Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Incident Teardowns

Articles in Incident Teardowns.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Microsoft 365Incident Teardowns

38 Million Records Exposed by Power Apps Portals (Aug 2021): Low-Code, High Risk

In August 2021, UpGuard researchers disclosed that about 38 million records were exposed through Microsoft Power Apps portals belonging to 47 organizations,...

Multi-CloudIncident Teardowns

Kaseya VSA (July 2021): Ransomware Delivered Through an MSP Tool

On July 2, 2021 — the start of a US holiday weekend — the REvil ransomware group exploited a zero-day vulnerability in Kaseya VSA, a remote monitoring and...

Multi-CloudIncident Teardowns

Colonial Pipeline (May 2021): One Legacy VPN Password Without MFA

On May 7, 2021, Colonial Pipeline — which carries a large share of the fuel supply for the US East Coast — shut down its pipeline operations after a...

Microsoft 365Incident Teardowns

ProxyLogon (Mar 2021): Exchange Server Zero-Days Exploited at Massive Scale

On March 2, 2021, Microsoft released emergency patches for four zero-day vulnerabilities in on-premises Microsoft Exchange Server, collectively known as...

Multi-CloudIncident Teardowns

Verkada Camera Breach (Mar 2021): A Super Admin Credential Left Exposed

In March 2021, a group of hackers gained access to Verkada, a cloud-based security camera company, and viewed live feeds from roughly 150,000 cameras at...

Microsoft 365Incident Teardowns

Mimecast Certificate Compromise (Jan 2021): When a Security Vendor Holds Keys to Your Tenant

In January 2021, email security company Mimecast disclosed that a certificate it used to authenticate certain products to Microsoft 365 Exchange Online had...

Entra ID & IdentityIncident Teardowns

SolarWinds and Golden SAML (Dec 2020): The Supply-Chain Attack That Reached the Cloud

On December 13, 2020, the world learned that attackers had compromised SolarWinds' Orion network monitoring software and inserted a backdoor — later called...

Entra ID & IdentityIncident Teardowns

After SolarWinds (Dec 2020): Attackers Abuse Azure AD Application Credentials

After SolarWinds was discovered in December 2020, Microsoft and incident responders described a key technique the attackers used in Microsoft 365: abusing...

AzureIncident Teardowns

Zerologon (Aug–Sept 2020): Taking Over a Domain Controller in Seconds

In August 2020, Microsoft patched CVE-2020-1472, a critical flaw in the Netlogon Remote Protocol used by Windows domain controllers. In September,...

Entra ID & IdentityIncident Teardowns

The Twitter Hack (July 2020): Phone Spear-Phishing Against Internal Admin Tools

On July 15, 2020, the Twitter accounts of Barack Obama, Joe Biden, Elon Musk, Bill Gates, Apple and others posted a cryptocurrency scam. Attackers had taken...

Microsoft 365Incident Teardowns

Illicit Consent Grant Phishing (July 2020): Attackers Stop Stealing Passwords

In July 2020, Microsoft warned about a rise in consent phishing (also called illicit consent grant) campaigns, many using COVID-19 themes. Instead of...

Multi-CloudIncident Teardowns

Blackbaud Ransomware (July 2020): When Your SaaS Provider Pays the Ransom

In July 2020, Blackbaud — a cloud software provider widely used by nonprofits, universities and healthcare organizations for fundraising and donor...

Microsoft 365Incident Teardowns

Zoom-Bombing (Apr 2020): What It Taught Us About Teams Meeting Security

In early 2020, as remote work exploded, "Zoom-bombing" entered the vocabulary: uninvited people joined online meetings and classrooms to disrupt them with...

Microsoft 365Incident Teardowns

The COVID-19 Remote Work Shift (Mar 2020): Teams Sprawl, Guest Access and Shadow IT

In March 2020, the COVID-19 pandemic sent much of the global workforce home almost overnight. Microsoft Teams usage exploded as organizations rushed to keep...

Multi-CloudIncident Teardowns

MGM Resorts Guest Data Leak (Feb 2020): 10 Million Records From a Cloud Server

In February 2020, personal details of more than 10.6 million MGM Resorts hotel guests were posted on a hacking forum. MGM confirmed the data came from a...

AzureIncident Teardowns

Microsoft's 250 Million Support Records Exposed (Jan 2020): A Misconfigured Azure Database

In January 2020, Microsoft disclosed that a customer support database containing about 250 million records had been exposed on the internet without password...

Multi-CloudIncident Teardowns

Travelex Ransomware (Dec 2019): Unpatched VPN Servers and a Business Standstill

On December 31, 2019, foreign exchange company Travelex was hit by Sodinokibi (REvil) ransomware. Its websites and systems went offline for weeks, and banks...

AWSIncident Teardowns

Imperva's Cloud WAF Breach (Aug 2019): A Stolen AWS API Key From an Internal Instance

In August 2019, Imperva, a security company known for its cloud web application firewall (formerly Incapsula), disclosed a data exposure affecting customers...

AWSIncident Teardowns

Capital One (July 2019): SSRF, the EC2 Metadata Service and 100 Million Records

On July 29, 2019, Capital One disclosed a breach affecting about 100 million people in the US and 6 million in Canada. It became the defining cloud breach...

AzureIncident Teardowns

BlueKeep (May 2019): Wormable RDP and the Risk of Internet-Exposed Azure VMs

In May 2019, Microsoft patched CVE-2019-0708, a critical vulnerability in Remote Desktop Services that became known as BlueKeep. It affected older Windows...

Microsoft 365Incident Teardowns

Outlook.com Support Agent Account Compromised (Apr 2019): The Help Desk Attack Surface

In April 2019, Microsoft notified some users of its consumer email services — Outlook.com, Hotmail and MSN — that a support agent's credentials had been...

Microsoft 365Incident Teardowns

Citrix Breached via Password Spraying (Mar 2019): Weak Passwords at Enterprise Scale

In March 2019, Citrix disclosed that the FBI had informed it of a breach of its internal network. The FBI's assessment, according to Citrix, was that...

Entra ID & IdentityIncident Teardowns

The Azure AD MFA Outage of November 2018: When Sign-In Itself Goes Down

On November 19, 2018, Azure Active Directory's multi-factor authentication service suffered a major outage. For much of a working day, many users in Europe,...

Multi-CloudIncident Teardowns

Marriott-Starwood (Nov 2018): A Four-Year Intrusion Inherited Through Acquisition

On November 30, 2018, Marriott International announced that attackers had accessed the guest reservation database of its Starwood brands. The intrusion had...

← NewerPage 3 of 4Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.