Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AWSIncident Teardowns

Tesla's Kubernetes Console Cryptojacked (Feb 2018): Exposed Dashboards, Exposed AWS Keys

In February 2018, researchers at RedLock disclosed that attackers had broken into Tesla's cloud environment and used it to mine cryptocurrency.

AWSHow-To & Hardening

How to Secure Kubernetes Dashboards and Cluster Credentials on AWS

An exposed Kubernetes dashboard gave attackers a path into Tesla's cloud in 2018. Here is how to secure Kubernetes management interfaces and cluster...

AWSDetection & Response

Detecting Cryptojacking in Cloud: CloudTrail, GuardDuty and Athena Queries

Cryptojacking — using stolen cloud resources to mine cryptocurrency — is one of the most common outcomes of a cloud compromise. It is also one of the most...

AWSCIO Briefings

CIO Brief: Cryptojacking — The Breach That Shows Up on Your Cloud Bill

The short version: In 2018, attackers broke into Tesla's cloud through an unprotected management console and used its computers to mine cryptocurrency....

Multi-CloudIncident Teardowns

Meltdown and Spectre (Jan 2018): When the CPU Itself Was the Vulnerability

On January 3, 2018, researchers disclosed Meltdown and Spectre, a family of vulnerabilities in the way modern processors execute instructions speculatively....

Multi-CloudHow-To & Hardening

How to Track Hypervisor and Guest Patching for Azure and AWS VMs

When a major vulnerability affects cloud hosts, providers patch the hypervisor — but your virtual machines are still yours to patch. Here is how to track...

Multi-CloudDetection & Response

Patch Verification Queries for CPU Vulnerabilities Across Azure and AWS VMs

Hardware vulnerabilities like Meltdown and Spectre are hard to detect being exploited. The practical detection task is making sure every system actually...

Multi-CloudCIO Briefings

CIO Brief: Shared Responsibility When the Flaw Is in the Hardware

The short version: In 2018, researchers found flaws in nearly every computer processor that could let one program read another's data. Cloud providers had...

AWSIncident Teardowns

Uber's Hidden Breach (Disclosed Nov 2017): AWS Keys in a Private GitHub Repo

In November 2017, Uber disclosed that a year earlier attackers had stolen personal data on about 57 million riders and drivers, including the driver's...

AWSHow-To & Hardening

How to Prevent Hardcoded AWS Keys With Secret Scanning and IAM Roles

Long-lived AWS access keys in source code have caused breaches at companies of every size, from Uber in 2016 to the extortion campaigns of the 2020s. Here...

AWSDetection & Response

Detecting Leaked AWS Access Keys: CloudTrail, GuardDuty and Athena Queries

Leaked AWS access keys are often used within minutes of exposure. Detecting misuse quickly limits how much an attacker can do.

AWSCIO Briefings

CIO Brief: Breach Concealment, Disclosure Laws and the Uber Lesson

The short version: Uber's 2016 breach began with cloud passwords left in a code repository. What made it infamous was the cover-up: the company paid the...

AWSIncident Teardowns

Pentagon Social Media Surveillance Data in Open S3 Buckets (Nov 2017)

In November 2017, UpGuard researchers found three Amazon S3 buckets configured for public access that contained billions of social media posts collected as...

AWSHow-To & Hardening

How to Enforce S3 Guardrails With AWS Config Rules

AWS Config continuously evaluates resource settings against rules. For S3, a handful of rules catches most of the misconfigurations behind past data...

AWSDetection & Response

Detecting S3 Misconfiguration: CloudTrail, GuardDuty and Athena Queries

Most S3 misconfigurations begin with a configuration change. Monitoring those changes in near real time catches exposures within minutes rather than months.

AWSCIO Briefings

CIO Brief: Even Defense Agencies Misconfigure Cloud Storage — Here's Why

The short version: In 2017, cloud storage tied to US military programs was found open to the public. If defense organizations can make this mistake, any...

AWSPlatform Changes

Amazon GuardDuty Launches at re:Invent 2017: Managed Threat Detection for AWS

At re:Invent in November 2017, AWS launched Amazon GuardDuty, a managed threat detection service. With one click, it began analyzing an account's activity...

AWSHow-To & Hardening

How to Enable GuardDuty Across an AWS Organization in One Afternoon

Amazon GuardDuty should be enabled in every account and every region you use. With AWS Organizations, you can do that in an afternoon. Here is how.

AWSHow-To & Hardening

GuardDuty Finding Triage Runbook for Small Security Teams

GuardDuty generates findings; your team turns them into decisions. This runbook gives small security teams a consistent way to triage GuardDuty findings.

AWSCIO Briefings

CIO Brief: Managed Threat Detection — Build vs. Buy for AWS

The short version: Amazon GuardDuty, launched in 2017, watches your AWS accounts for signs of attack and costs relatively little. The decision is not really...

Multi-CloudIncident Teardowns

Equifax (Sept 2017): One Unpatched Apache Struts Server, 147 Million Records

In September 2017, Equifax disclosed that attackers had stolen personal data on about 147 million people, including Social Security numbers, birth dates and...

Multi-CloudHow-To & Hardening

How to Build a Vulnerability Management Program for Cloud-Hosted Apps

Equifax was breached through a known vulnerability in a web framework that had a patch available for two months. A vulnerability management program makes...

Multi-CloudDetection & Response

Detecting Unpatched Web Application Exploitation: Sentinel and GuardDuty Detections

Exploitation of public-facing web applications is one of the most common ways attackers get in. Detecting exploitation attempts — and especially successful...

Multi-CloudCIO Briefings

CIO Brief: What the Equifax Hearings Mean for Executive Accountability

The short version: Equifax lost data on about 147 million people in 2017 because a known software flaw went unpatched for months, and monitoring that should...

← NewerPage 18 of 20Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.