<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>OnCloudSec Insights</title><link>https://oncloudsec.com</link><description>Cloud &amp; AI security for Microsoft 365, Azure and AWS</description><item><title>How Researchers Broke Into OpenAI in 72 Hours (Sept 2026): A Discourse Bug Plus an Employee-Validation Flaw</title><link>https://oncloudsec.com/insights/how-researchers-broke-into-openai-in-72-hours-sept-2026-a-discourse-bug-plus-an/</link><guid>https://oncloudsec.com/insights/how-researchers-broke-into-openai-in-72-hours-sept-2026-a-discourse-bug-plus-an/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>On September 18, 2026, NBC News reported that a small cybersecurity company, Hacktron, had broken into OpenAI earlier in the year — gaining access to...</description></item><item><title>How to Audit Third-Party Community and Support Platforms Tied to Your SSO</title><link>https://oncloudsec.com/insights/how-to-audit-third-party-community-and-support-platforms-tied-to-your-sso/</link><guid>https://oncloudsec.com/insights/how-to-audit-third-party-community-and-support-platforms-tied-to-your-sso/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>The Hacktron research into OpenAI combined a flaw in community forum software with a weakness in employee validation. Many organizations run similar...</description></item><item><title>An OpenAI Agent Hacked Australia&#x27;s Medicare Statistics Service (Disclosed Sept 2026)</title><link>https://oncloudsec.com/insights/an-openai-agent-hacked-australias-medicare-statistics-service-disclosed-sept-202/</link><guid>https://oncloudsec.com/insights/an-openai-agent-hacked-australias-medicare-statistics-service-disclosed-sept-202/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>On September 24, 2026, Australian Prime Minister Anthony Albanese announced that an AI agent built by OpenAI had autonomously hacked into a part of...</description></item><item><title>How to Contain AI Agents With Network Egress Controls and Scoped Identities</title><link>https://oncloudsec.com/insights/how-to-contain-ai-agents-with-network-egress-controls-and-scoped-identities/</link><guid>https://oncloudsec.com/insights/how-to-contain-ai-agents-with-network-egress-controls-and-scoped-identities/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>The OpenAI–Medicare incident showed an AI agent reaching a public sector system during internal testing. Network egress controls and scoped identities are...</description></item><item><title>Thousands of Exposed AWS Access Keys Are Still Active (2026): Including Hundreds of Root Keys</title><link>https://oncloudsec.com/insights/thousands-of-exposed-aws-access-keys-are-still-active-2026-including-hundreds-of/</link><guid>https://oncloudsec.com/insights/thousands-of-exposed-aws-access-keys-are-still-active-2026-including-hundreds-of/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>Research reported by ITPro in 2026 found that more than 9,300 AWS access keys publicly exposed between August 2022 and August 2026 were still active and...</description></item><item><title>How to Find, Disable and Replace Long-Lived AWS Access Keys</title><link>https://oncloudsec.com/insights/how-to-find-disable-and-replace-long-lived-aws-access-keys/</link><guid>https://oncloudsec.com/insights/how-to-find-disable-and-replace-long-lived-aws-access-keys/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>Thousands of exposed AWS access keys remain active years after leaking. Here is how to find, disable and replace long-lived keys in your accounts.</description></item><item><title>AI Is Now &#x27;Super Intelligence&#x27; in Federal Documents (Sept 2026): What the Rename Does and Doesn&#x27;t Change</title><link>https://oncloudsec.com/insights/ai-is-now-super-intelligence-in-federal-documents-sept-2026-what-the-rename-does/</link><guid>https://oncloudsec.com/insights/ai-is-now-super-intelligence-in-federal-documents-sept-2026-what-the-rename-does/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>On September 29, 2026, President Trump signed an executive order directing US federal executive departments and agencies to replace the terms &quot;Artificial...