This week's articles
The AI-Native SDLC playbook
Anthropic's stage-by-stage playbook for the AI-native SDLC: how teams plan, design, build, test, deploy, and maintain software with Claude.
VMs won't contain cyber-capable agents
GPT-5.6-Cyber, given a QEMU/KVM VM sandbox, escaped three times: exploiting a known kernel CVE, chaining two libslirp vulnerabilities, and finally using four bugs including three 0-days. Standard VMs are insufficient to contain cyber-capable AI agents; Firecracker with minimal attack surface is recommended.
Playing whack-a-mole is losing
Reactive bug-patching (whack-a-mole) is a losing security strategy. Instead of endlessly finding and fixing individual vulnerabilities, security teams should define and enforce system invariants to eliminate entire bug classes, including in the AI-accelerated vulnpocalypse era.
How to evaluate LLMs before production
Practical LLM evaluation lessons from GitHub secret scanning: define product goals and guardrails first, treat offline evaluation as repeatable integration testing, keep eval data close to production, audit labels, use error analysis, and apply LLM-as-judge for human review triage.
The state of email authentication, August 2026
August 2026 census of the top 1M domains: DMARC valid 63.6%, DANE 4.6%, MTA-STS 1.2%, BIMI 2.5%. New finding: only 0.2% of MX servers actually refuse cleartext, despite published policies. DMARC leads at 63.6%.
AI Data Centers Directory
A browsable directory of 83 AI data centers tracked by Epoch AI, covering hyperscale campuses, colocation sites, and AI training facilities across North America, Europe, and Asia. Each entry includes IT power capacity, compute estimates, operator details, satellite imagery, and buildout timelines.
|
|
Sponsor
Different cloud providers, different priorities
If juggling multiple cloud providers wasn't complicated enough, it turns out they don't fail in the same places. Intruder's new report found surprisingly little overlap in the issues affecting AWS, Azure, and Google Cloud, meaning each provider requires a different focus. The report helps you understand where those priorities differ, breaking down the most common issues for each provider, comparisons across key risk categories, and how those risks shift as organizations grow.
Get the report (no email needed)
|
|
|
Tools
tailcat
Like netcat, but over Tailscale's data plane, without Tailscale's control plane.
boost
Boost wraps the commands your agents already run, turning noisy logs into compact, structured context that keeps the signal while cutting the noise.
|
|
From the cloud providers
#AWS
Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation
A guide to detecting multi-stage AWS attacks by correlating signals across CloudTrail, VPC Flow Logs, and Route 53 DNS logs. Covers four business-context-aware patterns: unexpected S3 access, abnormal role chains, KMS key misuse, and off-hours privileged changes, with CloudWatch Logs Insights queries and Lambda automation.
|
|
Thanks for reading!
|
If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! ๐ If you have questions, comments, or feedback, let me know on Twitter ( @lancinimarco / @CloudSecList), or at feedback.cloudseclist.com! Thanks, Marco
|
|
|