Release Date: 06/09/2026 | Issue: 354
Know someone who'd find this useful? Forward this email
CloudSecList is a newsletter for busy professionals who want to keep up to date with the cloud security industry. Hand-curated by Marco Lancini.
Sponsor

Building a company? Trust closes deals.

Your prospects won’t sign without proof of security. A proof of compliance request stalls deals and pulls engineers into audit prep. Vanta gets you compliant fast (SOC 2, ISO 27001, HIPAA+) and keeps you that way. Trusted by 16,000+ companies like Ramp, Harvey, and Writer.

Watch the on-demand demo

This week's articles


Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps
A practitioner's guide to log visibility, incident readiness, and threat hunting across the major version control services.


Frontier Forensics: OpenAI
A guide to evidence sources, logging, and retention across ChatGPT Workspace, the API Platform, and agentic workloads.


When AI infrastructure becomes the target: Securing gateways and control points | Microsoft Security Blog
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity.


Aurora ransomware targets ESXi abuses Cursor Agent for exploitation
Aurora ransomware (active since April 2026) deploys a Linux/ESXi encryptor using ChaCha20+RSA-4096, kills VMs via esxcli before encrypting VMDK files, and abuses Cursor Agent (Claude Sonnet) to conduct hands-on exploitation across ten victim organizations. Russian-language operator instructions prohibited DCSync, account lockouts, and adding domain computer objects.


Breaking Claude Code Opus 5 Auto Mode
A multi-stage indirect prompt injection attack against Claude Code Opus 5 in Auto Mode achieved 60-80% RCE success via HTTP 415 trickery, ZIP-delivered Python module shadowing (struct.py), and C2 callbacks.


Amazon Kiro: AI Is Breaking Vulnerability Disclosure Processes
A prompt injection flaw in Amazon Kiro IDE v0.7.45 allowing attacker-controlled repository content to exfiltrate sensitive data via the powersRecommendationUrl setting and Kiro Powers, exploitable in both trusted and untrusted workspaces.


Password spraying campaign targets AWS root user accounts across 150+ organizations
Datadog Security Research observed a password spraying campaign targeting AWS root user accounts across 150+ organizations, attempting unauthorized authentication against these high-privilege accounts.


The Docs Say It's OK: When Documentation Replaces a Fix in Vertex AI
Two Vertex AI privilege escalation paths let holders of aiplatform.customJobs.create or aiplatform.reasoningEngines.create steal highly privileged Google-managed service agent tokens, reaching project-editor-equivalent access. Google's response: add documentation warnings instead of patching.

Sponsor

Are you setting good boundaries for your AI agents?

When you’re working with AI agents, you need to understand what they’re doing and what they have access to. Teleport’s Identity Security platform gives you insights and lets you set boundaries to contain and control agents. Audit and review their tasks, monitor their behavior, and understand all of the risks related to AI in your environment.

Join Teleport September 17th to learn more.

Tools


re-shell
Nix-powered agentic reverse engineering environment.


mantis
A modular, stack-agnostic toolkit of security review skills for AI coding agents to autonomously find, reproduce, and patch vulnerabilities.


sample-aiml-security-assessment
AI/ML and Generative AI Security Assessment Framework for AWS. Automatically audit Amazon Bedrock and SageMaker & AgentCore workloads for security best practices.

From the cloud providers


#AWS   Extend your data perimeter to the AWS Management Console with Private Access
AWS Management Console Private Access is now GA, routing all console traffic (auth, static assets, service APIs) through AWS PrivateLink VPC endpoints with no internet path required. VPC endpoint policies and Sign-In RCPs enforce identity, resource, and network perimeter controls on interactive console sessions.


#AWS   Automate IAM Identity Center governance with continuous discovery and reporting
A walkthrough deploying two AWS CDK stacks for IAM Identity Center governance: a reporting stack (EventBridge, Step Functions, Lambda, DynamoDB, API Gateway, S3) for automated daily discovery and CSV export, and a remediation stack for real-time event-driven enforcement and SNS notifications on non-compliant application assignments.

Thanks for reading!

If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! 👌

If you have questions, comments, or feedback, let me know on Twitter (@lancinimarco / @CloudSecList), or at feedback.cloudseclist.com!

Thanks,
Marco
Forward Forward
Twitter Tweet
Share Share

How did you like this issue of CloudSecList?

1       2       3       4       5

Archives View in browser Sponsorship
© 2019-present CloudSecList · Marco Lancini