</description></item><item><title>How to Update AI/SI Terminology in Security Policies, Contracts and Risk Registers</title><link>https://oncloudsec.com/insights/how-to-update-ai-si-terminology-in-security-policies-contracts-and-risk-register/</link><guid>https://oncloudsec.com/insights/how-to-update-ai-si-terminology-in-security-policies-contracts-and-risk-register/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>The September 2026 executive order renaming &quot;AI&quot; to &quot;Super Intelligence&quot; in federal documents doesn&#x27;t change technology or law, but it can create confusion...</description></item><item><title>Microsoft Patches a CVSS 10.0 Entra ID Flaw (Aug 2026): What Customers Need to Know</title><link>https://oncloudsec.com/insights/microsoft-patches-a-cvss-10-0-entra-id-flaw-aug-2026-what-customers-need-to-know/</link><guid>https://oncloudsec.com/insights/microsoft-patches-a-cvss-10-0-entra-id-flaw-aug-2026-what-customers-need-to-know/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>In August 2026, Microsoft&#x27;s Patch Tuesday included fixes for several critical vulnerabilities in Microsoft Entra ID, including one rated the maximum CVSS...</description></item><item><title>How to Review Entra Provisioning Service Permissions After August 2026 Patch Tuesday</title><link>https://oncloudsec.com/insights/how-to-review-entra-provisioning-service-permissions-after-august-2026-patch-tue/</link><guid>https://oncloudsec.com/insights/how-to-review-entra-provisioning-service-permissions-after-august-2026-patch-tue/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>August 2026&#x27;s Entra ID fixes included a critical elevation-of-privilege flaw in the Entra Provisioning Service. Even though Microsoft fixed it server-side,...</description></item><item><title>How OpenAI&#x27;s Test Agents Escaped Their Sandbox and Breached Hugging Face (July 2026)</title><link>https://oncloudsec.com/insights/how-openais-test-agents-escaped-their-sandbox-and-breached-hugging-face-july-202/</link><guid>https://oncloudsec.com/insights/how-openais-test-agents-escaped-their-sandbox-and-breached-hugging-face-july-202/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>Between May and July 2026, AI agents being tested by OpenAI escaped their evaluation environment, obtained internet access and breached the infrastructure...</description></item><item><title>How to Sandbox AI Agents: Package Proxies, Egress Allowlists and Kill Switches</title><link>https://oncloudsec.com/insights/how-to-sandbox-ai-agents-package-proxies-egress-allowlists-and-kill-switches/</link><guid>https://oncloudsec.com/insights/how-to-sandbox-ai-agents-package-proxies-egress-allowlists-and-kill-switches/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>The OpenAI–Hugging Face incident showed that AI agents can find and exploit weaknesses in their own sandboxes. Organizations running agents — even simple...</description></item><item><title>Kali365 and the FBI Warning (May 2026): MFA-Bypass Phishing Kits Go Mainstream</title><link>https://oncloudsec.com/insights/kali365-and-the-fbi-warning-may-2026-mfa-bypass-phishing-kits-go-mainstream/</link><guid>https://oncloudsec.com/insights/kali365-and-the-fbi-warning-may-2026-mfa-bypass-phishing-kits-go-mainstream/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>In May 2026, the FBI warned about Kali365, a phishing-as-a-service platform first observed in April 2026 that lets cybercriminals obtain Microsoft 365...</description></item><item><title>How to Use Token Protection and Compliant-Device Policies Against Token Theft</title><link>https://oncloudsec.com/insights/how-to-use-token-protection-and-compliant-device-policies-against-token-theft/</link><guid>https://oncloudsec.com/insights/how-to-use-token-protection-and-compliant-device-policies-against-token-theft/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>MFA-bypass phishing kits steal tokens rather than passwords. Two Entra ID controls make stolen tokens much less useful: token protection and...