Release Date: 26/07/2026 | Issue: 348
Know someone who'd find this useful? Forward this email
CloudSecList is a newsletter for busy professionals who want to keep up to date with the cloud security industry. Hand-curated by Marco Lancini.
Sponsor

The enterprise deal is ready. Is your SOC 2?

The fastest-growing startups get compliant early. That's where Vanta comes in. Used by over 16,000 companies like Ramp, Cursor, and Harvey, Vanta helps you get audit-ready quickly โ€” and stay that way. Don't let compliance be the reason a deal slips.
Sign up with Vanta and get audit-ready in weeks, not months.

Sign up

This week's articles


CISO's guide to agentic AI
Anthropic's Deputy CISO shares a four-question framework for assessing agentic AI risk, and walks through controls that keep agent deployments bounded and auditable.


HuggingFace Security incident disclosure
An autonomous AI agent exploited two RCE paths in HuggingFace's dataset processing pipeline, escalated to cluster level, harvested credentials, and moved laterally. Defense forensics used self-hosted GLM 5.2 after commercial APIs were blocked by safety guardrails. You can also read OpenAI's post on this.


Comparing Open-Source AI Code Security Harnesses
A guide to open-source AI tools for finding code vulnerabilities, comparing exploit generation, skill-boosted auditing, and SAST+LLM hybrid approaches.


Delegated authority, running locally: Give an agent on your machine an identity you can trust
A reference architecture for giving a locally-running AI agent a trustworthy, auditable identity, without long-lived credentials on disk, including a structural defense against prompt injection built into the protocol layer.


Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking
Two chained bugs in Google's OAuth device code flow: transferable sign-in sessions via URL, and missing server-side client_id/scope binding to device_code. Combined with prompt=none, any victim opening one link silently yields tokens for arbitrary Google-registered clients, including Gmail.


Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign
Attackers compromised a PHP developer's GitHub repos, injecting 583 malicious Actions workflows across 10 Packagist packages. These workflows used GitHub-hosted runners to exploit CVE-2026-41940 (cPanel/WHM auth bypass) and exfiltrate server credentials.


New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs
A study of ~200,000 LLM responses found 5 frontier models (Claude, GPT, Gemini, DeepSeek) hallucinate nonexistent package names at 4.62-6.10%, with 53 shared fictitious names on PyPI/npm still registrable and exploitable via slopsquatting attacks.

Sponsor

We broke (and fixed) Claude Code, Apple WebKit, and OpenClaw - you next?

Apex is Cantina's agentic OffSec engineer. Point it at any target and it hunts critical vulns the way a real adversary would. We're handing it to friends of CloudSecList on the house ๐Ÿ . Only 15 slots, first come, first served.
See what kinda shape your in vs Mythos mayhem, request your spot ASAP!

Request your spot โžก๏ธ

Tools


cloudshell-boto3
Cloudshell boto3 hidden API.


zeedumper
Zeedumper connects to a Kubernetes cluster using your kubeconfig and dumps component z-pages (flagz, statusz, and configz) retrieving them through the API server proxy. You can also check out the companion blog post.


iron-proxy
An egress firewall for untrusted workloads.

From the cloud providers


#AWS   Introducing the Amazon GuardDuty investigation agent: on-demand AI-powered threat assessment
Amazon GuardDuty investigation agent (public preview) uses AI to auto-investigate GuardDuty security findings, reducing investigation time from hours to minutes. It returns risk levels, confidence scores, MITRE ATT&CK mappings, and remediation steps via console, CLI, API, or AWS MCP server.


#AWS   Introducing Claude apps gateway for AWS
Amazon announced the Claude apps gateway for AWS, a self-hosted control plane that gives organizations a single point of control over access, cost, and policy for Claude Code and Claude Desktop.

Thanks for reading!

If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! ๐Ÿ‘Œ

If you have questions, comments, or feedback, let me know on Twitter (@lancinimarco / @CloudSecList), or at feedback.cloudseclist.com!

Thanks,
Marco
Forward Forward
Twitter Tweet
Share Share

How did you like this issue of CloudSecList?

1       2       3       4       5

Archives View in browser Sponsorship
ยฉ 2019-present CloudSecList ยท Marco Lancini