Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Multi-Cloud

Articles in Multi-Cloud.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Multi-CloudIncident Teardowns

Shai-Hulud (Sept 2025): A Self-Spreading npm Worm That Steals Cloud Secrets

In September 2025, a self-replicating worm called Shai-Hulud compromised more than 500 npm packages, stealing GitHub tokens and AWS, Azure and Google Cloud keys and publishing them publicly. Here is how it spread and how to protect developer machines and pipelines.

Multi-CloudIncident Teardowns

Salesloft Drift (Aug 2025): Stolen OAuth Tokens Hit Hundreds of Salesforce Tenants

In August 2025, UNC6395 used stolen OAuth tokens from the Salesloft Drift integration to export data from hundreds of Salesforce instances — then searched it for AWS keys, passwords and Snowflake tokens. Here is how SaaS-to-SaaS trust became an attack path.

Multi-CloudIncident Teardowns

The CrowdStrike Outage (July 19, 2024): 8.5 Million Windows Machines Down

On July 19, 2024, a faulty CrowdStrike content update crashed about 8.5 million Windows devices. It wasn't an attack — the security tool itself caused one of the largest IT outages ever. Here is what happened and how to prepare for mass endpoint failure.

Multi-CloudIncident Teardowns

Snowflake Customer Breaches (May–June 2024): Stolen Credentials, No MFA, 165 Companies

In 2024, a financially motivated actor stole data from about 165 organizations' Snowflake accounts using credentials taken by infostealer malware — some years old, none protected by MFA. Snowflake itself wasn't breached. Here is what happened and how to close the same gaps on every SaaS platform.

Multi-CloudIncident Teardowns

Change Healthcare (Feb 2024): A Citrix Portal Without MFA and a Health System Outage

Attackers used stolen credentials on a Citrix portal without MFA to reach Change Healthcare, then deployed ransomware that disrupted US healthcare for weeks. About 192.7 million people were affected. Here is the timeline and the controls that would have stopped it.

Multi-CloudIncident Teardowns

MOVEit Transfer (May–June 2023): One File-Transfer Zero-Day, Thousands of Victims

In May 2023, the CL0P gang exploited a zero-day in MOVEit Transfer and stole data from thousands of organizations without encrypting anything. Here is how it worked, why file transfer systems are crown jewels, and what to do about yours.

Multi-CloudHow-To & Hardening

How to Detect Leaked Cloud Credentials From Developer Packages

Supply-chain worms like Shai-Hulud steal cloud credentials from developer machines and CI runners. Here is how to detect leaked credentials and respond quickly.

Multi-CloudDetection & Response

Detecting npm Supply Chain Worm: Sentinel and GuardDuty Detections

Package ecosystem worms leave signals across developer endpoints, code platforms and cloud logs. These detections help spot an infection and its use of...

Multi-CloudCIO Briefings

CIO Brief: Open-Source Worms and Your Cloud Keys

The short version: In September 2025, a self-spreading worm infected hundreds of open-source software packages. When developers installed them, it stole...

Multi-CloudHow-To & Hardening

How to Audit SaaS-to-SaaS OAuth Integrations and Token Scopes

SaaS-to-SaaS integrations hold OAuth tokens that can read and export your data. The Salesloft Drift campaign showed how one compromised vendor can reach...

Multi-CloudDetection & Response

Detecting SaaS OAuth Token Theft: Sentinel and GuardDuty Detections

Stolen OAuth tokens used for data theft show up as bulk API activity from integrations. These detections help catch it.

Multi-CloudCIO Briefings

CIO Brief: Every Integration Is a Trust Relationship

The short version: In August 2025, attackers stole access tokens from Salesloft's Drift chatbot integration and used them to download data from hundreds of...

Multi-CloudIncident Teardowns

tj-actions/changed-files Compromise (Mar 2025): A GitHub Action Leaks CI Secrets

On March 14, 2025, security researchers discovered that tj-actions/changed-files, a popular GitHub Action used in tens of thousands of repositories, had...

Multi-CloudHow-To & Hardening

How to Pin and Allowlist GitHub Actions in Cloud Deployment Pipelines

The tj-actions compromise showed that referencing GitHub Actions by tag lets an attacker change your pipeline without touching your code. Here is how to pin...

Multi-CloudDetection & Response

Detecting GitHub Actions Supply Chain Attack: Sentinel and GuardDuty Detections

Supply-chain attacks on CI/CD dependencies often reveal themselves in workflow behavior and logs. These detections help spot compromised actions and secret...

Multi-CloudCIO Briefings

CIO Brief: Pipeline Supply-Chain Risk Explained

The short version: In March 2025, a popular add-on used in tens of thousands of software build pipelines was hijacked. It quietly printed companies' secret...

Multi-CloudIncident Teardowns

US Treasury Breached via a BeyondTrust API Key (Dec 2024)

On December 30, 2024, the US Treasury Department told Congress that a China state-sponsored actor had accessed some Treasury workstations and unclassified...

Multi-CloudHow-To & Hardening

How to Inventory and Rotate API Keys for Remote Support Tools

API keys for remote support and management tools can provide direct access to your devices. Here is how to inventory them and rotate them safely.

Multi-CloudDetection & Response

Detecting Stolen API Key: Sentinel and GuardDuty Detections

Stolen API keys for remote support tools grant access without user sign-ins. These detections focus on unusual key use and remote sessions.

Multi-CloudCIO Briefings

CIO Brief: Remote Support Vendors and Nation-State Risk

The short version: At the end of 2024, Chinese state hackers accessed US Treasury computers through BeyondTrust, a company whose software lets IT staff...

Multi-CloudHow-To & Hardening

How to Recover BitLocker-Protected Azure VMs and Endpoints at Scale

The CrowdStrike outage showed how hard recovery is when thousands of BitLocker-encrypted devices won't boot. Here is how to prepare for recovering Azure VMs...

Multi-CloudHow-To & Hardening

Endpoint Agent Update Risk Checklist

Security agents and other kernel-level software can take down entire fleets. Use this checklist to manage the risk of endpoint agent updates.

Multi-CloudCIO Briefings

CIO Brief: When Your Security Tool Causes the Outage

The short version: On July 19, 2024, a faulty update to CrowdStrike's security software crashed about 8.5 million Windows computers worldwide. Airlines,...

Multi-CloudHow-To & Hardening

How to Enforce SSO and MFA on Every SaaS Data Platform

The Snowflake customer breaches happened because SaaS data platforms were accessed with stolen passwords and no MFA. Here is how to enforce SSO and MFA...

Page 1 of 5Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.