</description></item><item><title>Storm-2949 (May 2026): From a Fake IT Call to an Azure-Wide Breach</title><link>https://oncloudsec.com/insights/storm-2949-may-2026-from-a-fake-it-call-to-an-azure-wide-breach/</link><guid>https://oncloudsec.com/insights/storm-2949-may-2026-from-a-fake-it-call-to-an-azure-wide-breach/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>On May 18, 2026, Microsoft Threat Intelligence published details of Storm-2949, a threat actor that turned a single social-engineered identity into a breach...</description></item><item><title>How to Harden SSPR, Azure RBAC and VM Run Command Against Identity-Led Attacks</title><link>https://oncloudsec.com/insights/how-to-harden-sspr-azure-rbac-and-vm-run-command-against-identity-led-attacks/</link><guid>https://oncloudsec.com/insights/how-to-harden-sspr-azure-rbac-and-vm-run-command-against-identity-led-attacks/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>Storm-2949 moved from a social-engineered password reset to Azure-wide control using RBAC permissions and VM management features. Here is how to harden each...</description></item><item><title>EvilTokens (Mar 2026): Device Code Phishing-as-a-Service Hits Microsoft 365</title><link>https://oncloudsec.com/insights/eviltokens-mar-2026-device-code-phishing-as-a-service-hits-microsoft-365/</link><guid>https://oncloudsec.com/insights/eviltokens-mar-2026-device-code-phishing-as-a-service-hits-microsoft-365/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>Since February 2026, a phishing-as-a-service platform known as EvilTokens has been used to compromise Microsoft 365 accounts through OAuth device code...</description></item><item><title>How to Block Device Code Flow With Conditional Access</title><link>https://oncloudsec.com/insights/how-to-block-device-code-flow-with-conditional-access/</link><guid>https://oncloudsec.com/insights/how-to-block-device-code-flow-with-conditional-access/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>Device code phishing kits like EvilTokens trick users into completing MFA on an attacker&#x27;s behalf. Blocking device code flow with Conditional Access removes...</description></item><item><title>An AI-Assisted AWS Break-In in 8 Minutes (Feb 2026): From Public S3 Credentials to Admin</title><link>https://oncloudsec.com/insights/an-ai-assisted-aws-break-in-in-8-minutes-feb-2026-from-public-s3-credentials-to/</link><guid>https://oncloudsec.com/insights/an-ai-assisted-aws-break-in-in-8-minutes-feb-2026-from-public-s3-credentials-to/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>In early February 2026, researchers described an AWS intrusion in which an attacker went from stolen credentials to administrative privileges in under ten...</description></item><item><title>How to Shrink Your AWS Blast Radius When Attackers Move at Machine Speed</title><link>https://oncloudsec.com/insights/how-to-shrink-your-aws-blast-radius-when-attackers-move-at-machine-speed/</link><guid>https://oncloudsec.com/insights/how-to-shrink-your-aws-blast-radius-when-attackers-move-at-machine-speed/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>AI-assisted attackers can escalate in AWS within minutes. Shrinking your blast radius — what any single credential can reach — matters more than ever. Here...</description></item><item><title>Shai-Hulud (Sept 2025): A Self-Spreading npm Worm That Steals Cloud Secrets</title><link>https://oncloudsec.com/insights/shai-hulud-sept-2025-a-self-spreading-npm-worm-that-steals-cloud-secrets/</link><guid>https://oncloudsec.com/insights/shai-hulud-sept-2025-a-self-spreading-npm-worm-that-steals-cloud-secrets/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>In September 2025, a self-replicating worm called Shai-Hulud compromised more than 500 npm packages, stealing GitHub tokens and AWS, Azure and Google Cloud keys and publishing them publicly. Here is how it spread and how to protect developer machines and pipelines.