ChaosDB (Aug 2021): A Cosmos DB Flaw Exposed Thousands of Azure Customers' Keys
In August 2021, researchers at Wiz disclosed ChaosDB, a vulnerability in Microsoft Azure Cosmos DB that could have allowed an attacker to obtain the primary...
Insights
News, breach teardowns, how-to guides, detections and CIO briefings for Microsoft 365, Entra ID, Azure, AWS and AI agents.
In August 2021, researchers at Wiz disclosed ChaosDB, a vulnerability in Microsoft Azure Cosmos DB that could have allowed an attacker to obtain the primary...
Cosmos DB primary keys grant full access to a database. ChaosDB showed how damaging a leaked key can be. Here is how to rotate keys and move to Entra ID...
Database keys and connection strings, once leaked, are used like legitimate access. Monitoring data plane activity helps you spot misuse.
The short version: In 2021, researchers found a flaw in one of Microsoft's own Azure database services that could have let attackers access thousands of...
In August 2021, details emerged of ProxyShell, a chain of three vulnerabilities in on-premises Microsoft Exchange Server. Security researcher Orange Tsai...
When a critical vulnerability is exploited in the wild, normal monthly patching is too slow. Here is how to build an emergency patching process for...
Remote code execution against Exchange servers leaves traces in IIS logs, process activity and the file system. These detections complement patching.
The short version: In 2021, a second wave of attacks hit company-run Microsoft Exchange email servers, months after the first. Patches had been available...
In August 2021, UpGuard researchers disclosed that about 38 million records were exposed through Microsoft Power Apps portals belonging to 47 organizations,...
Power Platform lets anyone build apps, flows and now AI agents. Without governance, data can leak through connectors, public portals or overshared apps....
Low-code apps and portals can expose data without anyone noticing. These detections help surface risky configurations and unusual data access in Power Platform.
The short version: In 2021, about 38 million records — including vaccination data and Social Security numbers — were exposed through websites built with...
On July 2, 2021 — the start of a US holiday weekend — the REvil ransomware group exploited a zero-day vulnerability in Kaseya VSA, a remote monitoring and...
Managed service providers often have broad administrative access to customer Microsoft 365 tenants. Here is how to restrict and monitor that access.
MSP supply-chain attacks use legitimate management tools and access. Detection focuses on unusual use of those tools and partner accounts.
The short version: In 2021, ransomware spread through Kaseya — software that IT service providers use to manage their clients' computers — reaching up to...
On May 7, 2021, Colonial Pipeline — which carries a large share of the fuel supply for the US East Coast — shut down its pipeline operations after a...
Colonial Pipeline and Change Healthcare were both breached through remote access accounts without MFA. Here is how to find accounts and access paths that...
Sign-ins without MFA to remote access systems are a leading ransomware entry point. These detections highlight them.
The short version: In 2021, Colonial Pipeline shut down fuel deliveries across the US East Coast after ransomware. The attackers got in through one old...
On May 12, 2021, President Biden signed Executive Order 14028, Improving the Nation's Cybersecurity, in response to SolarWinds, Microsoft Exchange...
"Zero trust" can sound abstract. In practice, it means verifying every access request based on identity, device and context — and limiting what each request...
Use this self-assessment to estimate your zero trust maturity across five pillars. Score each item: 0 = not started, 1 = partial, 2 = complete.
The short version: In 2021, a US executive order made "zero trust" official federal policy and required multi-factor authentication, encryption and better...