BlueBleed (Oct 2022): Misconfigured Azure Blob Storage Exposes Microsoft Customer Data
In October 2022, threat intelligence company SOCRadar reported a data leak it called BlueBleed: a misconfigured Microsoft-owned Azure Blob Storage container...
Insights
Articles in Retrospectives.
In October 2022, threat intelligence company SOCRadar reported a data leak it called BlueBleed: a misconfigured Microsoft-owned Azure Blob Storage container...
Azure Storage accounts can be exposed through anonymous blob access, overly permissive shared keys and SAS tokens, or public network endpoints. Here is how...
Public Azure Blob access is often discovered by outsiders scanning for open containers. Detecting both the configuration and anonymous access helps you find...
The short version: In 2022, researchers reported that a misconfigured Microsoft storage location exposed business documents involving Microsoft's customers....
On September 15, 2022, Uber disclosed a network security incident. An attacker had gained access to internal systems including its Slack workspace, cloud...
Contractors and guests often have less oversight than employees but similar access. Conditional Access lets you apply consistent — or stricter — controls....
MFA push bombing generates bursts of MFA requests. Even with number matching, attackers try variations. These detections help catch attempts early.
The short version: In 2022, Uber was breached through a contractor whose password had been stolen and who eventually approved one of many login prompts....
On September 29, 2022, Microsoft confirmed two zero-day vulnerabilities in on-premises Microsoft Exchange Server being exploited in limited, targeted...
Many organizations moved all mailboxes to Exchange Online but kept one Exchange server for recipient management. Microsoft now supports removing it in many...
Even after patching, exploited Exchange servers may still be compromised. These detections focus on post-exploitation behaviors common to ProxyNotShell and...
The short version: In late 2022, a third major wave of attacks hit company-run Microsoft Exchange email servers. Microsoft took about six weeks to release...
In August 2022, researchers at Group-IB described a phishing campaign they named 0ktapus. It targeted employees of more than 130 organizations — many of...
FIDO2 security keys provide phishing-resistant MFA: they won't authenticate to a fake site. Here is how to deploy them in Entra ID for high-risk users.
SMS phishing campaigns like 0ktapus harvest credentials and MFA codes through fake sign-in pages. Detection focuses on the sign-ins that follow.
The short version: In 2022, attackers sent text messages to employees at more than 130 companies, tricking them into entering passwords and MFA codes on...
On July 12, 2022, Microsoft published research on a large-scale adversary-in-the-middle (AiTM) phishing campaign that had targeted more than 10,000...
Adversary-in-the-middle phishing steals session cookies after users complete MFA. Two controls stop it: phishing-resistant authentication and...
AiTM phishing produces a valid session from an attacker's infrastructure. Detection focuses on session anomalies and the business email compromise that...
The short version: In 2022, Microsoft reported a phishing campaign that hit more than 10,000 organizations and got past multi-factor authentication by...
In late May 2022, researchers identified a malicious Word document that executed code without macros. The vulnerability it exploited, nicknamed Follina...
Attack surface reduction (ASR) rules in Microsoft Defender for Endpoint block behaviors commonly used by malware — such as Office apps launching child...
Malicious Office documents remain a top initial access method. Detecting Office applications launching unusual processes catches many techniques, from...
The short version: For years, the main defense against malicious Office documents was blocking macros. In 2022, attackers used a new flaw, Follina, to run...