The COVID-19 Remote Work Shift (Mar 2020): Teams Sprawl, Guest Access and Shadow IT
In March 2020, the COVID-19 pandemic sent much of the global workforce home almost overnight. Microsoft Teams usage exploded as organizations rushed to keep...
Insights
News, breach teardowns, how-to guides, detections and CIO briefings for Microsoft 365, Entra ID, Azure, AWS and AI agents.
In March 2020, the COVID-19 pandemic sent much of the global workforce home almost overnight. Microsoft Teams usage exploded as organizations rushed to keep...
Teams sprawl and forgotten guest access create real security risk. Here is how to put lightweight governance in place without slowing collaboration.
Guest accounts and broad Teams access can quietly expose sensitive data. These detections highlight risky guest activity and sharing.
The short version: When COVID-19 sent everyone home in 2020, companies opened up collaboration tools as fast as possible. Many never tightened them again....
In March 2020, Amazon Detective became generally available. It helps security teams investigate findings from GuardDuty and other sources by automatically...
Amazon Detective helps you answer the key questions after a GuardDuty finding: is it real, what did the identity do, and how far did it go? Here is a...
A short, consistent runbook helps small teams respond to AWS incidents calmly. Use this as a starting template.
The short version: Security tools generate alerts. The value comes from deciding quickly which ones are real. Amazon Detective, launched in 2020, is one of...
In February 2020, personal details of more than 10.6 million MGM Resorts hotel guests were posted on a hacking forum. MGM confirmed the data came from a...
You can't protect customer data you can't find. Here is a practical approach to classifying and monitoring customer data stores across Azure, AWS and...
Data exposures from cloud servers and databases often go unnoticed until data appears for sale. These detections help you spot exposure and unusual data...
The short version: In 2020, personal details of more than 10 million MGM hotel guests appeared on a hacking forum, from an earlier breach of a cloud server....
In January 2020, Microsoft disclosed that a customer support database containing about 250 million records had been exposed on the internet without password...
A single network rule change exposed a Microsoft database to the internet in 2019. Azure Policy and private endpoints let you prevent that class of mistake...
Exposed databases are often found by internet scanners within hours. Detecting public exposure — and unexpected access — quickly is critical.
The short version: In 2020, Microsoft disclosed that a customer support database had been left exposed to the internet after a network setting change. If...
In December 2019, AWS launched IAM Access Analyzer. It used automated reasoning — mathematical analysis of policies — to identify resources that were shared...
IAM Access Analyzer finds two kinds of risky access: resources shared outside your organization, and permissions nobody uses. Here is how to use both to...
External access to your AWS resources should be known and approved. This quarterly review checklist keeps it that way.
The short version: Companies routinely share cloud resources with vendors and partners. Over time, nobody remembers who has access to what. AWS released a...
On December 31, 2019, foreign exchange company Travelex was hit by Sodinokibi (REvil) ransomware. Its websites and systems went offline for weeks, and banks...
Traditional VPNs give users broad network access once connected and present a constantly targeted appliance on the internet. Zero trust access replaces that...
Attackers exploiting VPN and remote access appliances often look like legitimate users. Detection focuses on suspicious sessions and what happens after them.
The short version: On New Year's Eve 2019, ransomware shut down Travelex's systems for weeks. Attackers reportedly got in through a remote access device...