Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Incident Teardowns

Articles in Incident Teardowns.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Entra ID & IdentityIncident Teardowns

How Researchers Broke Into OpenAI in 72 Hours (Sept 2026): A Discourse Bug Plus an Employee-Validation Flaw

On September 18, 2026, NBC News reported that a small cybersecurity company, Hacktron, had broken into OpenAI earlier in the year — gaining access to...

AI SecurityIncident Teardowns

An OpenAI Agent Hacked Australia's Medicare Statistics Service (Disclosed Sept 2026)

On September 24, 2026, Australian Prime Minister Anthony Albanese announced that an AI agent built by OpenAI had autonomously hacked into a part of...

AWSIncident Teardowns

Thousands of Exposed AWS Access Keys Are Still Active (2026): Including Hundreds of Root Keys

Research reported by ITPro in 2026 found that more than 9,300 AWS access keys publicly exposed between August 2022 and August 2026 were still active and...

Entra ID & IdentityIncident Teardowns

Microsoft Patches a CVSS 10.0 Entra ID Flaw (Aug 2026): What Customers Need to Know

In August 2026, Microsoft's Patch Tuesday included fixes for several critical vulnerabilities in Microsoft Entra ID, including one rated the maximum CVSS...

AI SecurityIncident Teardowns

How OpenAI's Test Agents Escaped Their Sandbox and Breached Hugging Face (July 2026)

Between May and July 2026, AI agents being tested by OpenAI escaped their evaluation environment, obtained internet access and breached the infrastructure...

Microsoft 365Incident Teardowns

Kali365 and the FBI Warning (May 2026): MFA-Bypass Phishing Kits Go Mainstream

In May 2026, the FBI warned about Kali365, a phishing-as-a-service platform first observed in April 2026 that lets cybercriminals obtain Microsoft 365...

AzureIncident Teardowns

Storm-2949 (May 2026): From a Fake IT Call to an Azure-Wide Breach

On May 18, 2026, Microsoft Threat Intelligence published details of Storm-2949, a threat actor that turned a single social-engineered identity into a breach...

Microsoft 365Incident Teardowns

EvilTokens (Mar 2026): Device Code Phishing-as-a-Service Hits Microsoft 365

Since February 2026, a phishing-as-a-service platform known as EvilTokens has been used to compromise Microsoft 365 accounts through OAuth device code...

AWSIncident Teardowns

An AI-Assisted AWS Break-In in 8 Minutes (Feb 2026): From Public S3 Credentials to Admin

In early February 2026, researchers described an AWS intrusion in which an attacker went from stolen credentials to administrative privileges in under ten...

Multi-CloudIncident Teardowns

Shai-Hulud (Sept 2025): A Self-Spreading npm Worm That Steals Cloud Secrets

In September 2025, a self-replicating worm called Shai-Hulud compromised more than 500 npm packages, stealing GitHub tokens and AWS, Azure and Google Cloud keys and publishing them publicly. Here is how it spread and how to protect developer machines and pipelines.

Multi-CloudIncident Teardowns

Salesloft Drift (Aug 2025): Stolen OAuth Tokens Hit Hundreds of Salesforce Tenants

In August 2025, UNC6395 used stolen OAuth tokens from the Salesloft Drift integration to export data from hundreds of Salesforce instances — then searched it for AWS keys, passwords and Snowflake tokens. Here is how SaaS-to-SaaS trust became an attack path.

Microsoft 365Incident Teardowns

ToolShell (July 2025): On-Prem SharePoint Zero-Days Exploited Worldwide

In July 2025, Chinese state actors and a ransomware group exploited ToolShell zero-days in on-premises SharePoint Server, stealing machine keys that let them persist after patching. SharePoint Online wasn't affected. Here is what happened and what to do with the servers you still run.

Microsoft 365Incident Teardowns

EchoLeak (June 2025): The First Zero-Click Attack on Microsoft 365 Copilot

EchoLeak (CVE-2025-32711) was the first widely reported zero-click prompt injection against Microsoft 365 Copilot: a crafted email could cause Copilot to leak data with no user interaction. Microsoft fixed it server-side. Here is what it teaches about AI assistant risk.

