Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

AWS

Articles in AWS.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AWSIncident Teardowns

Exposed .env Files Fuel an AWS Extortion Campaign (Aug 2024)

In August 2024, researchers at Palo Alto Networks' Unit 42 described an extortion campaign that started with publicly exposed environment (.env) files on...

AWSHow-To & Hardening

How to Keep Secrets Out of Web Roots and Into AWS Secrets Manager

Exposed .env files led to an AWS extortion campaign in 2024. Here is how to keep secrets out of web-accessible locations and move them into AWS Secrets Manager.

AWSDetection & Response

Detecting Exposed Environment Variables: CloudTrail, GuardDuty and Athena Queries

Credential theft from exposed configuration files leads to predictable AWS activity. These detections target the patterns seen in .env-based extortion...

AWSCIO Briefings

CIO Brief: Leaked Configuration Files Are Leaked Keys

The short version: In 2024, attackers scanned the internet for websites accidentally publishing their configuration files — which contained cloud passwords...

AWSPlatform Changes

S3 Block Public Access and ACLs Disabled by Default for New Buckets (Apr 2023)

In April 2023, AWS changed the default settings for all new S3 buckets: S3 Block Public Access is enabled, and access control lists (ACLs) are disabled...

AWSHow-To & Hardening

How to Migrate Legacy S3 Buckets Off ACLs to Bucket Owner Enforced

New S3 buckets have ACLs disabled by default, but older buckets may still rely on them. Migrating to "Bucket owner enforced" simplifies access control. Here...

AWSHow-To & Hardening

S3 Object Ownership and ACL Cleanup Checklist

Use this checklist to clean up legacy S3 ACLs and ownership settings.

AWSCIO Briefings

CIO Brief: Secure Defaults Help — But Only for New Resources

The short version: In April 2023, AWS changed the defaults so new cloud storage buckets are private and simpler to secure. That's a big improvement — but it...

AWSPlatform Changes

AWS Encrypts All New S3 Objects by Default (Jan 2023)

On January 5, 2023, AWS began automatically applying server-side encryption with Amazon S3 managed keys (SSE-S3) to all new objects uploaded to S3, at no...

AWSHow-To & Hardening

How to Choose Between SSE-S3, SSE-KMS and DSSE-KMS for S3

All new S3 objects are encrypted by default with SSE-S3. For sensitive data, you may want more control. Here is how to choose between SSE-S3, SSE-KMS and...

AWSHow-To & Hardening

S3 Encryption and KMS Key Policy Audit Checklist

KMS key policies decide who can decrypt your sensitive S3 data. Use this checklist to audit encryption and key policies.

AWSCIO Briefings

CIO Brief: Encryption by Default — What It Does and Doesn't Protect

The short version: Since January 2023, AWS automatically encrypts all new files stored in S3. That's good — but encryption by default doesn't stop someone...

AWSPlatform Changes

re:Invent 2022: Amazon Security Lake and Verified Access Previews

At AWS re:Invent in November 2022, AWS announced previews of Amazon Security Lake and AWS Verified Access, alongside other security updates.

AWSHow-To & Hardening

How to Centralize AWS Security Logs With Amazon Security Lake

Amazon Security Lake centralizes and normalizes security logs from AWS and other sources into OCSF format in your own S3 buckets. Here is how to set it up.

AWSHow-To & Hardening

Security Lake Source and Retention Planning Checklist

Use this checklist to plan which data goes into Amazon Security Lake and how long you keep it.

AWSCIO Briefings

CIO Brief: Owning Your Security Data — The OCSF Shift

The short version: In 2022, AWS introduced Security Lake, which stores your security logs in your own cloud account, in a standard format any security tool...

AWSIncident Teardowns

The AWS us-east-1 Outage of December 2021: When the Control Plane Fails

On December 7, 2021, AWS's US-EAST-1 region experienced a major disruption lasting much of the day. Services including Disney+, Netflix, Slack, Venmo,...

AWSHow-To & Hardening

How to Plan Multi-Region Failover for Critical AWS Workloads

Regional outages are rare but real. Here is how to plan multi-region failover for the AWS workloads that truly need it.

AWSHow-To & Hardening

Multi-Region Disaster Recovery Test Checklist

Use this checklist to plan and run a multi-region disaster recovery test for an AWS workload.

AWSCIO Briefings

CIO Brief: Concentration Risk in a Single Cloud Region

The short version: In December 2021, a problem in one AWS region disrupted major services like Netflix, Disney+ and Amazon's own deliveries for much of a...

AWSPlatform Changes

AWS Network Firewall Goes GA (Nov 2020): Managed Stateful Inspection for VPCs

In November 2020, AWS Network Firewall became generally available — a managed, stateful network firewall and intrusion prevention service for Amazon VPCs.

AWSHow-To & Hardening

How to Deploy AWS Network Firewall in a Centralized Inspection VPC

A centralized inspection VPC lets one AWS Network Firewall deployment filter traffic for many VPCs. Here is the common architecture and setup sequence.

AWSHow-To & Hardening

VPC Egress Filtering Checklist

Egress filtering is one of the most effective controls against data exfiltration and malware. Use this checklist to put it in place across AWS VPCs.

AWSCIO Briefings

CIO Brief: Network Security Still Matters in the Cloud

The short version: Cloud servers can usually connect to anywhere on the internet by default. Attackers rely on that to steal data and control compromised...

← NewerPage 2 of 5Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.