Release Date: 07/09/2025 | Issue: 304
Know someone who'd find this useful? Forward this email
CloudSecList is a newsletter for busy professionals who want to keep up to date with the cloud security industry. Hand-curated by Marco Lancini.
Sponsor

Inside MCP Security: A Research Guide on Emerging Risks

The Model Context Protocol (MCP) is quickly emerging as the go-to standard for connecting LLMs to external tools and data. Thousands of MCP servers are already live, but as adoption picks up, many teams are implementing MCP without a clear security playbook. This new guide shares early research and practical guidance to help security teams evaluate and secure MCP in real-world environments.

Download the guide to get smart on securing MCP as adoption grows.

This week's articles


Zero-Click Remote Code Execution: Exploiting MCP & Agentic IDEs
How a zero-click MCP attack turns a shared Google Doc into remote code execution, stolen secrets, and enterprise-wide compromise.   #attack   #gsuite   #ai


Sandboxed to Compromised: Credential Exfiltration Paths in AWS Code Interpreters
The article discusses security vulnerabilities in AWS Code Interpreters, particularly focusing on sandboxed environments, and demonstrates that even sandboxed interpreters can access certain AWS services like S3, and their role credentials can be extracted through the Metadata Service.   #aws   #attack   #iam


Subverting code integrity checks to locally backdoor Signal, 1Password, Slack, and more
A vulnerability in Electron applications allows attackers to bypass code integrity checks by tampering with V8 heap snapshot files, enabling local backdoors in applications like Signal, 1Password, and Slack.   #attack   #supply-chain   #saas


The impact of the Salesloft Drift breach on Cloudflare
An advanced threat actor, GRUB1, exploited the integration between Salesloft's Drift chat agent and Salesforce to gain unauthorized access to Salesforce tenants of Cloudflare and many other companies.   #attack   #cloudflare   #saas   #supply-chain


A Primer on Forensic Investigation of Salesforce Security Incidents
Learn how to detect, investigate, and respond to Salesforce security incidents with logs, permissions, and backups.   #saas   #defend   #monitor


A Salesforce Admin’s Guide to Auditing Connected Apps
In the wake of recent attacks, it's crucial that Salesforce Admins everywhere review their Connected Apps.   #monitor   #saas


Drift Breach Tracker
Up-to-date list of organizations impacted by the Salesloft Drift OAuth token compromise targeting Salesforce customers, with links to official statements.   #saas   #monitor   #defend


Sliding into your DMs: Abusing Microsoft Teams for Malware Delivery
Malware delivery through Microsoft Teams is an emerging threat. Discover how attackers exploit external chats, which regions they target, and key IOCs defenders must track.   #attack   #defend   #monitor   #saas


Malicious Go Module Disguised as SSH Brute Forcer Exfiltrates Credentials via Telegram
A malicious Go module posing as an SSH brute forcer exfiltrates stolen credentials to a Telegram bot controlled by a Russian-speaking threat actor.   #attack   #supply-chain


Illicit Consent-Granting & App Backdooring – Obtaining persistence in Entra
This article details how attackers exploit Entra ID through OAuth consent injection and app backdooring, covering attack flows, MITRE ATT&CK mappings, detection strategies, and prevention methods for maintaining persistence in Azure environments.   #attack   #azure   #iam   #defend

Advance Your Cloud Security Career

Want to break into Cloud Security or move up fast?
πŸ“™ The CloudSec Engineer gives you straight-to-the-point, no-BS career advice based on real-world experience. From landing your first role to securing senior and leadership positions, this book helps you navigate the path with practical insights, proven strategies, and bonus tools to track your learning and ace interviews.

Get the guide that works

Tools


gandalf
Gandalf is a hacking simulator game, which challenges you to break and exploit AI agents in realistic scenarios from multiple angles. Each scenario simulates how a real-world Agentic GenAI application behaves.


mcp-audit-extension
Audit and log all GitHub Copilot MCP tool calls in VSCode with ease.


Saas Event Maturity Matrix
A web application to display data from the event-maturity-matrix framework.


windows
Windows inside a Docker container.


timesketch
Collaborative forensic timeline analysis.

From the cloud providers


#AWS   Use scalable controls to help prevent access from unexpected networks
AWS has introduced three new global condition keys for scalable access controls based on request origin: aws:VpceAccount, aws:VpceOrgPaths, and aws:VpceOrgID.


#AZURE   Cloud forensics: Why enabling Microsoft Azure Storage Account logs matters
Although often overlooked, Azure Storage logs can provide invaluable insights for digital forensics, helping investigators reconstruct attacker activity, trace data access patterns, and detect anomalies.

Thanks for reading!

If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! πŸ‘Œ

If you have questions, comments, or feedback, let me know on Twitter (@lancinimarco / @CloudSecList), or at feedback.cloudseclist.com!

Thanks,
Marco
Forward Forward
Twitter Tweet
Share Share

How did you like this issue of CloudSecList?

1       2       3       4       5

Archives View in browser Sponsorship
Β© 2019-present CloudSecList Β· Marco Lancini