Colonial Pipeline (May 2021): One Legacy VPN Password Without MFA
On May 7, 2021, Colonial Pipeline — which carries a large share of the fuel supply for the US East Coast — shut down its pipeline operations after a...
Insights
Articles in Retrospectives.
On May 7, 2021, Colonial Pipeline — which carries a large share of the fuel supply for the US East Coast — shut down its pipeline operations after a...
Colonial Pipeline and Change Healthcare were both breached through remote access accounts without MFA. Here is how to find accounts and access paths that...
Sign-ins without MFA to remote access systems are a leading ransomware entry point. These detections highlight them.
The short version: In 2021, Colonial Pipeline shut down fuel deliveries across the US East Coast after ransomware. The attackers got in through one old...
On May 12, 2021, President Biden signed Executive Order 14028, Improving the Nation's Cybersecurity, in response to SolarWinds, Microsoft Exchange...
"Zero trust" can sound abstract. In practice, it means verifying every access request based on identity, device and context — and limiting what each request...
Use this self-assessment to estimate your zero trust maturity across five pillars. Score each item: 0 = not started, 1 = partial, 2 = complete.
The short version: In 2021, a US executive order made "zero trust" official federal policy and required multi-factor authentication, encryption and better...
On March 2, 2021, Microsoft released emergency patches for four zero-day vulnerabilities in on-premises Microsoft Exchange Server, collectively known as...
On-premises Exchange servers were exploited repeatedly from 2021 to 2022. If you've moved mailboxes to Exchange Online, you may be able to retire your last...
Exchange Server exploitation typically results in web shells and suspicious processes spawned by IIS worker processes. These are the key detections.
The short version: In 2021, attackers exploited flaws in Microsoft Exchange email servers that companies ran themselves, compromising tens of thousands of...
In March 2021, a group of hackers gained access to Verkada, a cloud-based security camera company, and viewed live feeds from roughly 150,000 cameras at...
Hardcoded credentials in scripts, configuration files and repositories are one of the easiest ways for attackers to escalate. Here is how to find them...
Exposed administrator credentials are often used soon after discovery. Detecting both the exposure and the misuse helps you respond before damage spreads.
The short version: In 2021, hackers accessed about 150,000 security cameras — in hospitals, schools and factories — by finding a single "super admin"...
In January 2021, email security company Mimecast disclosed that a certificate it used to authenticate certain products to Microsoft 365 Exchange Online had...
Third-party applications connected to Exchange Online can read, send or manage mail across your organization. Here is how to review them.
A compromised third-party integration can access your tenant with the app's permissions. These detections focus on unusual behavior by third-party apps.
The short version: In 2021, Mimecast — an email security company — disclosed that a digital certificate its products used to connect to customers' Microsoft...
On December 13, 2020, the world learned that attackers had compromised SolarWinds' Orion network monitoring software and inserted a backdoor — later called...
The SolarWinds attackers used stolen AD FS token-signing certificates to forge SAML tokens (Golden SAML) and access Microsoft 365. Moving authentication...
Golden SAML attacks forge tokens with a stolen AD FS signing certificate, letting attackers sign in to Microsoft 365 as anyone. These detections help...
The short version: In 2020, Russian intelligence hid malicious code inside updates for SolarWinds software used by thousands of organizations. For a smaller...