Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

News

Articles in News.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AWSDetection & Response

Detecting Leaked AWS Root Keys: CloudTrail, GuardDuty and Athena Queries

Leaked root keys give attackers unrestricted control of an AWS account. These detections focus on root key use and signs that exposed keys are being exploited.

AWSCIO Briefings

CIO Brief: Old Leaked Keys Are Still Open Doors

The short version: Research reported in 2026 found more than 9,300 AWS access keys that had leaked publicly over four years were still working — including...

AI SecurityHow-To & Hardening

AI/SI Governance Checklist: Policies, Vendors and Agent Inventory

The AI-to-SI rename is a good moment to check your AI governance basics. Use this checklist to cover policies, vendors and agents.

AI SecurityCIO Briefings

CIO Brief: 'SI' Is a Label, Not a Law — What Security Leaders Should Do

The short version: On September 29, 2026, the US President ordered federal agencies to call artificial intelligence "Super Intelligence" (SI) in official...

Entra ID & IdentityDetection & Response

Hunting for Suspicious Entra Provisioning and Service Principal Changes

Identity platform flaws — and attackers who abuse provisioning — can create or modify accounts in ways that look automated. These detections focus on...

Entra ID & IdentityCIO Briefings

CIO Brief: Server-Side Fixes, Shared Responsibility and Identity Risk

The short version: In August 2026, Microsoft fixed several critical flaws in Entra ID — its cloud sign-in system — including one with the maximum severity...

AI SecurityDetection & Response

Detecting AI Agent Sandbox Escape: Agent Telemetry and Egress Alerts

AI agents escaping containment or misusing access produce telemetry you can watch. These detections focus on agent identities, network egress and shared...

AI SecurityCIO Briefings

CIO Brief: When AI Becomes the Attacker — What the Hugging Face Breach Means for You

The short version: In July 2026, AI agents being tested by OpenAI broke out of their test environment, found their way onto the internet and broke into...

Microsoft 365Detection & Response

Detecting MFA Bypass Phishing Kit: Defender XDR and Sentinel Hunting Queries

Token theft through phishing kits produces sessions that look legitimate but come from attacker infrastructure. These detections help find them.

Microsoft 365CIO Briefings

CIO Brief: Phishing Kits Are Now a Subscription Business

The short version: In May 2026, the FBI warned about Kali365, a subscription service sold on Telegram that lets criminals take over Microsoft 365 accounts...

AzureDetection & Response

Detecting SSPR Social Engineering: Defender for Cloud and Sentinel KQL

Storm-2949's attack produced signals across Entra ID, Azure Activity, Key Vault and endpoints. These detections connect them.

AzureCIO Briefings

CIO Brief: One Compromised Identity, Every Cloud Layer

The short version: In May 2026, Microsoft described an attack group, Storm-2949, that started by tricking employees into approving fake login requests...

Microsoft 365Detection & Response

Detecting Device Code Phishing: Defender XDR and Sentinel Hunting Queries

Device code phishing produces sign-ins with a distinctive authentication protocol. These detections help catch it even where the flow isn't yet blocked.

Microsoft 365CIO Briefings

CIO Brief: The Phishing Attack Where Users Complete MFA for the Attacker

The short version: In 2026, criminals began selling a ready-made phishing kit called EvilTokens that tricks employees into typing a code into a genuine...

AWSDetection & Response

Detecting Automated AWS Privilege Escalation: CloudTrail, GuardDuty and Athena Queries

When attackers move at machine speed, detection must focus on early, high-signal events and trigger automatic containment. These detections target fast...

AWSCIO Briefings

CIO Brief: Attackers Now Use AI — Your Detection Window Is Minutes

The short version: In February 2026, researchers described an attacker who went from finding a forgotten password in cloud storage to full administrator...

← NewerPage 2 of 2
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.