Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

AWS

Articles in AWS.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AWSPlatform Changes

S3 Block Public Access Launches (Nov 2018): The Feature That Should Have Existed Day One

In November 2018, AWS launched S3 Block Public Access, a set of four settings that override bucket policies and access control lists to prevent public...

AWSHow-To & Hardening

How to Enforce S3 Block Public Access at the AWS Organization Level

Account-level S3 Block Public Access protects every bucket in an account. With AWS Organizations, you can apply it everywhere and prevent anyone from...

AWSHow-To & Hardening

S3 Public Access Audit Checklist

Use this checklist to audit S3 public access across your AWS organization.

AWSCIO Briefings

CIO Brief: One Setting That Prevents the Most Common Cloud Breach

The short version: In 2018, AWS added a setting that prevents cloud storage from being made public at all. Turned on across an account, it stops the most...

AWSPlatform Changes

re:Invent 2018: AWS Security Hub and Control Tower Previews Change Multi-Account Security

At re:Invent in November 2018, AWS announced previews of two services that reshaped multi-account security: AWS Security Hub and AWS Control Tower.

AWSHow-To & Hardening

How to Design a Multi-Account AWS Landing Zone With Security Guardrails

A multi-account AWS landing zone separates workloads, centralizes security tools and protects logs. Here is how to design one using AWS's own reference...

AWSHow-To & Hardening

AWS Security Hub Standards Triage Checklist

AWS Security Hub can produce hundreds of failed controls on day one. This checklist helps you triage them without drowning.

AWSCIO Briefings

CIO Brief: Why One Big AWS Account Is a Security Liability

The short version: AWS recommends running your cloud as many separate accounts — one per application or environment — instead of one big account. In 2018,...

AWSIncident Teardowns

Tesla's Kubernetes Console Cryptojacked (Feb 2018): Exposed Dashboards, Exposed AWS Keys

In February 2018, researchers at RedLock disclosed that attackers had broken into Tesla's cloud environment and used it to mine cryptocurrency.

AWSHow-To & Hardening

How to Secure Kubernetes Dashboards and Cluster Credentials on AWS

An exposed Kubernetes dashboard gave attackers a path into Tesla's cloud in 2018. Here is how to secure Kubernetes management interfaces and cluster...

AWSDetection & Response

Detecting Cryptojacking in Cloud: CloudTrail, GuardDuty and Athena Queries

Cryptojacking — using stolen cloud resources to mine cryptocurrency — is one of the most common outcomes of a cloud compromise. It is also one of the most...

AWSCIO Briefings

CIO Brief: Cryptojacking — The Breach That Shows Up on Your Cloud Bill

The short version: In 2018, attackers broke into Tesla's cloud through an unprotected management console and used its computers to mine cryptocurrency....

AWSIncident Teardowns

Uber's Hidden Breach (Disclosed Nov 2017): AWS Keys in a Private GitHub Repo

In November 2017, Uber disclosed that a year earlier attackers had stolen personal data on about 57 million riders and drivers, including the driver's...

AWSHow-To & Hardening

How to Prevent Hardcoded AWS Keys With Secret Scanning and IAM Roles

Long-lived AWS access keys in source code have caused breaches at companies of every size, from Uber in 2016 to the extortion campaigns of the 2020s. Here...

AWSDetection & Response

Detecting Leaked AWS Access Keys: CloudTrail, GuardDuty and Athena Queries

Leaked AWS access keys are often used within minutes of exposure. Detecting misuse quickly limits how much an attacker can do.

AWSCIO Briefings

CIO Brief: Breach Concealment, Disclosure Laws and the Uber Lesson

The short version: Uber's 2016 breach began with cloud passwords left in a code repository. What made it infamous was the cover-up: the company paid the...

AWSIncident Teardowns

Pentagon Social Media Surveillance Data in Open S3 Buckets (Nov 2017)

In November 2017, UpGuard researchers found three Amazon S3 buckets configured for public access that contained billions of social media posts collected as...

AWSHow-To & Hardening

How to Enforce S3 Guardrails With AWS Config Rules

AWS Config continuously evaluates resource settings against rules. For S3, a handful of rules catches most of the misconfigurations behind past data...

AWSDetection & Response

Detecting S3 Misconfiguration: CloudTrail, GuardDuty and Athena Queries

Most S3 misconfigurations begin with a configuration change. Monitoring those changes in near real time catches exposures within minutes rather than months.

AWSCIO Briefings

CIO Brief: Even Defense Agencies Misconfigure Cloud Storage — Here's Why

The short version: In 2017, cloud storage tied to US military programs was found open to the public. If defense organizations can make this mistake, any...

AWSPlatform Changes

Amazon GuardDuty Launches at re:Invent 2017: Managed Threat Detection for AWS

At re:Invent in November 2017, AWS launched Amazon GuardDuty, a managed threat detection service. With one click, it began analyzing an account's activity...

AWSHow-To & Hardening

How to Enable GuardDuty Across an AWS Organization in One Afternoon

Amazon GuardDuty should be enabled in every account and every region you use. With AWS Organizations, you can do that in an afternoon. Here is how.

AWSHow-To & Hardening

GuardDuty Finding Triage Runbook for Small Security Teams

GuardDuty generates findings; your team turns them into decisions. This runbook gives small security teams a consistent way to triage GuardDuty findings.

AWSCIO Briefings

CIO Brief: Managed Threat Detection — Build vs. Buy for AWS

The short version: Amazon GuardDuty, launched in 2017, watches your AWS accounts for signs of attack and costs relatively little. The decision is not really...

← NewerPage 4 of 5Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.