Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Multi-Cloud

Articles in Multi-Cloud.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Multi-CloudDetection & Response

Detecting SaaS Credential Stuffing: Sentinel and GuardDuty Detections

Infostealer-sourced credentials are used against SaaS platforms in automated campaigns. These detections help catch SaaS account takeover and data theft.

Multi-CloudCIO Briefings

CIO Brief: SaaS Shared Responsibility — Snowflake Wasn't Hacked, Its Customers Were

The short version: In 2024, attackers stole data from about 165 companies' accounts on Snowflake, a cloud data platform — including Ticketmaster and AT&T....

Multi-CloudIncident Teardowns

The XZ Utils Backdoor (Mar 2024): A Multi-Year Open-Source Supply-Chain Plot

On March 29, 2024, Microsoft engineer Andres Freund disclosed that he had found a backdoor in XZ Utils, a compression library included in many Linux...

Multi-CloudHow-To & Hardening

How to Scan Cloud Images and Containers for Compromised Packages

When a compromised package like XZ Utils is discovered, you need to know quickly whether it's in your cloud images and containers. Here is how to scan...

Multi-CloudDetection & Response

Detecting Compromised Open Source Packages: Sentinel and GuardDuty Detections

Compromised open-source packages are hard to detect by behavior — they're designed to look legitimate. Detection relies on inventory, threat intelligence...

Multi-CloudCIO Briefings

CIO Brief: Open-Source Dependencies Are Third-Party Risk

The short version: In 2024, a hidden backdoor was discovered in XZ Utils, a small but widely used piece of free software in Linux systems. Someone had spent...

Multi-CloudHow-To & Hardening

How to Enforce MFA on Every Remote Access Portal

Change Healthcare and Colonial Pipeline were both breached through remote access without MFA. Here is how to enforce MFA on every remote access portal.

Multi-CloudDetection & Response

Detecting Remote Access Without MFA: Sentinel and GuardDuty Detections

Remote access without MFA is a top ransomware entry point. These detections look for single-factor access and the activity that typically follows.

Multi-CloudCIO Briefings

CIO Brief: Change Healthcare and the Systemic Risk of One Missing Control

The short version: In February 2024, ransomware shut down Change Healthcare, disrupting pharmacies and medical billing across the US for weeks. The...

Multi-CloudHow-To & Hardening

How to Inventory Internet-Facing File Transfer and Integration Services

Attackers repeatedly target internet-facing file transfer, integration and remote access services. Here is how to inventory them so you can patch, restrict...

Multi-CloudDetection & Response

Detecting File Transfer Zero-Day Exploitation: Sentinel and GuardDuty Detections

Mass exploitation of file transfer products typically targets web interfaces and ends with bulk data downloads. These detections help catch both stages.

Multi-CloudCIO Briefings

CIO Brief: Managed File Transfer — The Forgotten Crown Jewel

The short version: In 2023, a ransomware gang exploited a flaw in MOVEit, a file transfer product, stealing data from over 2,000 organizations — many of...

Multi-CloudIncident Teardowns

CircleCI Secrets Breach (Jan 2023): Rotate Everything

On January 4, 2023, CircleCI, a widely used continuous integration and delivery platform, told customers to rotate all secrets stored in its platform...

Multi-CloudHow-To & Hardening

How to Run a Secrets Rotation Fire Drill Across AWS and Azure

When a provider tells you to rotate everything, the hardest part is knowing what "everything" is. A rotation fire drill — practiced in advance — makes it...

Multi-CloudDetection & Response

Detecting CI/CD Secrets Theft: Sentinel and GuardDuty Detections

After a CI/CD provider breach, attackers use stolen secrets to access your cloud. Detecting that use — and use of secrets after rotation — tells you whether...

Multi-CloudCIO Briefings

CIO Brief: When a Dev Tool Breach Forces a Company-Wide Credential Reset

The short version: In January 2023, CircleCI — a service many companies use to build and deploy software — told every customer to change every password and...

Multi-CloudIncident Teardowns

LastPass (Disclosed Dec 2022): Vault Backups Stolen From Cloud Storage

In August 2022, password manager LastPass disclosed that an attacker had accessed its development environment. In December 2022, it revealed that the...

Multi-CloudHow-To & Hardening

How to Protect Cloud Backup Storage With Separate Credentials and Immutability

In the LastPass breach, attackers stole backups from cloud storage using credentials taken from an engineer's home computer. Backups need their own...

Multi-CloudDetection & Response

Detecting Cloud Backup Theft: Sentinel and GuardDuty Detections

Attackers increasingly target backups — to steal data or to delete it before ransomware. These detections watch for unusual backup access and changes.

Multi-CloudCIO Briefings

CIO Brief: Password Manager Breaches and Your Enterprise Secrets

The short version: In 2022, attackers stole encrypted copies of LastPass customers' password vaults by hacking an engineer's home computer and using it to...

Multi-CloudIncident Teardowns

Heroku and Travis CI OAuth Tokens Stolen (Apr 2022): Hijacking GitHub Access

In April 2022, GitHub disclosed that an attacker had used stolen OAuth user tokens issued to two third-party integrators — Heroku and Travis CI — to...

Multi-CloudHow-To & Hardening

How to Secure CI/CD Pipelines With OIDC Federation Instead of Stored Secrets

Stored cloud credentials in CI/CD systems are a prime target. OIDC federation lets pipelines get short-lived credentials from AWS or Azure on demand — with...

Multi-CloudDetection & Response

Detecting Stolen OAuth Tokens: Sentinel and GuardDuty Detections

Stolen OAuth tokens let attackers act as a trusted app without passwords or MFA. Detection focuses on token use that doesn't fit the app's normal behavior.

Multi-CloudCIO Briefings

CIO Brief: Your Build Pipeline Has the Keys to Production

The short version: In 2022, attackers stole the digital access passes that Heroku and Travis CI used to connect to customers' GitHub code repositories, and...

← NewerPage 2 of 5Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.