Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

Retrospectives

Articles in Retrospectives.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
Entra ID & IdentityDetection & Response

Detecting Help Desk MFA Reset Abuse: Entra Sign-In Logs and Sentinel KQL

After help desk social engineering, attackers typically reset MFA, register their own method and sign in. These detections connect those events.

Entra ID & IdentityCIO Briefings

CIO Brief: Retail Lessons From a £300 Million Cyber Attack

The short version: In 2025, attackers reportedly tricked an IT help desk into resetting access, then shut down Marks & Spencer's online store for weeks. The...

Multi-CloudIncident Teardowns

tj-actions/changed-files Compromise (Mar 2025): A GitHub Action Leaks CI Secrets

On March 14, 2025, security researchers discovered that tj-actions/changed-files, a popular GitHub Action used in tens of thousands of repositories, had...

Multi-CloudHow-To & Hardening

How to Pin and Allowlist GitHub Actions in Cloud Deployment Pipelines

The tj-actions compromise showed that referencing GitHub Actions by tag lets an attacker change your pipeline without touching your code. Here is how to pin...

Multi-CloudDetection & Response

Detecting GitHub Actions Supply Chain Attack: Sentinel and GuardDuty Detections

Supply-chain attacks on CI/CD dependencies often reveal themselves in workflow behavior and logs. These detections help spot compromised actions and secret...

Multi-CloudCIO Briefings

CIO Brief: Pipeline Supply-Chain Risk Explained

The short version: In March 2025, a popular add-on used in tens of thousands of software build pipelines was hijacked. It quietly printed companies' secret...

Entra ID & IdentityIncident Teardowns

Oracle Cloud Login Breach Claims (Mar 2025): When the Provider Denies and Customers Rotate

In March 2025, a threat actor using the name "rose87168" claimed to have stolen millions of records from Oracle Cloud's single sign-on (SSO) login...

Entra ID & IdentityHow-To & Hardening

How to Respond When Your Identity or Cloud Provider Is Allegedly Breached

When a credible report claims your identity or cloud provider was breached — but the provider hasn't confirmed it — you still need to act. Here is a...

Entra ID & IdentityDetection & Response

Detecting Cloud SSO Compromise: Entra Sign-In Logs and Sentinel KQL

When an SSO or identity provider is compromised, attackers may use stolen credentials or forged tokens to access connected applications. These detections...

Entra ID & IdentityCIO Briefings

CIO Brief: Acting on Unconfirmed Breach Reports

The short version: In 2025, a hacker claimed to have stolen login data from Oracle's cloud. Oracle denied it; researchers said the evidence looked real....

AWSHow-To & Hardening

How to Protect Developer Workstations and Short-Lived AWS Sessions

The Bybit theft began with a compromised developer machine and stolen AWS session tokens. Here is how to protect developer workstations and limit the value...

AWSDetection & Response

Detecting AWS Session Token Hijacking: CloudTrail, GuardDuty and Athena Queries

Stolen AWS session tokens let attackers act as a legitimate user without signing in. Detection focuses on where and how sessions are used.

AWSCIO Briefings

CIO Brief: Developers Are Privileged Users

The short version: In 2025, North Korean hackers stole about $1.5 billion from crypto exchange Bybit. They didn't attack Bybit directly — they hacked a...

AWSHow-To & Hardening

How to Block SSE-C Usage and Protect S3 With Versioning and Object Lock

Codefinger ransomware encrypted S3 objects with SSE-C keys only the attacker held. Here is how to block SSE-C and make your S3 data recoverable.

AWSDetection & Response

Detecting S3 Ransomware SSE-C: CloudTrail, GuardDuty and Athena Queries

Cloud-native ransomware like Codefinger leaves clear traces in CloudTrail — if you're logging S3 data events and watching for them.

AWSCIO Briefings

CIO Brief: Cloud-Native Ransomware Doesn't Need Malware

The short version: In early 2025, attackers used stolen AWS keys to lock companies' cloud storage files with encryption keys only the attackers had — using...

Multi-CloudIncident Teardowns

US Treasury Breached via a BeyondTrust API Key (Dec 2024)

On December 30, 2024, the US Treasury Department told Congress that a China state-sponsored actor had accessed some Treasury workstations and unclassified...

Multi-CloudHow-To & Hardening

How to Inventory and Rotate API Keys for Remote Support Tools

API keys for remote support and management tools can provide direct access to your devices. Here is how to inventory them and rotate them safely.

Multi-CloudDetection & Response

Detecting Stolen API Key: Sentinel and GuardDuty Detections

Stolen API keys for remote support tools grant access without user sign-ins. These detections focus on unusual key use and remote sessions.

Multi-CloudCIO Briefings

CIO Brief: Remote Support Vendors and Nation-State Risk

The short version: At the end of 2024, Chinese state hackers accessed US Treasury computers through BeyondTrust, a company whose software lets IT staff...

AzurePlatform Changes

Microsoft Ignite 2024: Security Exposure Management and the Windows Resiliency Initiative

At Microsoft Ignite in November 2024, security announcements centered on resilience and exposure. Two stood out: the Windows Resiliency Initiative, a...

AzureHow-To & Hardening

How to Use Attack Path Analysis to Prioritize Cloud Fixes

Not all vulnerabilities and misconfigurations matter equally. Attack path analysis shows which ones an attacker could chain to reach your critical assets....

AzureHow-To & Hardening

Exposure Management Quick-Start Checklist

Use this checklist to start an exposure management program with Microsoft Defender tools.

AzureCIO Briefings

CIO Brief: From Alert Counts to Exposure Management

The short version: Security teams are drowning in alerts and vulnerability lists. In 2024, Microsoft and other vendors pushed a different approach:...

← NewerPage 3 of 20Older →
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.