Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Multi-CloudIncident Teardowns

Shai-Hulud (Sept 2025): A Self-Spreading npm Worm That Steals Cloud Secrets

In September 2025, a self-replicating worm called Shai-Hulud compromised more than 500 npm packages, stealing GitHub tokens and AWS, Azure and Google Cloud keys and publishing them publicly. Here is how it spread and how to protect developer machines and pipelines.

Multi-CloudIncident Teardowns

Salesloft Drift (Aug 2025): Stolen OAuth Tokens Hit Hundreds of Salesforce Tenants

In August 2025, UNC6395 used stolen OAuth tokens from the Salesloft Drift integration to export data from hundreds of Salesforce instances — then searched it for AWS keys, passwords and Snowflake tokens. Here is how SaaS-to-SaaS trust became an attack path.

Microsoft 365Incident Teardowns

ToolShell (July 2025): On-Prem SharePoint Zero-Days Exploited Worldwide

In July 2025, Chinese state actors and a ransomware group exploited ToolShell zero-days in on-premises SharePoint Server, stealing machine keys that let them persist after patching. SharePoint Online wasn't affected. Here is what happened and what to do with the servers you still run.

Microsoft 365Incident Teardowns

EchoLeak (June 2025): The First Zero-Click Attack on Microsoft 365 Copilot

EchoLeak (CVE-2025-32711) was the first widely reported zero-click prompt injection against Microsoft 365 Copilot: a crafted email could cause Copilot to leak data with no user interaction. Microsoft fixed it server-side. Here is what it teaches about AI assistant risk.

Entra ID & IdentityPlatform Changes

Microsoft Entra Agent ID (May 2025): Giving AI Agents Their Own Identities

At Build in May 2025, Microsoft introduced Entra Agent ID, giving AI agents their own identities in the directory. A year later, agents escaping sandboxes made the idea urgent. Here is what Agent ID does and how to govern AI agents like privileged users.

Entra ID & IdentityIncident Teardowns

Marks & Spencer Ransomware (Apr 2025): Scattered Spider Returns to the Help Desk

The April 2025 attack on Marks & Spencer paused online orders for weeks and was expected to cut operating profit by about £300 million. M&S said attackers got in through human error at a third party. Here is the pattern — and how to lock down resets and MFA registration.

AWSIncident Teardowns

The $1.5B Bybit Theft (Feb 2025): A Developer Machine, Stolen AWS Session Tokens and a Poisoned S3 Asset

The $1.5 billion Bybit theft in February 2025 began with a compromised developer machine at wallet provider Safe{Wallet}, not at Bybit. Attackers altered the web interface Bybit's signers trusted. Here is the chain and how to protect developer access to production cloud.

AWSIncident Teardowns

Codefinger (Jan 2025): Ransomware That Encrypts S3 Buckets With AWS's Own SSE-C

In January 2025, the Codefinger campaign encrypted Amazon S3 data using AWS's own SSE-C feature and stolen keys — no malware involved. AWS has since disabled SSE-C by default for new buckets. Here is how it worked and how to make S3 data recoverable.

AzurePlatform Changes

Mandatory MFA for the Azure Portal Begins (Oct 2024)

From October 15, 2024, Microsoft began enforcing MFA for the Azure portal, Entra admin center and Intune admin center, and from 2025 for Azure CLI, PowerShell and infrastructure-as-code tools. Here is what it covers, what breaks, and how to migrate automation to workload identities.

Microsoft 365Platform Changes

Microsoft 365 Copilot Wave 2 (Sept 2024): New Oversharing Controls in SharePoint

On September 16, 2024, Microsoft announced Copilot Wave 2 — Pages, agents and more — alongside tools to tackle the oversharing that stalled many pilots. Here is what changed and a practical playbook for scaling Copilot safely.

Multi-CloudIncident Teardowns

The CrowdStrike Outage (July 19, 2024): 8.5 Million Windows Machines Down

On July 19, 2024, a faulty CrowdStrike content update crashed about 8.5 million Windows devices. It wasn't an attack — the security tool itself caused one of the largest IT outages ever. Here is what happened and how to prepare for mass endpoint failure.

