The US National Security Agency (NSA) published a security advisory, warning about two techniques abused by threat actors for escalating attacks from local networks to cloud infrastructure. The exploitation occurs after the actors have gained access to a victims on-premises network. The actors exhibit two sets of tactics, techniques, and procedures (TTP) for gaining access to the victim network’s cloud resources, often with a particular focus on organizational email. Cloud tenants must lock down tenant SSO configuration and service principal usage, as well as harden systems that run on-Premises identity and federation services.”]

