Release Date: 04/10/2026 | Issue: 358
Know someone who'd find this useful? Forward this email
CloudSecList is a newsletter for busy professionals who want to keep up to date with the cloud security industry. Hand-curated by Marco Lancini.
Sponsor

Compliance is not a security strategy

First security hire, or the engineer who got handed security?
A SOC 2 report won't tell you what to fix next.

PrimeOutpost gives you a sequenced program to work through and show to leadership, and the certifications follow from the work.
We're looking for a few design partners: full product free and hands-on onboarding, in exchange for honest feedback.

Interested? Email [email protected]

This week's articles


Throw Away the Playbook: Security in the AI-Native SDLC
We, as an industry, should have the courage to throw away the playbooks we've been working on for the past 20+ years and create new (and better) ones for the AI era.


Securing the software factory at machine speed
GitLab's CISO argues that agentic AI development requires security, governance, and guardrails embedded in the SDLC execution path. The key metric is time from detection to verified remediation, driven to machine speed using AI-powered triage, constrained agent identities, and continuous scanning.


Test-driving Jev on a security task: identity resolution
Test-driving Jev, a decision model trained for calibrated probabilities, on identity resolution across five data sets. Compared against gpt-oss-20b, Claude Haiku 4.5, Sonnet 5 and Opus 5.5, and traditional entity resolution (Fellegi-Sunter and gradient-boosted trees), with cost, latency, prompt, stability and error analysis.


Package Name to Role Credentials in Code Interpreter: Two RCE CVEs in the AgentCore Python SDK
BeyondTrust found two RCE CVEs in the Amazon Bedrock AgentCore Python SDK's install_packages() helper. A crafted package name with a newline or pip extras command substitution bypassed input validation, achieving RCE inside the Firecracker sandbox and stealing attached execution role AWS credentials from MMDS.


Enforce positive security with Cloudflare Application Profiles
Cloudflare Application Profiles launches a positive security layer for web apps: it learns HTTP request structure from traffic, flags deviations (type mismatches, out-of-range values, invalid UUIDs), and exposes violations as metadata for Security Rules enforcement.


How DigitalOcean Manages Credentials for Autonomous Agents
DigitalOcean Managed Agents secure autonomous workloads by ensuring agents never hold live credentials directly, utilizing ephemeral execution-time brokering via Action Gateway and strict runtime boundaries. This architecture aligns with NVIDIA's Open Agent Safety Platform and OpenShell policy schemas to prevent data exfiltration and limit blast radii across agent swarms.


Google's PageBreak Project
By combining agentic reasoning with live-site verification, PageBreak uncovered complex logic flaws that traditional scanners will often miss. The post shows three examples of high-severity vulnerabilities PageBreak found in Google applications.


Discovering and exploiting a remote code execution vulnerability in OpenCode
Datadog Security Labs found GHSA-632h-h47v-g4x4 in OpenCode: the unauthenticated /global/upgrade API endpoint accepted arbitrary npm tarball URLs, enabling RCE via a crafted cross-origin HTML form submission bypassing CORS.

Tools


gh-secure
A GitHub CLI extension to enable security features on repositories following best practices from GitHub Security Lab.


coop
Isolated VM environment for running Claude Code and Codex.


cf
The agentic CLI for the entire Cloudflare API.


tidcli
A simple touchID prompt'er for use in shell scripts.

From the cloud providers


#AZURE   Storm-3168: Agentic-driven cloud attacks using compromised service principals
Storm-3168 (JADEPUFFER) used compromised Azure service principals to conduct automated reconnaissance, bulk deletion of Storage Accounts, Key Vaults, and Function Apps, and credential harvesting via ListKeys, consistent with ransomware-aligned objectives. Mitigations include least privilege, secret rotation, and resource locks.

Thanks for reading!

If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! ๐Ÿ‘Œ

If you have questions, comments, or feedback, let me know on Twitter (@lancinimarco / @CloudSecList), or at feedback.cloudseclist.com!

Thanks,
Marco
Forward Forward
Twitter Tweet
Share Share

How did you like this issue of CloudSecList?

1       2       3       4       5

Archives View in browser Sponsorship
ยฉ 2019-present CloudSecList ยท Marco Lancini