Uber's Hidden Breach (Disclosed Nov 2017): AWS Keys in a Private GitHub Repo
In November 2017, Uber disclosed that a year earlier attackers had stolen personal data on about 57 million riders and drivers, including the driver's...
Insights
News, breach teardowns, how-to guides, detections and CIO briefings for Microsoft 365, Entra ID, Azure, AWS and AI agents.
In November 2017, Uber disclosed that a year earlier attackers had stolen personal data on about 57 million riders and drivers, including the driver's...
Long-lived AWS access keys in source code have caused breaches at companies of every size, from Uber in 2016 to the extortion campaigns of the 2020s. Here...
Leaked AWS access keys are often used within minutes of exposure. Detecting misuse quickly limits how much an attacker can do.
The short version: Uber's 2016 breach began with cloud passwords left in a code repository. What made it infamous was the cover-up: the company paid the...
In November 2017, UpGuard researchers found three Amazon S3 buckets configured for public access that contained billions of social media posts collected as...
AWS Config continuously evaluates resource settings against rules. For S3, a handful of rules catches most of the misconfigurations behind past data...
Most S3 misconfigurations begin with a configuration change. Monitoring those changes in near real time catches exposures within minutes rather than months.
The short version: In 2017, cloud storage tied to US military programs was found open to the public. If defense organizations can make this mistake, any...
At re:Invent in November 2017, AWS launched Amazon GuardDuty, a managed threat detection service. With one click, it began analyzing an account's activity...
Amazon GuardDuty should be enabled in every account and every region you use. With AWS Organizations, you can do that in an afternoon. Here is how.
GuardDuty generates findings; your team turns them into decisions. This runbook gives small security teams a consistent way to triage GuardDuty findings.
The short version: Amazon GuardDuty, launched in 2017, watches your AWS accounts for signs of attack and costs relatively little. The decision is not really...
In September 2017, Equifax disclosed that attackers had stolen personal data on about 147 million people, including Social Security numbers, birth dates and...
Equifax was breached through a known vulnerability in a web framework that had a patch available for two months. A vulnerability management program makes...
Exploitation of public-facing web applications is one of the most common ways attackers get in. Detecting exploitation attempts — and especially successful...
The short version: Equifax lost data on about 147 million people in 2017 because a known software flaw went unpatched for months, and monitoring that should...
In September 2017, The Guardian reported that Deloitte, one of the world's largest accounting and consulting firms, had suffered a breach of its global...
Global Administrators can change every setting, read every mailbox and create new admins in Microsoft 365. Protecting those accounts is the highest-value...
Compromised administrator accounts give attackers control of an entire Microsoft 365 tenant. Detecting unusual admin behavior early is one of the...
The short version: Deloitte's 2017 email breach reportedly started with one administrator account protected only by a password. Admin accounts are the keys...
In August 2017, AWS launched Amazon Macie, a service that used machine learning to discover, classify and protect sensitive data stored in Amazon S3. It...
Amazon Macie scans S3 buckets for sensitive data such as names, financial information and credentials. Here is how to run it effectively without a surprise...
Use this checklist before and after enabling Amazon Macie to get value quickly while keeping costs predictable.
The short version: In 2017, AWS released Macie, a tool that finds sensitive data like customer records hidden in cloud storage. Its premise is simple and...