OMIGOD (Sept 2021): Hidden Azure Agents Running as Root
In September 2021, Wiz researchers disclosed OMIGOD, four vulnerabilities in Open Management Infrastructure (OMI), a software agent that Microsoft silently...
In September 2021, Wiz researchers disclosed OMIGOD, four vulnerabilities in Open Management Infrastructure (OMI), a software agent that Microsoft silently...
Azure VM extensions and management agents add capabilities — and attack surface. Here is how to inventory and patch them.
Management agents and VM extensions run with high privilege. Attackers exploit vulnerable agents or abuse extensions to run code. These detections cover both.
The short version: In 2021, researchers found serious flaws in a management program Microsoft quietly installed on many Linux servers in Azure. Many...
In August 2021, researchers at Wiz disclosed ChaosDB, a vulnerability in Microsoft Azure Cosmos DB that could have allowed an attacker to obtain the primary...
Cosmos DB primary keys grant full access to a database. ChaosDB showed how damaging a leaked key can be. Here is how to rotate keys and move to Entra ID...
Database keys and connection strings, once leaked, are used like legitimate access. Monitoring data plane activity helps you spot misuse.
The short version: In 2021, researchers found a flaw in one of Microsoft's own Azure database services that could have let attackers access thousands of...
In August 2020, Microsoft patched CVE-2020-1472, a critical flaw in the Netlogon Remote Protocol used by Windows domain controllers. In September,...
Domain controllers hold the keys to your on-premises identity — and, in hybrid environments, a path to the cloud. Here is how to patch and monitor them...
Attacks on Active Directory — including Zerologon exploitation, DCSync and Kerberos abuse — leave specific traces. Microsoft Defender for Identity and...
The short version: In 2020, a flaw called Zerologon let attackers take over a company's core identity system — Active Directory — in seconds, without a...
In January 2020, Microsoft disclosed that a customer support database containing about 250 million records had been exposed on the internet without password...
A single network rule change exposed a Microsoft database to the internet in 2019. Azure Policy and private endpoints let you prevent that class of mistake...
Exposed databases are often found by internet scanners within hours. Detecting public exposure — and unexpected access — quickly is critical.
The short version: In 2020, Microsoft disclosed that a customer support database had been left exposed to the internet after a network setting change. If...
In May 2019, Microsoft patched CVE-2019-0708, a critical vulnerability in Remote Desktop Services that became known as BlueKeep. It affected older Windows...
Exposed RDP and SSH ports are among the most attacked entry points in the cloud. Azure Bastion and just-in-time (JIT) VM access let administrators reach...
Even with patches, exposed RDP invites brute force, credential stuffing and exploitation. Detecting both the exposure and attacks against it is essential...
The short version: In 2019, Microsoft warned about BlueKeep, a flaw that could let attackers take over older Windows computers through remote desktop...
On February 28, 2019, Microsoft announced Azure Sentinel in preview — a cloud-native security information and event management (SIEM) service built on Azure...
A good Microsoft Sentinel deployment starts with planning workspaces, data sources and costs before turning anything on. Here is the sequence Microsoft's...
Data connectors determine both what Microsoft Sentinel can detect and what it costs. Use this checklist to prioritize them.
The short version: In 2019, Microsoft released Sentinel, a security monitoring service that runs in the cloud. It made centralized security monitoring...