This week's articles
The Agent Access Model
Cloudflare's Agent Access Model (AAM) proposes a zero-trust architecture for AI agents using short-lived task-scoped credentials, harness/network-layer enforcement, a stateful Trust Ratchet that irreversibly narrows capabilities upon protected data access, and an activity log for least-privilege grant review.
How We Secure Figmaโs Internal Systems With Agents
Figma's security team built an agentic system on AWS Bedrock, Kendra, and Tines that triages SIEM alerts, queries a Snowflake security data lake, and opens remediation PRs. It uses RAG-based case memory, behavioral steering memory, and self-built procedural schema memory, achieving a 71% reduction in alert time-to-resolution.
How Cloudflare enforces engineering standards using AI
Cloudflare built the Codex, a governed RFC-based body of engineering standards consumed by AI agents to enforce consistency across code reviews (230,000 violations flagged, 16,000 merges blocked), spec reviews, and incident report reviews throughout the development lifecycle.
Investigating Persistence Mechanisms in AWS
Rapid7 Labs details four AWS persistence techniques used by attackers: rogue IAM user creation, backdoored assume role policies granting external account access, malicious Lambda functions provisioning privileged users, and federated user sessions that survive key rotation. Includes LEQL detection queries and remediation steps.
CosmosEscape: Taking Over Every Azure Cosmos DB
Wiz Research found CosmosEscape, a critical vulnerability in Azure Cosmos DB's Gremlin API enabling sandbox escape via .NET reflection. Attackers could obtain a platform-wide Cosmos Master Key granting full read/write access to any customer database and enumeration of all accounts.
keyv and cacheable npm Package Hijacked in Supply Chain Attack
A compromised GitHub maintainer account led to malicious versions of keyv and related npm packages being published, spreading Shai-Hulud-family malware to over 400 packages. The payload steals cloud, developer, and crypto credentials, uses an Ethereum smart contract for C2 retrieval, and establishes IDE persistence.
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
Unit 42 discloses three novel attacks (Pass-ta-key, Silver, Golden) against Google synced passkeys on Windows. Endpoint malware can silently authenticate, forge UV flag verification by registering attacker-controlled keys, or extract the plaintext security domain secret from Chrome memory to decrypt all synced passkey private keys.
|
|
Sponsor
We broke (and fixed) Claude Code, Apple WebKit, and OpenClaw - you next?
Apex is Cantina's agentic OffSec engineer. Point it at any target and it hunts critical vulns the way a real adversary would. We're handing it to friends of CloudSecList on the house ๐ . Only 15 slots, first come, first served. See what kinda shape you're in vs Mythos mayhem, request your spot ASAP!
Request your spot โก๏ธ
|
|
|
Tools
computer
A SQLite-backed virtual filesystem in a Durable Object, exposing pluggable execution via container (FUSE), isolate shell, or isolate JavaScript backends.
cloudflare-os
Agent workspace built on Cloudflare Workers for creating documents, building apps, and running agents with your company's context and systems.
open-code-review
Open-source AI code review CLI (ocr) using a hybrid LLM agent + deterministic pipeline, with line-level comments, built-in rulesets, and OpenAI/Anthropic support.
pangolin
Identity-aware VPN and tunneled reverse proxy for remote access based on WireGuard.
ADR
ADR (Agentic Detection and Response) captures AI agent telemetry (prompts, tool calls, MCP activity, reasoning traces) to detect credential exposure, prompt injection, and data exfiltration. Deployed at Uber.
|
|
From the cloud providers
#AWS
HIPAA Security Rule on AWS
AWS released a whitepaper guiding covered entities and business associates on implementing HIPAA Security Rule Technical Safeguards on AWS, covering access control, audit, MFA, encryption, and 2025 NPRM proposed changes, with shared responsibility mapping and ePHI architecture guidance.
#GCP
Cloud CISO Perspectives: Why AI Threat Defense is the new boardroom baseline
Google Cloud CISO Chris Betz argues that AI-native threat defense is now a board-level requirement. Boards should govern five areas: business enablement, remediation cycle speed, platform consolidation, contextual vulnerability prioritization, and AI safety policy to enable secure, AI-driven business agility.
|
|
Thanks for reading!
|
If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! ๐ If you have questions, comments, or feedback, let me know on Twitter ( @lancinimarco / @CloudSecList), or at feedback.cloudseclist.com! Thanks, Marco
|
|
|