Release Date: 02/08/2026 | Issue: 349
Know someone who'd find this useful? Forward this email
CloudSecList is a newsletter for busy professionals who want to keep up to date with the cloud security industry. Hand-curated by Marco Lancini.
Sponsor

The frenemies conundrum: CTOs, CISOs, and CIAM

AI adoption is outrunning the identity layer. CTOs and CISOs know it, they just measure the gap differently. In this on-demand session, Eve Maler (author of Mastering Digital Identity, founder of Venn Factory, longtime UMA and OAuth contributor) joins FusionAuth's Dan Moore to name the "frenemies conundrum" โ€” where product, security, and IT fight over identity ownership, why the KPIs never align, and what responsible AI adoption actually demands from CIAM infrastructure.

Watch on-demand โ†’

This week's articles


How Figma Stays Ahead of Vulnerabilities With Agents
For the past year, agents at Figma have guarded code as it's written, reviewed every pull request, and audited a decade-old monorepo, all on one policy.


Structural desynchronization in Gmail and Gemini: a fabricated inbox and real email content exfiltrated from Gmail into a shared Calendar
A single crafted email makes Gemini reconstruct fabricated inbox entries as real, then an embedded directive drives an autonomous Calendar event that exfiltrates content from a genuine inbox message into a shared Calendar event visible to colleagues. It arrives looking like indirect prompt injection, but the mechanism underneath both effects is structural desynchronization, and the fabrication half involves no instruction at all.


AI Worming through Word
A coordinated disclosure with MSRC demonstrating a document-borne AI worm in Microsoft Copilot for Word: hidden XPIA prompts in source documents cause Copilot to alter generated content and self-propagate the malicious instructions into downstream documents.


A Security Analysis of Amazon S3 Vectors and Its Use in LLM Retrieval Pipelines
An analysis of the security model of Amazon S3 Vectors and of the considerations that arise when it is used as the retrieval layer for LLM applications: access control scope, input validation, metadata integrity, and audit coverage.


Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
A companion technical writeup to HunggingFace's incident disclosure from last week. This post walks through how the intrusion actually worked: the two initial-access vectors, how the agent pivoted and moved laterally, representative examples of the commands that were run and how they investigated with GLM 5.2.


Inside the OpenClaw Ecosystem: What Happens When AI Agents Get Credentials to Everything
Permiso researchers deployed an AI agent (Rufio) into the OpenClaw ecosystem and found active malware campaigns in its unvetted skill marketplace (ClawHub), credential-harvesting skills with 377+ downloads, C2 infrastructure, and prompt injection attacks targeting agents holding plaintext credentials to email, Slack, and file systems.


Least privilege for AI agents: Identity, access, and tool binding
AI agents acting as autonomous multi-system actors require dedicated managed identities, least-privilege task-scoped RBAC, explicit tool allowlists, JIT time-limited entitlements, downstream re-authorization per call, and end-to-end audit logs capturing identity, role, scope, and correlation IDs.

Sponsor

An identity-driven alternative to legacy VPN and bastion access

VPNs create friction and rely on IP-based tracking. Teleport VNet provides secure, identity-based access to internal TCP applications without legacy VPNs, SSH tunnels, or port forwarding. By validating authenticated identities, RBAC policies, label-based permissions, and session restrictions before proxying connections, Teleport VNet provides greater control and visibility. VNet also supports custom DNS zones, mapping hardcoded domains to virtual IPs locally to prevent broken automation.

See how Teleport VNet is used

Tools


suzaku
A sigma-based threat hunting and fast forensics timeline generator for cloud logs.


terraform-plan-tui
A Terminal UI for Terraform Plans.


nono
A secure, kernel-enforced capability sandbox for AI agents.


pvcli
A curl-like client for a privacy proxy. You can also check out the companion blog post.

Thanks for reading!

If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! ๐Ÿ‘Œ

If you have questions, comments, or feedback, let me know on Twitter (@lancinimarco / @CloudSecList), or at feedback.cloudseclist.com!

Thanks,
Marco
Forward Forward
Twitter Tweet
Share Share

How did you like this issue of CloudSecList?

1       2       3       4       5

Archives View in browser Sponsorship
ยฉ 2019-present CloudSecList ยท Marco Lancini