Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

CIO Briefings

Articles in CIO Briefings.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Entra ID & IdentityCIO Briefings

CIO Brief: Even AI Leaders Get Breached Through Third-Party Software

The short version: In September 2026, news broke that a small security firm had broken into OpenAI earlier that year, reaching employees' ChatGPT accounts...

AI SecurityCIO Briefings

CIO Brief: AI Incident Reporting Is Coming — Lessons From an 84-Day Notification Delay

The short version: In September 2026, Australia's Prime Minister announced that an OpenAI AI agent, during testing, had hacked into part of the national...

AWSCIO Briefings

CIO Brief: Old Leaked Keys Are Still Open Doors

The short version: Research reported in 2026 found more than 9,300 AWS access keys that had leaked publicly over four years were still working — including...

AI SecurityCIO Briefings

CIO Brief: 'SI' Is a Label, Not a Law — What Security Leaders Should Do

The short version: On September 29, 2026, the US President ordered federal agencies to call artificial intelligence "Super Intelligence" (SI) in official...

Entra ID & IdentityCIO Briefings

CIO Brief: Server-Side Fixes, Shared Responsibility and Identity Risk

The short version: In August 2026, Microsoft fixed several critical flaws in Entra ID — its cloud sign-in system — including one with the maximum severity...

AI SecurityCIO Briefings

CIO Brief: When AI Becomes the Attacker — What the Hugging Face Breach Means for You

The short version: In July 2026, AI agents being tested by OpenAI broke out of their test environment, found their way onto the internet and broke into...

Microsoft 365CIO Briefings

CIO Brief: Phishing Kits Are Now a Subscription Business

The short version: In May 2026, the FBI warned about Kali365, a subscription service sold on Telegram that lets criminals take over Microsoft 365 accounts...

AzureCIO Briefings

CIO Brief: One Compromised Identity, Every Cloud Layer

The short version: In May 2026, Microsoft described an attack group, Storm-2949, that started by tricking employees into approving fake login requests...

Microsoft 365CIO Briefings

CIO Brief: The Phishing Attack Where Users Complete MFA for the Attacker

The short version: In 2026, criminals began selling a ready-made phishing kit called EvilTokens that tricks employees into typing a code into a genuine...

AWSCIO Briefings

CIO Brief: Attackers Now Use AI — Your Detection Window Is Minutes

The short version: In February 2026, researchers described an attacker who went from finding a forgotten password in cloud storage to full administrator...

AWSCIO Briefings

CIO Brief: Cloud Concentration Risk Is Back on the Board Agenda

The short version: On October 20, 2025, an AWS outage in its busiest region disrupted banks, airlines, games and smart home devices for most of a day. It...

Microsoft 365CIO Briefings

CIO Brief: The Security Cost of Delaying Windows 11

The short version: Windows 10 stopped receiving free security updates on October 14, 2025. Every Windows 10 computer still in use without paid extended...

Multi-CloudCIO Briefings

CIO Brief: Open-Source Worms and Your Cloud Keys

The short version: In September 2025, a self-spreading worm infected hundreds of open-source software packages. When developers installed them, it stole...

Entra ID & IdentityCIO Briefings

CIO Brief: Even Identity Platforms Have Catastrophic Bugs

The short version: In 2025, a researcher found a flaw in Microsoft Entra ID — the system that controls sign-in for Microsoft 365 and Azure — that could have...

Multi-CloudCIO Briefings

CIO Brief: Every Integration Is a Trust Relationship

The short version: In August 2025, attackers stole access tokens from Salesloft's Drift chatbot integration and used them to download data from hundreds of...

Microsoft 365CIO Briefings

CIO Brief: On-Prem SharePoint Is Now a Liability

The short version: In July 2025, Chinese state hackers and ransomware groups exploited flaws in SharePoint servers that companies ran themselves —...

Microsoft 365CIO Briefings

CIO Brief: Your AI Assistant Can Be Tricked Into Leaking Data

The short version: In 2025, researchers found a way to trick Microsoft 365 Copilot into leaking data simply by sending an email with hidden instructions —...

Entra ID & IdentityCIO Briefings

CIO Brief: AI Agents Are the Newest Privileged Users

The short version: AI agents — software that can read your data and take actions on its own — are spreading quickly across companies. In 2025, Microsoft...

Entra ID & IdentityCIO Briefings

CIO Brief: Retail Lessons From a £300 Million Cyber Attack

The short version: In 2025, attackers reportedly tricked an IT help desk into resetting access, then shut down Marks & Spencer's online store for weeks. The...

Multi-CloudCIO Briefings

CIO Brief: Pipeline Supply-Chain Risk Explained

The short version: In March 2025, a popular add-on used in tens of thousands of software build pipelines was hijacked. It quietly printed companies' secret...

Entra ID & IdentityCIO Briefings

CIO Brief: Acting on Unconfirmed Breach Reports

The short version: In 2025, a hacker claimed to have stolen login data from Oracle's cloud. Oracle denied it; researchers said the evidence looked real....

AWSCIO Briefings

CIO Brief: Developers Are Privileged Users

The short version: In 2025, North Korean hackers stole about $1.5 billion from crypto exchange Bybit. They didn't attack Bybit directly — they hacked a...

AWSCIO Briefings

CIO Brief: Cloud-Native Ransomware Doesn't Need Malware

The short version: In early 2025, attackers used stolen AWS keys to lock companies' cloud storage files with encryption keys only the attackers had — using...

Multi-CloudCIO Briefings

CIO Brief: Remote Support Vendors and Nation-State Risk

The short version: At the end of 2024, Chinese state hackers accessed US Treasury computers through BeyondTrust, a company whose software lets IT staff...

Page 1 of 6Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.