Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

AWS

Articles in AWS.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AWSIncident Teardowns

Thousands of Exposed AWS Access Keys Are Still Active (2026): Including Hundreds of Root Keys

Research reported by ITPro in 2026 found that more than 9,300 AWS access keys publicly exposed between August 2022 and August 2026 were still active and...

AWSHow-To & Hardening

How to Find, Disable and Replace Long-Lived AWS Access Keys

Thousands of exposed AWS access keys remain active years after leaking. Here is how to find, disable and replace long-lived keys in your accounts.

AWSIncident Teardowns

An AI-Assisted AWS Break-In in 8 Minutes (Feb 2026): From Public S3 Credentials to Admin

In early February 2026, researchers described an AWS intrusion in which an attacker went from stolen credentials to administrative privileges in under ten...

AWSHow-To & Hardening

How to Shrink Your AWS Blast Radius When Attackers Move at Machine Speed

AI-assisted attackers can escalate in AWS within minutes. Shrinking your blast radius — what any single credential can reach — matters more than ever. Here...

AWSIncident Teardowns

The $1.5B Bybit Theft (Feb 2025): A Developer Machine, Stolen AWS Session Tokens and a Poisoned S3 Asset

The $1.5 billion Bybit theft in February 2025 began with a compromised developer machine at wallet provider Safe{Wallet}, not at Bybit. Attackers altered the web interface Bybit's signers trusted. Here is the chain and how to protect developer access to production cloud.

AWSIncident Teardowns

Codefinger (Jan 2025): Ransomware That Encrypts S3 Buckets With AWS's Own SSE-C

In January 2025, the Codefinger campaign encrypted Amazon S3 data using AWS's own SSE-C feature and stolen keys — no malware involved. AWS has since disabled SSE-C by default for new buckets. Here is how it worked and how to make S3 data recoverable.

AWSDetection & Response

Detecting Leaked AWS Root Keys: CloudTrail, GuardDuty and Athena Queries

Leaked root keys give attackers unrestricted control of an AWS account. These detections focus on root key use and signs that exposed keys are being exploited.

AWSCIO Briefings

CIO Brief: Old Leaked Keys Are Still Open Doors

The short version: Research reported in 2026 found more than 9,300 AWS access keys that had leaked publicly over four years were still working — including...

AWSDetection & Response

Detecting Automated AWS Privilege Escalation: CloudTrail, GuardDuty and Athena Queries

When attackers move at machine speed, detection must focus on early, high-signal events and trigger automatic containment. These detections target fast...

AWSCIO Briefings

CIO Brief: Attackers Now Use AI — Your Detection Window Is Minutes

The short version: In February 2026, researchers described an attacker who went from finding a forgotten password in cloud storage to full administrator...

AWSIncident Teardowns

The AWS us-east-1 Outage of October 2025: DNS, DynamoDB and a Day of Downtime

On October 20, 2025, AWS's US-EAST-1 region suffered a major outage that disrupted a wide range of services — from banking and gaming apps to smart home...

AWSHow-To & Hardening

How to Reduce Your Dependence on a Single AWS Region's Control Plane

Many AWS workloads depend on US-EAST-1 more than their owners realize. Here is how to reduce dependence on a single region's control plane.

AWSHow-To & Hardening

Region Failure Readiness Checklist for AWS Workloads

Use this checklist to check whether an AWS workload is ready for a regional failure.

AWSCIO Briefings

CIO Brief: Cloud Concentration Risk Is Back on the Board Agenda

The short version: On October 20, 2025, an AWS outage in its busiest region disrupted banks, airlines, games and smart home devices for most of a day. It...

AWSHow-To & Hardening

How to Protect Developer Workstations and Short-Lived AWS Sessions

The Bybit theft began with a compromised developer machine and stolen AWS session tokens. Here is how to protect developer workstations and limit the value...

AWSDetection & Response

Detecting AWS Session Token Hijacking: CloudTrail, GuardDuty and Athena Queries

Stolen AWS session tokens let attackers act as a legitimate user without signing in. Detection focuses on where and how sessions are used.

AWSCIO Briefings

CIO Brief: Developers Are Privileged Users

The short version: In 2025, North Korean hackers stole about $1.5 billion from crypto exchange Bybit. They didn't attack Bybit directly — they hacked a...

AWSHow-To & Hardening

How to Block SSE-C Usage and Protect S3 With Versioning and Object Lock

Codefinger ransomware encrypted S3 objects with SSE-C keys only the attacker held. Here is how to block SSE-C and make your S3 data recoverable.

AWSDetection & Response

Detecting S3 Ransomware SSE-C: CloudTrail, GuardDuty and Athena Queries

Cloud-native ransomware like Codefinger leaves clear traces in CloudTrail — if you're logging S3 data events and watching for them.

AWSCIO Briefings

CIO Brief: Cloud-Native Ransomware Doesn't Need Malware

The short version: In early 2025, attackers used stolen AWS keys to lock companies' cloud storage files with encryption keys only the attackers had — using...

AWSPlatform Changes

AWS Centralized Root Access Management (Nov 2024): Removing Root Credentials From Member Accounts

In November 2024, AWS launched centralized root access management for AWS Organizations. It lets security teams remove root user credentials from member...

AWSHow-To & Hardening

How to Remove Root User Credentials Across an AWS Organization

AWS centralized root access management lets you delete root credentials in member accounts. Here is how to enable it and lock down root across your...

AWSHow-To & Hardening

AWS Root User Lockdown Checklist

Use this checklist to lock down the AWS root user across your organization.

AWSCIO Briefings

CIO Brief: The Most Powerful AWS Credential — and How to Retire It

The short version: Every AWS account has a "root" login with unlimited power. Companies with many AWS accounts had many of these super-passwords to protect....

Page 1 of 5Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.