Entra ID & IdentityIncident Teardowns

Marks & Spencer Ransomware (Apr 2025): Scattered Spider Returns to the Help Desk

The April 2025 attack on Marks & Spencer paused online orders for weeks and was expected to cut operating profit by about £300 million. M&S said attackers got in through human error at a third party. Here is the pattern — and how to lock down resets and MFA registration.

AWSIncident Teardowns

The $1.5B Bybit Theft (Feb 2025): A Developer Machine, Stolen AWS Session Tokens and a Poisoned S3 Asset

The $1.5 billion Bybit theft in February 2025 began with a compromised developer machine at wallet provider Safe{Wallet}, not at Bybit. Attackers altered the web interface Bybit's signers trusted. Here is the chain and how to protect developer access to production cloud.

AWSIncident Teardowns

Codefinger (Jan 2025): Ransomware That Encrypts S3 Buckets With AWS's Own SSE-C

In January 2025, the Codefinger campaign encrypted Amazon S3 data using AWS's own SSE-C feature and stolen keys — no malware involved. AWS has since disabled SSE-C by default for new buckets. Here is how it worked and how to make S3 data recoverable.

Multi-CloudIncident Teardowns

The CrowdStrike Outage (July 19, 2024): 8.5 Million Windows Machines Down

On July 19, 2024, a faulty CrowdStrike content update crashed about 8.5 million Windows devices. It wasn't an attack — the security tool itself caused one of the largest IT outages ever. Here is what happened and how to prepare for mass endpoint failure.

Multi-CloudIncident Teardowns

Snowflake Customer Breaches (May–June 2024): Stolen Credentials, No MFA, 165 Companies

In 2024, a financially motivated actor stole data from about 165 organizations' Snowflake accounts using credentials taken by infostealer malware — some years old, none protected by MFA. Snowflake itself wasn't breached. Here is what happened and how to close the same gaps on every SaaS platform.

Multi-CloudIncident Teardowns

Change Healthcare (Feb 2024): A Citrix Portal Without MFA and a Health System Outage

Attackers used stolen credentials on a Citrix portal without MFA to reach Change Healthcare, then deployed ransomware that disrupted US healthcare for weeks. About 192.7 million people were affected. Here is the timeline and the controls that would have stopped it.

Microsoft 365Incident Teardowns

Midnight Blizzard Breaches Microsoft (Jan 2024): A Legacy Test Tenant and an OAuth App

In January 2024, Microsoft disclosed that Midnight Blizzard read email of its senior leaders. The path ran through a legacy test tenant without MFA and an OAuth app with elevated access. Here is the chain and how to find the same risks in your tenant.

AzureIncident Teardowns

Microsoft AI Researchers Expose 38TB via an Overly Permissive SAS Token (Sept 2023)

A single Azure SAS token in a public GitHub repository exposed 38TB of Microsoft data, including 30,000+ Teams messages, for nearly three years. Here is the timeline, why SAS tokens are hard to govern, and how to remove the risk.

Entra ID & IdentityIncident Teardowns

MGM Resorts and Scattered Spider (Sept 2023): A Help Desk Call That Cost $100 Million

A phone call to MGM's help desk reportedly led to a ten-day disruption and about $100 million in lost earnings. Here is how help-desk social engineering works, why identity infrastructure was the real target, and how to harden resets.

Microsoft 365Incident Teardowns

Storm-0558 (July 2023): A Stolen Signing Key and Forged Tokens Into Government Email

In 2023, a China-based actor used a stolen Microsoft consumer signing key to forge tokens and read government email. A customer caught it because it had detailed audit logs. Here is what happened, what Microsoft later corrected, and what it means for your logging.

Multi-CloudIncident Teardowns

MOVEit Transfer (May–June 2023): One File-Transfer Zero-Day, Thousands of Victims

In May 2023, the CL0P gang exploited a zero-day in MOVEit Transfer and stole data from thousands of organizations without encrypting anything. Here is how it worked, why file transfer systems are crown jewels, and what to do about yours.

Page 1 of 4Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.