NewCyngular is now live across AWS, Azure, GCP & on-prem environments — book a demo
Research & Blog

Notes from the agentic SOC

Cloud attack research from the Cyngular team — control-plane abuse, identity-driven intrusions, and the detection gaps that let them hide in plain sight.

AWSApril 20263 min read

Modern cloud attacks don't break in. They log in.

The Vercel breach reflects a fundamental shift: attackers no longer exploit infrastructure vulnerabilities — they exploit trust, and simply operate as the user.

Read article
AzureMarch 2026

Legitimate by Design: The Cyberattack That Looks Like Normal Business

The March 2026 Stryker attack wasn't malware-driven. Attackers abused identity and cloud management systems to execute destructive actions at scale — entirely within expected system behavior.

7 min readRead
AzureDecember 2025

ConsentFix: Abusing Azure OAuth Consent to Take Over Microsoft Accounts

A browser-native phishing technique that compromises Microsoft accounts by abusing legitimate Entra ID OAuth flows — often without capturing passwords, and sometimes without an MFA prompt.

5 min readRead
AWSOctober 2025

The One-Line Backdoor: How a Single EventBridge Rule Becomes an Attacker's Control Channel

A configuration-only persistence mechanism: one EventBridge rule quietly forwards your events to a Lambda in an attacker's account. No malware, no rogue compute — just a line of JSON pointing somewhere you don't control.

8 min readRead
GCPSeptember 2025

Lateral Movement via External GCP Service Accounts

When Service Accounts from outside an organization are granted permissions inside projects, they become a hidden backdoor — effectively trusting another tenant's user with a permanent bridge into your cloud.

4 min readRead
AWSSeptember 2025

Shadow Access in AWS: Federation Attacks with Temporary STS Tokens

Adversaries no longer rely on stealing long-lived AWS keys. They abuse STS GetFederationToken to mint short-lived, high-privilege credentials that appear as legitimate FederatedUser sessions — resilient shadow access that survives key rotations.

8 min readRead

See these attacks stopped in real time

Every intrusion in these write-ups unfolds as a sequence of quiet, legitimate-looking actions. Cyngular's agents connect them into one investigation — before impact.