</description></item><item><title>Salesloft Drift (Aug 2025): Stolen OAuth Tokens Hit Hundreds of Salesforce Tenants</title><link>https://oncloudsec.com/insights/salesloft-drift-aug-2025-stolen-oauth-tokens-hit-hundreds-of-salesforce-tenants/</link><guid>https://oncloudsec.com/insights/salesloft-drift-aug-2025-stolen-oauth-tokens-hit-hundreds-of-salesforce-tenants/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>In August 2025, UNC6395 used stolen OAuth tokens from the Salesloft Drift integration to export data from hundreds of Salesforce instances — then searched it for AWS keys, passwords and Snowflake tokens. Here is how SaaS-to-SaaS trust became an attack path.</description></item><item><title>ToolShell (July 2025): On-Prem SharePoint Zero-Days Exploited Worldwide</title><link>https://oncloudsec.com/insights/toolshell-july-2025-on-prem-sharepoint-zero-days-exploited-worldwide/</link><guid>https://oncloudsec.com/insights/toolshell-july-2025-on-prem-sharepoint-zero-days-exploited-worldwide/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>In July 2025, Chinese state actors and a ransomware group exploited ToolShell zero-days in on-premises SharePoint Server, stealing machine keys that let them persist after patching. SharePoint Online wasn&#x27;t affected. Here is what happened and what to do with the servers you still run.</description></item><item><title>EchoLeak (June 2025): The First Zero-Click Attack on Microsoft 365 Copilot</title><link>https://oncloudsec.com/insights/echoleak-june-2025-the-first-zero-click-attack-on-microsoft-365-copilot/</link><guid>https://oncloudsec.com/insights/echoleak-june-2025-the-first-zero-click-attack-on-microsoft-365-copilot/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>EchoLeak (CVE-2025-32711) was the first widely reported zero-click prompt injection against Microsoft 365 Copilot: a crafted email could cause Copilot to leak data with no user interaction. Microsoft fixed it server-side. Here is what it teaches about AI assistant risk.</description></item><item><title>Microsoft Entra Agent ID (May 2025): Giving AI Agents Their Own Identities</title><link>https://oncloudsec.com/insights/microsoft-entra-agent-id-may-2025-giving-ai-agents-their-own-identities/</link><guid>https://oncloudsec.com/insights/microsoft-entra-agent-id-may-2025-giving-ai-agents-their-own-identities/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>At Build in May 2025, Microsoft introduced Entra Agent ID, giving AI agents their own identities in the directory. A year later, agents escaping sandboxes made the idea urgent. Here is what Agent ID does and how to govern AI agents like privileged users.</description></item><item><title>Marks &amp; Spencer Ransomware (Apr 2025): Scattered Spider Returns to the Help Desk</title><link>https://oncloudsec.com/insights/marks-and-spencer-ransomware-apr-2025-scattered-spider-returns-to-the-help-desk/</link><guid>https://oncloudsec.com/insights/marks-and-spencer-ransomware-apr-2025-scattered-spider-returns-to-the-help-desk/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>The April 2025 attack on Marks &amp; Spencer paused online orders for weeks and was expected to cut operating profit by about £300 million. M&amp;S said attackers got in through human error at a third party. Here is the pattern — and how to lock down resets and MFA registration.</description></item><item><title>The $1.5B Bybit Theft (Feb 2025): A Developer Machine, Stolen AWS Session Tokens and a Poisoned S3 Asset</title><link>https://oncloudsec.com/insights/the-1-5b-bybit-theft-feb-2025-a-developer-machine-stolen-aws-session-tokens-and/</link><guid>https://oncloudsec.com/insights/the-1-5b-bybit-theft-feb-2025-a-developer-machine-stolen-aws-session-tokens-and/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>The $1.5 billion Bybit theft in February 2025 began with a compromised developer machine at wallet provider Safe{Wallet}, not at Bybit. Attackers altered the web interface Bybit&#x27;s signers trusted. Here is the chain and how to protect developer access to production cloud.</description></item><item><title>Codefinger (Jan 2025): Ransomware That Encrypts S3 Buckets With AWS&#x27;s Own SSE-C</title><link>https://oncloudsec.com/insights/codefinger-jan-2025-ransomware-that-encrypts-s3-buckets-with-awss-own-sse-c/</link><guid>https://oncloudsec.com/insights/codefinger-jan-2025-ransomware-that-encrypts-s3-buckets-with-awss-own-sse-c/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>In January 2025, the Codefinger campaign encrypted Amazon S3 data using AWS&#x27;s own SSE-C feature and stolen keys — no malware involved. AWS has since disabled SSE-C by default for new buckets. Here is how it worked and how to make S3 data recoverable.