Release Date: 09/08/2026 | Issue: 350
Know someone who'd find this useful? Forward this email
CloudSecList is a newsletter for busy professionals who want to keep up to date with the cloud security industry. Hand-curated by Marco Lancini.
Sponsor

Building trust in the AI era: Unifying security, risk and privacy
Trust is the defining problem of the AI era. Boards, regulators โ€” even Five Eyes โ€” and customers demand proof of control over security, privacy, and AI risk. See a unified trust program: one picture, one evidence trail, board-ready reporting.
You'll learn how to:
  • Manage security, privacy, and AI risk in one program
  • Move from point-in-time to continuous monitoring
  • Map evidence once for multiple frameworks
  • Strengthen governance with one source of truth
Register to save your spot, or register anyway for the recording.

This week's articles


The Agent Access Model
Cloudflare's Agent Access Model (AAM) proposes a zero-trust architecture for AI agents using short-lived task-scoped credentials, harness/network-layer enforcement, a stateful Trust Ratchet that irreversibly narrows capabilities upon protected data access, and an activity log for least-privilege grant review.


How We Secure Figmaโ€™s Internal Systems With Agents
Figma's security team built an agentic system on AWS Bedrock, Kendra, and Tines that triages SIEM alerts, queries a Snowflake security data lake, and opens remediation PRs. It uses RAG-based case memory, behavioral steering memory, and self-built procedural schema memory, achieving a 71% reduction in alert time-to-resolution.


How Cloudflare enforces engineering standards using AI
Cloudflare built the Codex, a governed RFC-based body of engineering standards consumed by AI agents to enforce consistency across code reviews (230,000 violations flagged, 16,000 merges blocked), spec reviews, and incident report reviews throughout the development lifecycle.


Before the first prompt: Code execution paths in trusted coding-agent projects
Trusted coding-agent projects can execute repository-controlled code before the first user prompt via MCP server configs or PATH hijacking in .claude/settings.json. Developers should treat project trust like running an arbitrary setup script.


Investigating Persistence Mechanisms in AWS
Rapid7 Labs details four AWS persistence techniques used by attackers: rogue IAM user creation, backdoored assume role policies granting external account access, malicious Lambda functions provisioning privileged users, and federated user sessions that survive key rotation. Includes LEQL detection queries and remediation steps.


CosmosEscape: Taking Over Every Azure Cosmos DB
Wiz Research found CosmosEscape, a critical vulnerability in Azure Cosmos DB's Gremlin API enabling sandbox escape via .NET reflection. Attackers could obtain a platform-wide Cosmos Master Key granting full read/write access to any customer database and enumeration of all accounts.


keyv and cacheable npm Package Hijacked in Supply Chain Attack
A compromised GitHub maintainer account led to malicious versions of keyv and related npm packages being published, spreading Shai-Hulud-family malware to over 400 packages. The payload steals cloud, developer, and crypto credentials, uses an Ethereum smart contract for C2 retrieval, and establishes IDE persistence.


Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
Unit 42 discloses three novel attacks (Pass-ta-key, Silver, Golden) against Google synced passkeys on Windows. Endpoint malware can silently authenticate, forge UV flag verification by registering attacker-controlled keys, or extract the plaintext security domain secret from Chrome memory to decrypt all synced passkey private keys.

Sponsor

We broke (and fixed) Claude Code, Apple WebKit, and OpenClaw - you next?

Apex is Cantina's agentic OffSec engineer. Point it at any target and it hunts critical vulns the way a real adversary would. We're handing it to friends of CloudSecList on the house ๐Ÿ . Only 15 slots, first come, first served.
See what kinda shape you're in vs Mythos mayhem, request your spot ASAP!

Request your spot โžก๏ธ

Tools


computer
A SQLite-backed virtual filesystem in a Durable Object, exposing pluggable execution via container (FUSE), isolate shell, or isolate JavaScript backends.


cloudflare-os
Agent workspace built on Cloudflare Workers for creating documents, building apps, and running agents with your company's context and systems.


open-code-review
Open-source AI code review CLI (ocr) using a hybrid LLM agent + deterministic pipeline, with line-level comments, built-in rulesets, and OpenAI/Anthropic support.


pangolin
Identity-aware VPN and tunneled reverse proxy for remote access based on WireGuard.


ADR
ADR (Agentic Detection and Response) captures AI agent telemetry (prompts, tool calls, MCP activity, reasoning traces) to detect credential exposure, prompt injection, and data exfiltration. Deployed at Uber.

From the cloud providers


#AWS   HIPAA Security Rule on AWS
AWS released a whitepaper guiding covered entities and business associates on implementing HIPAA Security Rule Technical Safeguards on AWS, covering access control, audit, MFA, encryption, and 2025 NPRM proposed changes, with shared responsibility mapping and ePHI architecture guidance.


#GCP   Cloud CISO Perspectives: Why AI Threat Defense is the new boardroom baseline
Google Cloud CISO Chris Betz argues that AI-native threat defense is now a board-level requirement. Boards should govern five areas: business enablement, remediation cycle speed, platform consolidation, contextual vulnerability prioritization, and AI safety policy to enable secure, AI-driven business agility.

Thanks for reading!

If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! ๐Ÿ‘Œ

If you have questions, comments, or feedback, let me know on Twitter (@lancinimarco / @CloudSecList), or at feedback.cloudseclist.com!

Thanks,
Marco
Forward Forward
Twitter Tweet
Share Share

How did you like this issue of CloudSecList?

1       2       3       4       5

Archives View in browser Sponsorship
ยฉ 2019-present CloudSecList ยท Marco Lancini