CloudBreach
@cloud_breach
๐ฉ๏ธ Empowering You to Defend Against Cloud Breaches ๐ฉ๏ธ
ID: 1478753923263614977
http://cloudbreach.io/ 05-01-2022 15:43:39
597 Tweet
3,3K Takipรงi
66 Takip Edilen
๐๐ Cybersecurity Awareness Month is here ๐๐ A huge THANK YOU to our amazing sponsors of 2025 who enabled us to bring Cloud Village across conferences like DEF CON RSAC BSidesCharm BSidesSF and Out Of The Box Security Conference ๐ Your support empowers our talks, workshops, CTFs & labs and
โ๏ธ Cloud under fire: #Microsoftโs 2025 Digital Defense Report shows a surge in cloud-focused #cyberattacks ๐ฅ ๐ฅ +87% rise in destructive campaigns on Azure ๐งฉ 40% of ransomware now hybrid (cloud + on-prem) ๐ต๏ธโโ๏ธ OAuth & identity abuse increasing ๐ Non-human identities = new weak
๐ ๏ธ๐งฐ NoPrompt by NotSoSecure | Part of Claranet Cyber Security - #Azure CAP testing tool ๐ Checks for password-only access to Microsoft Entra ID / Azure AD (MFA gaps) ๐ Simulates OAuth2 & web logins across multiple device user-agents ๐งฉ Tests Microsoft Graph, AAD Graph, and Service Management APIs โ๏ธ
โ ๏ธ๐ฉ๏ธ Microsoft SharePoint Online attacks on the rise! ๐ฃ Adversaries abuse: ๐ธ Power Automate โ stealthy exfiltration ๐ธ OAuth & Graph โ persistence ๐ธ Guest links โ lateral movement ๐ก๏ธ Defend by: ๐ซ Disabling anonymous sharing ๐ Reviewing Power Automate flows โ Auditing
๐๐พ 4TB SQL backup exposed online by EY ๐ฑ Even the Big Four โ proof that no org is too big for a simple cloud misconfig to burn them ๐ Key takeaways: ๐ Discovered by NeoSecurity ๐๏ธ Full MSSQL .bak file publicly accessible ๐ Contained schema, customer, financial and