Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Azure

Articles in Azure.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AzureIncident Teardowns

NotPetya (June 2017): How a Tax Software Update Wiped Out Global Networks

On June 27, 2017, a malware outbreak later called NotPetya began in Ukraine and spread to multinational companies within hours. Shipping giant Maersk had to...

AzureHow-To & Hardening

How to Tier Your Active Directory Admin Accounts to Contain Lateral Movement

NotPetya spread by stealing administrator credentials from memory and reusing them across the network. Tiering your Active Directory admin accounts stops...

AzureDetection & Response

Detecting Credential Theft Lateral Movement: Defender for Cloud and Sentinel KQL

NotPetya combined credential theft with legitimate admin tools to move across networks. Detecting that pattern early is one of the most effective ways to...

AzureCIO Briefings

CIO Brief: NotPetya and the True Cost of Flat Networks and Shared Admin Accounts

The short version: NotPetya, in 2017, entered companies through a trusted software update and then spread using administrator passwords stolen from one...

AzureIncident Teardowns

WannaCry (May 2017): SMBv1, Unpatched Servers and What Cloud Teams Missed

On May 12, 2017, WannaCry ransomware spread across the world in a matter of hours, encrypting files on hundreds of thousands of Windows computers in more...

AzureHow-To & Hardening

How to Disable SMBv1 and Enforce Patch Compliance on Azure VMs

SMBv1 is a decades-old file-sharing protocol with known critical flaws, and it was the doorway for WannaCry and NotPetya. Here is how to remove it from...

AzureDetection & Response

Detecting SMBv1 Exploitation: Defender for Cloud and Sentinel KQL

WannaCry and its successors exploited SMB flaws to spread across networks. Even with SMBv1 removed, detecting suspicious SMB activity is a valuable early...

AzureCIO Briefings

CIO Brief: Why Patch Management Is a Board-Level Issue After WannaCry

The short version: In 2017, WannaCry ransomware infected hundreds of thousands of computers worldwide using a Windows flaw that had been patched two months...

← NewerPage 3 of 3
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.