Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Incident Teardowns

Articles in Incident Teardowns.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AWSIncident Teardowns

The AWS us-east-1 Outage of October 2025: DNS, DynamoDB and a Day of Downtime

On October 20, 2025, AWS's US-EAST-1 region suffered a major outage that disrupted a wide range of services — from banking and gaming apps to smart home...

Entra ID & IdentityIncident Teardowns

Entra ID Actor Token Flaw (Sept 2025): A Cross-Tenant Global Admin Bug

In September 2025, security researcher Dirk-jan Mollema published details of a critical flaw in Microsoft Entra ID that could have allowed an attacker to...

Multi-CloudIncident Teardowns

tj-actions/changed-files Compromise (Mar 2025): A GitHub Action Leaks CI Secrets

On March 14, 2025, security researchers discovered that tj-actions/changed-files, a popular GitHub Action used in tens of thousands of repositories, had...

Entra ID & IdentityIncident Teardowns

Oracle Cloud Login Breach Claims (Mar 2025): When the Provider Denies and Customers Rotate

In March 2025, a threat actor using the name "rose87168" claimed to have stolen millions of records from Oracle Cloud's single sign-on (SSO) login...

Multi-CloudIncident Teardowns

US Treasury Breached via a BeyondTrust API Key (Dec 2024)

On December 30, 2024, the US Treasury Department told Congress that a China state-sponsored actor had accessed some Treasury workstations and unclassified...

AWSIncident Teardowns

Exposed .env Files Fuel an AWS Extortion Campaign (Aug 2024)

In August 2024, researchers at Palo Alto Networks' Unit 42 described an extortion campaign that started with publicly exposed environment (.env) files on...

Multi-CloudIncident Teardowns

The XZ Utils Backdoor (Mar 2024): A Multi-Year Open-Source Supply-Chain Plot

On March 29, 2024, Microsoft engineer Andres Freund disclosed that he had found a backdoor in XZ Utils, a compression library included in many Linux...

Entra ID & IdentityIncident Teardowns

Okta Support System Breach (Oct 2023): Session Tokens in Uploaded HAR Files

In October 2023, Okta disclosed that an attacker had used stolen credentials to access its customer support case management system and view files uploaded...

Microsoft 365Incident Teardowns

Midnight Blizzard Phishes Through Microsoft Teams (Aug 2023): External Chat as an Attack Vector

On August 2, 2023, Microsoft reported that Midnight Blizzard — the Russian state actor also known as APT29 or Nobelium, linked to SolarWinds — was using...

Multi-CloudIncident Teardowns

CircleCI Secrets Breach (Jan 2023): Rotate Everything

On January 4, 2023, CircleCI, a widely used continuous integration and delivery platform, told customers to rotate all secrets stored in its platform...

Multi-CloudIncident Teardowns

LastPass (Disclosed Dec 2022): Vault Backups Stolen From Cloud Storage

In August 2022, password manager LastPass disclosed that an attacker had accessed its development environment. In December 2022, it revealed that the...

AzureIncident Teardowns

BlueBleed (Oct 2022): Misconfigured Azure Blob Storage Exposes Microsoft Customer Data

In October 2022, threat intelligence company SOCRadar reported a data leak it called BlueBleed: a misconfigured Microsoft-owned Azure Blob Storage container...

Entra ID & IdentityIncident Teardowns

Uber Breached via MFA Fatigue (Sept 2022): A Contractor, a Push Storm and Hardcoded Admin Secrets

On September 15, 2022, Uber disclosed a network security incident. An attacker had gained access to internal systems including its Slack workspace, cloud...

Microsoft 365Incident Teardowns

ProxyNotShell (Sept 2022): The Third Major Exchange Zero-Day Wave

On September 29, 2022, Microsoft confirmed two zero-day vulnerabilities in on-premises Microsoft Exchange Server being exploited in limited, targeted...

Entra ID & IdentityIncident Teardowns

0ktapus and the Twilio Breach (Aug 2022): SMS Phishing Against 130+ Companies

In August 2022, researchers at Group-IB described a phishing campaign they named 0ktapus. It targeted employees of more than 130 organizations — many of...

Microsoft 365Incident Teardowns

Adversary-in-the-Middle Phishing Hits 10,000 Organizations (July 2022): MFA Bypassed at Scale

On July 12, 2022, Microsoft published research on a large-scale adversary-in-the-middle (AiTM) phishing campaign that had targeted more than 10,000...

Microsoft 365Incident Teardowns

Follina (May–June 2022): Office Documents That Ran Code Without Macros

In late May 2022, researchers identified a malicious Word document that executed code without macros. The vulnerability it exploited, nicknamed Follina...

Multi-CloudIncident Teardowns

Heroku and Travis CI OAuth Tokens Stolen (Apr 2022): Hijacking GitHub Access

In April 2022, GitHub disclosed that an attacker had used stolen OAuth user tokens issued to two third-party integrators — Heroku and Travis CI — to...

Entra ID & IdentityIncident Teardowns

Lapsus$ (Mar 2022): Teenagers, MFA Fatigue and Breaches at Okta and Microsoft

Between late 2021 and March 2022, a loosely organized group calling itself Lapsus$ breached some of the world's largest technology companies, including...

Multi-CloudIncident Teardowns

Log4Shell (Dec 2021): The Vulnerability in Everything

On December 9, 2021, a critical vulnerability in Apache Log4j 2 — a Java logging library used in countless applications — became public. Tracked as...

AWSIncident Teardowns

The AWS us-east-1 Outage of December 2021: When the Control Plane Fails

On December 7, 2021, AWS's US-EAST-1 region experienced a major disruption lasting much of the day. Services including Disney+, Netflix, Slack, Venmo,...

AzureIncident Teardowns

OMIGOD (Sept 2021): Hidden Azure Agents Running as Root

In September 2021, Wiz researchers disclosed OMIGOD, four vulnerabilities in Open Management Infrastructure (OMI), a software agent that Microsoft silently...

AzureIncident Teardowns

ChaosDB (Aug 2021): A Cosmos DB Flaw Exposed Thousands of Azure Customers' Keys

In August 2021, researchers at Wiz disclosed ChaosDB, a vulnerability in Microsoft Azure Cosmos DB that could have allowed an attacker to obtain the primary...

Microsoft 365Incident Teardowns

ProxyShell (Aug 2021): Exchange Server Exploited Again

In August 2021, details emerged of ProxyShell, a chain of three vulnerabilities in on-premises Microsoft Exchange Server. Security researcher Orange Tsai...

← NewerPage 2 of 4Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.