Release Date: 27/09/2026 | Issue: 357
Know someone who'd find this useful? Forward this email
CloudSecList is a newsletter for busy professionals who want to keep up to date with the cloud security industry. Hand-curated by Marco Lancini.
Sponsor

Build Compliance into your AI Stack

As AI adoption accelerates, so does the risk your security team manages, new frameworks, audits, and vendors keep piling on. Evidence gets chased manually, controls get validated by hand, and every audit turns into a scramble. With Vanta, you'll
  • Get audit-ready fast (SOC 2, ISO 27001, Essential Eight, CPS 234, and more)
  • Stay audit-ready with continuous monitoring as your tools evolve
  • Access the Vanta agent everywhere you work, even in Claude or Cursor
Trusted by 16,000+ companies including Atlassian, Supabase, and Harvey.
Watch the on-demand demo โ†’

This week's articles


One does not simply defend agentically
Defenders face organisational/political constraints that prevent agentic AI use analogous to attackers. NCSC proposes a risk framework across potency, scope, criticality, rollout confidence, and recoverability dimensions to safely identify and expand automatable defensive actions.


Detection fidelity in the age of AI agents living off the land
AI agents using standard Linux tools (curl, tcpdump, Python scripts) erode tripwire detection fidelity by flooding systems with legitimate-looking noise. Detection must shift to probabilistic correlation of co-occurring signals across the kill chain, not isolated indicators.


Send GitLab an email, push to main
GitLab gives you a private email address to create issues. If leaked, anyone who has it can push code, execute CI/CD jobs, and bypass IP restrictions across all of your public and private projects.


Exploring the new AWS Sign Up experience
This post will explore what this new concept does, how it works with the new Account Access capability, and why a strong security posture still requires upgrading out of the sandbox.


Containers Are No Longer a Security Boundary
AI-accelerated kernel vuln discovery (5,976 CVEs in 2026) has made container escapes trivial. CVE-2026-80521, a Linux AF_UNIX use-after-free, demonstrates a full container escape.


Mapping Scaleway IAM, An Attacker's View of the Trust Boundaries
An attacker-focused analysis of Scaleway IAM trust boundaries, showing how a stolen user API key equals full account takeover, how policy-less keys still enable reconnaissance, and offering defender mitigations including preferring application keys and treating org metadata as public.


Hacking OpenAI
Researchers chained a libheif heap buffer overflow (via Discourse/ImageMagick image upload) with an OpenAI SSO misconfiguration to achieve RCE on community.openai.com, take over employee ChatGPT/Codex accounts, and access OpenAI's internal GitHub monorepo.


Attacker infrastructure, but vibe-coded: tracking the evolution of credential harvesting platforms
Researchers analyzed two AI vibe-coded credential harvesting platforms, Loot and UltraVault, tracking how attackers used Amazon Bedrock to automatically validate stolen cloud secrets at scale.

Sponsor

How two small bugs led Teleport to a critical vulnerability and a cryptography audit of Go's SSH library

CVE-2025-49825 was a critical vulnerability that let SSH certs issued to cluster users sign other SSH certs, which were then accepted as valid, letting users escalate privileges and bypass authentication. Teleport found the bug in its own code, then partnered with Filippo Valsorda, his team at Geomys, and NCC Cryptography Services on a deeper audit, resulting in nine CVEs. The full report is now public, for any team running on Go's SSH library.

[Read the full audit findings โ†’]

Tools


drop
Linux sandboxing that doesn't get in your way.


req2proto
Tool for reversing Google internal protobuf definitions.


substrate
Secure-by-default agent execution runtime on Kubernetes, multiplexing millions of sandboxed actors onto fewer workers with sub-500ms resume, zero-trust isolation, and microVM/gVisor support.


EntraTrace
EntraTrace is a defensive security research tool for tracking and identifying the behavior of offensive tooling targeting Microsoft Entra ID.

From the cloud providers


#GCP   Strengthen your CI/CD pipeline with new Secure Source Manager capabilities
Google Cloud Secure Source Manager adds two GA features: a Code Owners system enabling per-file and per-branch PR approval governance with nestable CODEOWNERS files, and Developer Connect integration for private-network CI/CD connectivity using Private Service Connect and VPC Service Controls.


#AZURE   How to secure edge AI in customer-owned environments
Edge AI shifts trust responsibility to customers who operate more of the AI stack outside provider control. Organizations must verify runtimes via attestation, validate AI artifact provenance, constrain model actions through deterministic mediation, and bind sensitive assets only to trusted, evidence-verified environments.

Thanks for reading!

If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! ๐Ÿ‘Œ

If you have questions, comments, or feedback, let me know on Twitter (@lancinimarco / @CloudSecList), or at feedback.cloudseclist.com!

Thanks,
Marco
Forward Forward
Twitter Tweet
Share Share

How did you like this issue of CloudSecList?

1       2       3       4       5

Archives View in browser Sponsorship
ยฉ 2019-present CloudSecList ยท Marco Lancini