Release Date: 20/09/2026 | Issue: 356
Know someone who'd find this useful? Forward this email
CloudSecList is a newsletter for busy professionals who want to keep up to date with the cloud security industry. Hand-curated by Marco Lancini.
Sponsor

Building with AI demands speed. Securing it demands rigor.

AI teams are shipping models, agents, and integrations faster than security programs can keep pace with. New frameworks, attack surfaces, and vendors, compliance tooling wasn't built for it.
Vanta works differently, with automated workflows for fast-moving AI teams. Get audit-ready fast, then stay secure with continuous monitoring as your models and infrastructure evolve.
Teams at Atlassian, Supabase, and Harvey closed bigger deals by getting security right early. Start with Vanta's AI Security Assessment.

Start the assessment β†’

This week's articles


Detecting and countering misuse of AI: September 2026
Anthropic's September 2026 threat report covers disrupted misuse of Claude (Dec 2025-Aug 2026) across seven harm areas: AI-augmented cyber ops by state and criminal actors, influence operations across six continents, surveillance platforms targeting dissidents, conventional weapons software development, dual-use biological research, fraud/scams, and illicit distillation by PRC AI labs including Alibaba, DeepSeek, Moonshot, and Zhipu.


OpenAI's Defense Factory
OpenAI's Defense Factory is a continuous, agent-first vulnerability detection and remediation pipeline using Codex and specialized cyber models (Daybreak Blue/Red). It automates inventory, triage, dynamic validation, ownership assignment, and verified patching, achieving 0.81% false-positive rate and 0.53% fix rollback rate.


Breaking into Google's GFile for $100k
This post details an attack on Google's internal APIs, bypassing authorization to exploit the GFile library to gain access to internal filesystems and storage.


Hacking AI customer service agents
Techniques for attacking AI customer service agents: email spoofing to hijack agent actions, MFA bypass via email normalization and IVR channel-switching, email address smuggling via RFC comments for IDOR, OTP exfiltration via inbox-monitoring agents, asymmetric MIME content, conversation forgery, and RAG knowledge base poisoning.


DeepSeek Harness Vulnerability Lets AI Agents Escape Their Own Sandbox
CVE-2026-82533 (CVSS 9.4) in DeepSeek Harness lets a sandboxed AI agent escape confinement via a single curl call to the unauthenticated local API, spoofing the Host header to elevate its session to danger-full-access.


GitHub Actions Adds cache-mode to Limit Cache Poisoning Risk
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.


Mapping out your unknown: A threat hunter’s guide to GitHub
A threat hunter's guide covering various GitHub-specific threats and detection techniques, targeting security practitioners monitoring GitHub environments for malicious activity.

Tools


mecatl
Open source agent harness, built from the ground up for cloud-native production workloads on infrastructure you control.


litecli
CLI for SQLite Databases with auto-completion and syntax highlighting.


codegraph
Pre-indexed code knowledge graph, auto syncs on code changes, for Claude Code, Codex, Gemini, Cursor, OpenCode, AntiGravity, Kiro, CoPilot, and Hermes Agent.


open-code-review
Fast, efficient, battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in multi-language ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible.

From the cloud providers


#AWS   AWS STS simplifies session token size limits and adds session token size monitoring
AWS STS replaces its previous dual limits (packed policy size + assembled token size) with a single 4,096-byte session token limit. Token size is now reported via API responses, CloudWatch, and CloudTrail. A new MinimumSessionTokenSize parameter enables infrastructure compatibility testing.


#AWS   Introducing Amazon EBS Volume Clones across AWS account
AWS introduces Amazon EBS Volume Clones with cross-account copy, so you can create copies of your EBS volumes into other AWS accounts and optionally re-encrypt them with an AWS Key Management Service (AWS KMS) key in the target account.

Thanks for reading!

If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! πŸ‘Œ

If you have questions, comments, or feedback, let me know on Twitter (@lancinimarco / @CloudSecList), or at feedback.cloudseclist.com!

Thanks,
Marco
Forward Forward
Twitter Tweet
Share Share

How did you like this issue of CloudSecList?

1       2       3       4       5

Archives View in browser Sponsorship
Β© 2019-present CloudSecList Β· Marco Lancini