Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AWSIncident Teardowns

Imperva's Cloud WAF Breach (Aug 2019): A Stolen AWS API Key From an Internal Instance

In August 2019, Imperva, a security company known for its cloud web application firewall (formerly Incapsula), disclosed a data exposure affecting customers...

AWSHow-To & Hardening

How to Replace Long-Lived AWS Access Keys With IAM Roles and Identity Center

Long-lived IAM user access keys are one of the most common causes of AWS breaches. IAM roles and IAM Identity Center provide short-lived credentials...

AWSDetection & Response

Detecting Stolen AWS API Keys: CloudTrail, GuardDuty and Athena Queries

Stolen AWS API keys are frequently used for reconnaissance, data theft and resource abuse. These detections help you spot misuse quickly.

AWSCIO Briefings

CIO Brief: When Your Security Vendor Loses Its Cloud Keys

The short version: In 2019, Imperva — a company that sells security protection — disclosed that customer data was exposed after an attacker stole a cloud...

AWSIncident Teardowns

Capital One (July 2019): SSRF, the EC2 Metadata Service and 100 Million Records

On July 29, 2019, Capital One disclosed a breach affecting about 100 million people in the US and 6 million in Canada. It became the defining cloud breach...

AWSHow-To & Hardening

How to Enforce IMDSv2 and Lock Down EC2 Instance Role Permissions

IMDSv2 protects EC2 instance credentials from server-side request forgery, the technique used in the Capital One breach. Combined with least-privilege...

AWSDetection & Response

Detecting SSRF Metadata Credential Theft: CloudTrail, GuardDuty and Athena Queries

The Capital One attack path — SSRF to the metadata service, then stolen role credentials used to read data — leaves traces in CloudTrail and GuardDuty if...

AWSCIO Briefings

CIO Brief: The $80 Million Fine — What Regulators Expect From Cloud Security

The short version: Capital One's 2019 breach exposed data on about 106 million people. It was caused by a misconfigured firewall combined with a server that...

AWSPlatform Changes

AWS Control Tower Goes GA (June 2019): Guardrails for Multi-Account AWS

In June 2019, AWS Control Tower became generally available. It automated the creation of a secure multi-account AWS environment — a landing zone — with...

AWSHow-To & Hardening

How to Set Up AWS Control Tower With Preventive and Detective Guardrails

AWS Control Tower sets up a governed multi-account environment with guard rails. Here is how to set it up and choose the right controls.

AWSHow-To & Hardening

Control Tower Guardrail Selection Checklist

Control Tower offers hundreds of controls. Use this checklist to choose a practical starting set.

AWSCIO Briefings

CIO Brief: Governance at Scale — Why Control Tower Matters

The short version: AWS Control Tower, released in 2019, sets up your AWS cloud as a well-organized group of accounts with security rules built in. It is the...

AzureIncident Teardowns

BlueKeep (May 2019): Wormable RDP and the Risk of Internet-Exposed Azure VMs

In May 2019, Microsoft patched CVE-2019-0708, a critical vulnerability in Remote Desktop Services that became known as BlueKeep. It affected older Windows...

AzureHow-To & Hardening

How to Replace Public RDP With Azure Bastion and Just-in-Time Access

Exposed RDP and SSH ports are among the most attacked entry points in the cloud. Azure Bastion and just-in-time (JIT) VM access let administrators reach...

AzureDetection & Response

Detecting Exposed RDP Exploitation: Defender for Cloud and Sentinel KQL

Even with patches, exposed RDP invites brute force, credential stuffing and exploitation. Detecting both the exposure and attacks against it is essential...

AzureCIO Briefings

CIO Brief: Exposed Remote Access Is Still the Front Door for Ransomware

The short version: In 2019, Microsoft warned about BlueKeep, a flaw that could let attackers take over older Windows computers through remote desktop...

Microsoft 365Incident Teardowns

Outlook.com Support Agent Account Compromised (Apr 2019): The Help Desk Attack Surface

In April 2019, Microsoft notified some users of its consumer email services — Outlook.com, Hotmail and MSN — that a support agent's credentials had been...

Microsoft 365How-To & Hardening

How to Secure Help Desk and Support Roles in Microsoft 365

Help desk and support staff can reset passwords, change MFA methods and see user data. Here is how to scope those roles tightly in Microsoft 365 and Entra ID.

Microsoft 365Detection & Response

Detecting Help Desk Account Compromise: Defender XDR and Sentinel Hunting Queries

A compromised help desk account — or a manipulated help desk agent — can reset credentials across your organization. Detecting unusual support activity...

Microsoft 365CIO Briefings

CIO Brief: Your Help Desk Is a Target — Protecting Support Workflows

The short version: In 2019, attackers got into Microsoft's consumer email support systems by compromising a single support agent's account. Help desks are...

Microsoft 365Incident Teardowns

Citrix Breached via Password Spraying (Mar 2019): Weak Passwords at Enterprise Scale

In March 2019, Citrix disclosed that the FBI had informed it of a breach of its internal network. The FBI's assessment, according to Citrix, was that...

Microsoft 365How-To & Hardening

How to Use Entra ID Smart Lockout and Identity Protection Against Spraying

Entra ID includes two built-in defenses against password spraying: smart lockout and Identity Protection. Here is how to configure both.

Microsoft 365Detection & Response

Detecting Password Spray Attacks: Defender XDR and Sentinel Hunting Queries

Password spray attacks distribute attempts to avoid detection. Combining Entra ID's built-in detections with your own queries gives you the best chance of...

Microsoft 365CIO Briefings

CIO Brief: Your Security Vendor Can Be Breached — Plan for It

The short version: In 2019, Citrix — a company that sells remote access technology to enterprises — was breached, likely through attackers trying common...

← NewerPage 15 of 20Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.