This week's articles
CISO's guide to agentic AI
Anthropic's Deputy CISO shares a four-question framework for assessing agentic AI risk, and walks through controls that keep agent deployments bounded and auditable.
HuggingFace Security incident disclosure
An autonomous AI agent exploited two RCE paths in HuggingFace's dataset processing pipeline, escalated to cluster level, harvested credentials, and moved laterally. Defense forensics used self-hosted GLM 5.2 after commercial APIs were blocked by safety guardrails. You can also read OpenAI's post on this.
|
|
Sponsor
We broke (and fixed) Claude Code, Apple WebKit, and OpenClaw - you next?
Apex is Cantina's agentic OffSec engineer. Point it at any target and it hunts critical vulns the way a real adversary would. We're handing it to friends of CloudSecList on the house ๐ . Only 15 slots, first come, first served. See what kinda shape your in vs Mythos mayhem, request your spot ASAP!
Request your spot โก๏ธ
|
|
|
Tools
zeedumper
Zeedumper connects to a Kubernetes cluster using your kubeconfig and dumps component z-pages (flagz, statusz, and configz) retrieving them through the API server proxy. You can also check out the companion blog post.
iron-proxy
An egress firewall for untrusted workloads.
|
|
From the cloud providers
#AWS
Introducing Claude apps gateway for AWS
Amazon announced the Claude apps gateway for AWS, a self-hosted control plane that gives organizations a single point of control over access, cost, and policy for Claude Code and Claude Desktop.
|
|
Thanks for reading!
|
If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! ๐ If you have questions, comments, or feedback, let me know on Twitter ( @lancinimarco / @CloudSecList), or at feedback.cloudseclist.com! Thanks, Marco
|
|
|