CloudBreach
@cloud_breach
π©οΈ Empowering You to Defend Against Cloud Breaches π©οΈ
ID: 1478753923263614977
http://cloudbreach.io/ 05-01-2022 15:43:39
597 Tweet
3,3K Followers
66 Following
ππ Cybersecurity Awareness Month is here ππ A huge THANK YOU to our amazing sponsors of 2025 who enabled us to bring Cloud Village across conferences like DEF CON RSAC BSidesCharm BSidesSF and Out Of The Box Security Conference π Your support empowers our talks, workshops, CTFs & labs and
βοΈ Cloud under fire: #Microsoftβs 2025 Digital Defense Report shows a surge in cloud-focused #cyberattacks π₯ π₯ +87% rise in destructive campaigns on Azure π§© 40% of ransomware now hybrid (cloud + on-prem) π΅οΈββοΈ OAuth & identity abuse increasing π Non-human identities = new weak
π οΈπ§° NoPrompt by NotSoSecure | Part of Claranet Cyber Security - #Azure CAP testing tool π Checks for password-only access to Microsoft Entra ID / Azure AD (MFA gaps) π Simulates OAuth2 & web logins across multiple device user-agents π§© Tests Microsoft Graph, AAD Graph, and Service Management APIs βοΈ
β οΈπ©οΈ Microsoft SharePoint Online attacks on the rise! π£ Adversaries abuse: πΈ Power Automate β stealthy exfiltration πΈ OAuth & Graph β persistence πΈ Guest links β lateral movement π‘οΈ Defend by: π« Disabling anonymous sharing π Reviewing Power Automate flows β Auditing
ππΎ 4TB SQL backup exposed online by EY π± Even the Big Four β proof that no org is too big for a simple cloud misconfig to burn them π Key takeaways: π Discovered by NeoSecurity ποΈ Full MSSQL .bak file publicly accessible π Contained schema, customer, financial and