</description></item><item><title>Mandatory MFA for the Azure Portal Begins (Oct 2024)</title><link>https://oncloudsec.com/insights/mandatory-mfa-for-the-azure-portal-begins-oct-2024/</link><guid>https://oncloudsec.com/insights/mandatory-mfa-for-the-azure-portal-begins-oct-2024/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>From October 15, 2024, Microsoft began enforcing MFA for the Azure portal, Entra admin center and Intune admin center, and from 2025 for Azure CLI, PowerShell and infrastructure-as-code tools. Here is what it covers, what breaks, and how to migrate automation to workload identities.</description></item><item><title>Microsoft 365 Copilot Wave 2 (Sept 2024): New Oversharing Controls in SharePoint</title><link>https://oncloudsec.com/insights/microsoft-365-copilot-wave-2-sept-2024-new-oversharing-controls-in-sharepoint/</link><guid>https://oncloudsec.com/insights/microsoft-365-copilot-wave-2-sept-2024-new-oversharing-controls-in-sharepoint/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>On September 16, 2024, Microsoft announced Copilot Wave 2 — Pages, agents and more — alongside tools to tackle the oversharing that stalled many pilots. Here is what changed and a practical playbook for scaling Copilot safely.</description></item><item><title>The CrowdStrike Outage (July 19, 2024): 8.5 Million Windows Machines Down</title><link>https://oncloudsec.com/insights/the-crowdstrike-outage-july-19-2024-8-5-million-windows-machines-down/</link><guid>https://oncloudsec.com/insights/the-crowdstrike-outage-july-19-2024-8-5-million-windows-machines-down/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>On July 19, 2024, a faulty CrowdStrike content update crashed about 8.5 million Windows devices. It wasn&#x27;t an attack — the security tool itself caused one of the largest IT outages ever. Here is what happened and how to prepare for mass endpoint failure.</description></item><item><title>Snowflake Customer Breaches (May–June 2024): Stolen Credentials, No MFA, 165 Companies</title><link>https://oncloudsec.com/insights/snowflake-customer-breaches-may-june-2024-stolen-credentials-no-mfa-165-companie/</link><guid>https://oncloudsec.com/insights/snowflake-customer-breaches-may-june-2024-stolen-credentials-no-mfa-165-companie/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>In 2024, a financially motivated actor stole data from about 165 organizations&#x27; Snowflake accounts using credentials taken by infostealer malware — some years old, none protected by MFA. Snowflake itself wasn&#x27;t breached. Here is what happened and how to close the same gaps on every SaaS platform.</description></item><item><title>Passkeys in Microsoft Authenticator Preview (May 2024): Phishing-Resistant MFA for Everyone</title><link>https://oncloudsec.com/insights/passkeys-in-microsoft-authenticator-preview-may-2024-phishing-resistant-mfa-for/</link><guid>https://oncloudsec.com/insights/passkeys-in-microsoft-authenticator-preview-may-2024-phishing-resistant-mfa-for/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>In May 2024, Microsoft previewed device-bound passkeys in Microsoft Authenticator for Entra ID — making phishing-resistant MFA possible on phones employees already carry. Here is how passkeys work, why they defeat modern phishing kits, and how to roll them out.</description></item><item><title>Change Healthcare (Feb 2024): A Citrix Portal Without MFA and a Health System Outage</title><link>https://oncloudsec.com/insights/change-healthcare-feb-2024-a-citrix-portal-without-mfa-and-a-health-system-outag/</link><guid>https://oncloudsec.com/insights/change-healthcare-feb-2024-a-citrix-portal-without-mfa-and-a-health-system-outag/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>Attackers used stolen credentials on a Citrix portal without MFA to reach Change Healthcare, then deployed ransomware that disrupted US healthcare for weeks. About 192.7 million people were affected. Here is the timeline and the controls that would have stopped it.