Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Multi-Cloud

Articles in Multi-Cloud.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Multi-CloudIncident Teardowns

MGM Resorts Guest Data Leak (Feb 2020): 10 Million Records From a Cloud Server

In February 2020, personal details of more than 10.6 million MGM Resorts hotel guests were posted on a hacking forum. MGM confirmed the data came from a...

Multi-CloudHow-To & Hardening

How to Classify and Monitor Customer Data Stores Across Clouds

You can't protect customer data you can't find. Here is a practical approach to classifying and monitoring customer data stores across Azure, AWS and...

Multi-CloudDetection & Response

Detecting Cloud Server Data Exposure: Sentinel and GuardDuty Detections

Data exposures from cloud servers and databases often go unnoticed until data appears for sale. These detections help you spot exposure and unusual data...

Multi-CloudCIO Briefings

CIO Brief: Customer Data Leaks and Reputational Damage

The short version: In 2020, personal details of more than 10 million MGM hotel guests appeared on a hacking forum, from an earlier breach of a cloud server....

Multi-CloudIncident Teardowns

Travelex Ransomware (Dec 2019): Unpatched VPN Servers and a Business Standstill

On December 31, 2019, foreign exchange company Travelex was hit by Sodinokibi (REvil) ransomware. Its websites and systems went offline for weeks, and banks...

Multi-CloudHow-To & Hardening

How to Retire Legacy VPNs in Favor of Zero Trust Access

Traditional VPNs give users broad network access once connected and present a constantly targeted appliance on the internet. Zero trust access replaces that...

Multi-CloudDetection & Response

Detecting VPN Vulnerability Exploitation: Sentinel and GuardDuty Detections

Attackers exploiting VPN and remote access appliances often look like legitimate users. Detection focuses on suspicious sessions and what happens after them.

Multi-CloudCIO Briefings

CIO Brief: When Ransomware Stops Revenue — The Travelex Timeline

The short version: On New Year's Eve 2019, ransomware shut down Travelex's systems for weeks. Attackers reportedly got in through a remote access device...

Multi-CloudIncident Teardowns

Marriott-Starwood (Nov 2018): A Four-Year Intrusion Inherited Through Acquisition

On November 30, 2018, Marriott International announced that attackers had accessed the guest reservation database of its Starwood brands. The intrusion had...

Multi-CloudHow-To & Hardening

How to Run a Cloud Security Due Diligence Review During M&A

When you acquire a company, you acquire its cloud environments, identities and possibly its attackers. Here is how to run a cloud security due diligence...

Multi-CloudDetection & Response

Hunting for Long-Dwell Intruders in Cloud and Hybrid Environments

Marriott's attackers stayed inside Starwood's network for about four years. Long-dwell intruders are quiet by design. Hunting for them means looking for...

Multi-CloudCIO Briefings

CIO Brief: When You Buy a Company, You Buy Its Breaches

The short version: When Marriott bought Starwood in 2016, it also bought a hacker who had been inside Starwood's systems since 2014. The breach wasn't...

Multi-CloudIncident Teardowns

Meltdown and Spectre (Jan 2018): When the CPU Itself Was the Vulnerability

On January 3, 2018, researchers disclosed Meltdown and Spectre, a family of vulnerabilities in the way modern processors execute instructions speculatively....

Multi-CloudHow-To & Hardening

How to Track Hypervisor and Guest Patching for Azure and AWS VMs

When a major vulnerability affects cloud hosts, providers patch the hypervisor — but your virtual machines are still yours to patch. Here is how to track...

Multi-CloudDetection & Response

Patch Verification Queries for CPU Vulnerabilities Across Azure and AWS VMs

Hardware vulnerabilities like Meltdown and Spectre are hard to detect being exploited. The practical detection task is making sure every system actually...

Multi-CloudCIO Briefings

CIO Brief: Shared Responsibility When the Flaw Is in the Hardware

The short version: In 2018, researchers found flaws in nearly every computer processor that could let one program read another's data. Cloud providers had...

Multi-CloudIncident Teardowns

Equifax (Sept 2017): One Unpatched Apache Struts Server, 147 Million Records

In September 2017, Equifax disclosed that attackers had stolen personal data on about 147 million people, including Social Security numbers, birth dates and...

Multi-CloudHow-To & Hardening

How to Build a Vulnerability Management Program for Cloud-Hosted Apps

Equifax was breached through a known vulnerability in a web framework that had a patch available for two months. A vulnerability management program makes...

Multi-CloudDetection & Response

Detecting Unpatched Web Application Exploitation: Sentinel and GuardDuty Detections

Exploitation of public-facing web applications is one of the most common ways attackers get in. Detecting exploitation attempts — and especially successful...

Multi-CloudCIO Briefings

CIO Brief: What the Equifax Hearings Mean for Executive Accountability

The short version: Equifax lost data on about 147 million people in 2017 because a known software flaw went unpatched for months, and monitoring that should...

Multi-CloudIncident Teardowns

Cloudbleed (Feb 2017): When Your CDN Leaks Your Customers' Session Tokens

In February 2017, Google Project Zero researcher Tavis Ormandy noticed something strange in search results: fragments of private data from websites that...

Multi-CloudHow-To & Hardening

How to Rotate Sessions and Secrets After a Third-Party Provider Leak

When a provider you depend on — a CDN, identity platform, CI/CD service or SaaS tool — announces that tokens or secrets may have leaked, speed matters more...

Multi-CloudDetection & Response

Detecting Leaked Session Tokens: Sentinel and GuardDuty Detections

When a provider leaks session tokens, the question is whether anyone used them. Detection focuses on sessions that look valid but behave differently from...

Multi-CloudCIO Briefings

CIO Brief: Managing Risk When a Core Internet Provider Has a Bug

The short version: In 2017, a bug at Cloudflare, a major internet provider, leaked private data from customer websites, including login sessions. The...

← NewerPage 4 of 5Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.