Multi-CloudIncident Teardowns

Snowflake Customer Breaches (May–June 2024): Stolen Credentials, No MFA, 165 Companies

In 2024, a financially motivated actor stole data from about 165 organizations' Snowflake accounts using credentials taken by infostealer malware — some years old, none protected by MFA. Snowflake itself wasn't breached. Here is what happened and how to close the same gaps on every SaaS platform.

Entra ID & IdentityPlatform Changes

Passkeys in Microsoft Authenticator Preview (May 2024): Phishing-Resistant MFA for Everyone

In May 2024, Microsoft previewed device-bound passkeys in Microsoft Authenticator for Entra ID — making phishing-resistant MFA possible on phones employees already carry. Here is how passkeys work, why they defeat modern phishing kits, and how to roll them out.

Multi-CloudIncident Teardowns

Change Healthcare (Feb 2024): A Citrix Portal Without MFA and a Health System Outage

Attackers used stolen credentials on a Citrix portal without MFA to reach Change Healthcare, then deployed ransomware that disrupted US healthcare for weeks. About 192.7 million people were affected. Here is the timeline and the controls that would have stopped it.

Microsoft 365Incident Teardowns

Midnight Blizzard Breaches Microsoft (Jan 2024): A Legacy Test Tenant and an OAuth App

In January 2024, Microsoft disclosed that Midnight Blizzard read email of its senior leaders. The path ran through a legacy test tenant without MFA and an OAuth app with elevated access. Here is the chain and how to find the same risks in your tenant.

Microsoft 365Platform Changes

Microsoft 365 Copilot Goes GA for Enterprise (Nov 2023): The Oversharing Problem Arrives

Microsoft 365 Copilot reached enterprise general availability on November 1, 2023. It respects existing permissions — which is exactly the problem in tenants with years of oversharing. Here is how Copilot uses your data and how to prepare.

AzureIncident Teardowns

Microsoft AI Researchers Expose 38TB via an Overly Permissive SAS Token (Sept 2023)

A single Azure SAS token in a public GitHub repository exposed 38TB of Microsoft data, including 30,000+ Teams messages, for nearly three years. Here is the timeline, why SAS tokens are hard to govern, and how to remove the risk.

Entra ID & IdentityIncident Teardowns

MGM Resorts and Scattered Spider (Sept 2023): A Help Desk Call That Cost $100 Million

A phone call to MGM's help desk reportedly led to a ten-day disruption and about $100 million in lost earnings. Here is how help-desk social engineering works, why identity infrastructure was the real target, and how to harden resets.

Microsoft 365Incident Teardowns

Storm-0558 (July 2023): A Stolen Signing Key and Forged Tokens Into Government Email

In 2023, a China-based actor used a stolen Microsoft consumer signing key to forge tokens and read government email. A customer caught it because it had detailed audit logs. Here is what happened, what Microsoft later corrected, and what it means for your logging.

Multi-CloudIncident Teardowns

MOVEit Transfer (May–June 2023): One File-Transfer Zero-Day, Thousands of Victims

In May 2023, the CL0P gang exploited a zero-day in MOVEit Transfer and stole data from thousands of organizations without encrypting anything. Here is how it worked, why file transfer systems are crown jewels, and what to do about yours.

AWSIncident Teardowns

The AWS us-east-1 Outage of October 2025: DNS, DynamoDB and a Day of Downtime

On October 20, 2025, AWS's US-EAST-1 region suffered a major outage that disrupted a wide range of services — from banking and gaming apps to smart home...

AWSHow-To & Hardening

How to Reduce Your Dependence on a Single AWS Region's Control Plane

Many AWS workloads depend on US-EAST-1 more than their owners realize. Here is how to reduce dependence on a single region's control plane.

AWSHow-To & Hardening

Region Failure Readiness Checklist for AWS Workloads

Use this checklist to check whether an AWS workload is ready for a regional failure.

AWSCIO Briefings

CIO Brief: Cloud Concentration Risk Is Back on the Board Agenda

The short version: On October 20, 2025, an AWS outage in its busiest region disrupted banks, airlines, games and smart home devices for most of a day. It...

Page 1 of 20Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.