On this episode we're dissecting a Unit 42 cloud incident response case and highlights from their 2026 Global Incident Response Report. We describe an AWS compromise where a publicly exposed access key enabled attackers to disable and delete CloudTrail, create a new elevated IAM user, and launch GPU-heavy EC2 instances for crypto mining. This use case frames cloud incidents around IAM issues, misconfigurations, and vulnerabilities, citing stats on slow remediation, weak MFA enforcement, excessive permissions, and exposed credentials, and warns attackers are accelerating to exfiltration in about 72 minutes. On the episode we make some recommendations about phishing-resistant MFA, least privilege and just-in-time admin, tamper-resistant centralized logging, DevSecOps guardrails, SaaS/OAuth inventory, and automated containment, and offer a readiness review and 90-day plan via ATP Gov and Unit 42.
00:00 Real Cloud Compromise Setup
01:19 Unit 42 Case Breakdown: How the Attack Unfolded
02:47 Root Causes and Key Stats
03:48 What It Means for Federal DOD
04:30 Attack Speed and Identity Trends
06:03 Priority Defensive Actions
07:47 Implementation Playbook
09:20 Bottom Line Takeaways
10:19 How to Get Help and Wrap Up
This episode is brought to you by ATP Gov. Visit us online at www.atpgov.com or follow us on LinkedIn.
No comments yet. Be the first to say something!