage container...
Azure Storage accounts can be exposed through anonymous blob access, overly permissive shared keys and SAS tokens, or public network endpoints. Here is how...
Public Azure Blob access is often discovered by outsiders scanning for open containers. Detecting both the configuration and anonymous access helps you find...
The short version: In 2022, researchers reported that a misconfigured Microsoft storage location exposed business documents involving Microsoft's customers....
On September 15, 2022, Uber disclosed a network security incident. An attacker had gained access to internal systems including its Slack workspace, cloud...
Contractors and guests often have less oversight than employees but similar access. Conditional Access lets you apply consistent — or stricter — controls....
MFA push bombing generates bursts of MFA requests. Even with number matching, attackers try variations. These detections help catch attempts early.
The short version: In 2022, Uber was breached through a contractor whose password had been stolen and who eventually approved one of many login prompts....