Release Date: 30/08/2026 | Issue: 353
Know someone who'd find this useful? Forward this email
CloudSecList is a newsletter for busy professionals who want to keep up to date with the cloud security industry. Hand-curated by Marco Lancini.
Sponsor

Stop Losing Deals to Compliance Delays

No one signs without proof of your security. When a prospect asks for compliance and you're not ready, the deal stalls and your engineer gets pulled off the roadmap to scramble through an audit.
Vanta gets you compliant fast (SOC 2, ISO 27001, HIPAA, GDPR) and keeps you that way with continuous monitoring, right where you work, even inside Claude or Cursor.
16,000+ companies, including Ramp, Harvey, and Writer, trust Vanta.

Get started with Vanta โ†’

This week's articles


The AI-Native SDLC playbook
Anthropic's stage-by-stage playbook for the AI-native SDLC: how teams plan, design, build, test, deploy, and maintain software with Claude.


VMs won't contain cyber-capable agents
GPT-5.6-Cyber, given a QEMU/KVM VM sandbox, escaped three times: exploiting a known kernel CVE, chaining two libslirp vulnerabilities, and finally using four bugs including three 0-days. Standard VMs are insufficient to contain cyber-capable AI agents; Firecracker with minimal attack surface is recommended.


Playing whack-a-mole is losing
Reactive bug-patching (whack-a-mole) is a losing security strategy. Instead of endlessly finding and fixing individual vulnerabilities, security teams should define and enforce system invariants to eliminate entire bug classes, including in the AI-accelerated vulnpocalypse era.


How to evaluate LLMs before production
Practical LLM evaluation lessons from GitHub secret scanning: define product goals and guardrails first, treat offline evaluation as repeatable integration testing, keep eval data close to production, audit labels, use error analysis, and apply LLM-as-judge for human review triage.


Extension Possession: One click to take over every extension on Open VSX
A stored XSS flaw (CVE-2026-13323) in Open VSX allowed an attacker to mint a persistent PAT in a maintainer's session via one click, then silently publish malicious extension updates to millions of developer endpoints via auto-update.


The state of email authentication, August 2026
August 2026 census of the top 1M domains: DMARC valid 63.6%, DANE 4.6%, MTA-STS 1.2%, BIMI 2.5%. New finding: only 0.2% of MX servers actually refuse cleartext, despite published policies. DMARC leads at 63.6%.


AI Data Centers Directory
A browsable directory of 83 AI data centers tracked by Epoch AI, covering hyperscale campuses, colocation sites, and AI training facilities across North America, Europe, and Asia. Each entry includes IT power capacity, compute estimates, operator details, satellite imagery, and buildout timelines.


Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaign's infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios.

Sponsor

Different cloud providers, different priorities

If juggling multiple cloud providers wasn't complicated enough, it turns out they don't fail in the same places. Intruder's new report found surprisingly little overlap in the issues affecting AWS, Azure, and Google Cloud, meaning each provider requires a different focus. The report helps you understand where those priorities differ, breaking down the most common issues for each provider, comparisons across key risk categories, and how those risks shift as organizations grow.

Get the report (no email needed)

Tools


tailcat
Like netcat, but over Tailscale's data plane, without Tailscale's control plane.


boost
Boost wraps the commands your agents already run, turning noisy logs into compact, structured context that keeps the signal while cutting the noise.

From the cloud providers


#AWS   Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation
A guide to detecting multi-stage AWS attacks by correlating signals across CloudTrail, VPC Flow Logs, and Route 53 DNS logs. Covers four business-context-aware patterns: unexpected S3 access, abnormal role chains, KMS key misuse, and off-hours privileged changes, with CloudWatch Logs Insights queries and Lambda automation.


#AWS   From clickops to governed IaC: CloudFormation drift detection in practice
A guide for migrating ClickOps-managed AWS infrastructure to governed CloudFormation IaC using IaC Generator for template generation, stack organization by lifecycle/ownership, and automated drift detection via EventBridge for continuous compliance monitoring.

Thanks for reading!

If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! ๐Ÿ‘Œ

If you have questions, comments, or feedback, let me know on Twitter (@lancinimarco / @CloudSecList), or at feedback.cloudseclist.com!

Thanks,
Marco
Forward Forward
Twitter Tweet
Share Share

How did you like this issue of CloudSecList?

1       2       3       4       5

Archives View in browser Sponsorship
ยฉ 2019-present CloudSecList ยท Marco Lancini