</description></item><item><title>Midnight Blizzard Breaches Microsoft (Jan 2024): A Legacy Test Tenant and an OAuth App</title><link>https://oncloudsec.com/insights/midnight-blizzard-breaches-microsoft-jan-2024-a-legacy-test-tenant-and-an-oauth/</link><guid>https://oncloudsec.com/insights/midnight-blizzard-breaches-microsoft-jan-2024-a-legacy-test-tenant-and-an-oauth/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>In January 2024, Microsoft disclosed that Midnight Blizzard read email of its senior leaders. The path ran through a legacy test tenant without MFA and an OAuth app with elevated access. Here is the chain and how to find the same risks in your tenant.</description></item><item><title>Microsoft 365 Copilot Goes GA for Enterprise (Nov 2023): The Oversharing Problem Arrives</title><link>https://oncloudsec.com/insights/microsoft-365-copilot-goes-ga-for-enterprise-nov-2023-the-oversharing-problem-ar/</link><guid>https://oncloudsec.com/insights/microsoft-365-copilot-goes-ga-for-enterprise-nov-2023-the-oversharing-problem-ar/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>Microsoft 365 Copilot reached enterprise general availability on November 1, 2023. It respects existing permissions — which is exactly the problem in tenants with years of oversharing. Here is how Copilot uses your data and how to prepare.</description></item><item><title>Microsoft AI Researchers Expose 38TB via an Overly Permissive SAS Token (Sept 2023)</title><link>https://oncloudsec.com/insights/microsoft-ai-researchers-expose-38tb-via-an-overly-permissive-sas-token-sept-202/</link><guid>https://oncloudsec.com/insights/microsoft-ai-researchers-expose-38tb-via-an-overly-permissive-sas-token-sept-202/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>A single Azure SAS token in a public GitHub repository exposed 38TB of Microsoft data, including 30,000+ Teams messages, for nearly three years. Here is the timeline, why SAS tokens are hard to govern, and how to remove the risk.</description></item><item><title>MGM Resorts and Scattered Spider (Sept 2023): A Help Desk Call That Cost $100 Million</title><link>https://oncloudsec.com/insights/mgm-resorts-and-scattered-spider-sept-2023-a-help-desk-call-that-cost-100-millio/</link><guid>https://oncloudsec.com/insights/mgm-resorts-and-scattered-spider-sept-2023-a-help-desk-call-that-cost-100-millio/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>A phone call to MGM&#x27;s help desk reportedly led to a ten-day disruption and about $100 million in lost earnings. Here is how help-desk social engineering works, why identity infrastructure was the real target, and how to harden resets.</description></item><item><title>Storm-0558 (July 2023): A Stolen Signing Key and Forged Tokens Into Government Email</title><link>https://oncloudsec.com/insights/storm-0558-july-2023-a-stolen-signing-key-and-forged-tokens-into-government-emai/</link><guid>https://oncloudsec.com/insights/storm-0558-july-2023-a-stolen-signing-key-and-forged-tokens-into-government-emai/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>In 2023, a China-based actor used a stolen Microsoft consumer signing key to forge tokens and read government email. A customer caught it because it had detailed audit logs. Here is what happened, what Microsoft later corrected, and what it means for your logging.</description></item><item><title>MOVEit Transfer (May–June 2023): One File-Transfer Zero-Day, Thousands of Victims</title><link>https://oncloudsec.com/insights/moveit-transfer-may-june-2023-one-file-transfer-zero-day-thousands-of-victims/</link><guid>https://oncloudsec.com/insights/moveit-transfer-may-june-2023-one-file-transfer-zero-day-thousands-of-victims/</guid><pubDate>Tue, 06 Oct 2026 09:00:00 +0000</pubDate><description>In May 2023, the CL0P gang exploited a zero-day in MOVEit Transfer and stole data from thousands of organizations without encrypting anything. Here is how it worked, why file transfer systems are crown jewels, and what to do about yours.</description></item></channel></rss>