This week's articles
The AI SDLC transformation playbook
Atlassian's shared their own version of an AI SDLC playbook, which outlines transforming the full dev lifecycle using agentic AI, requiring two platform investments (context graph, measurement) and workflow shifts across planning, design, development, review, and maintenance, with humans retaining governance and judgment.
Agent containment best practices
Private beta guidance from Anthropic: run autonomous agents in hardware-virtualized sandboxes, one microVM per agent; keep credentials out of agent environments; use auto mode as extra check; retain transcripts 30+ days; report out-of-scope behavior.
Designing MCP Gateway Uber's MCP Management Platform
Uber built MCP Gateway, a centralized microservice hosting 800+ MCP servers and 5000+ tools. It auto-discovers internal APIs via IDL crawling, translates HTTP/gRPC/TChannel calls to MCP, enforces auth/redaction, and provides runtime discovery via Omni MCP to reduce agent context bloat.
Azure's Weakest Link - Five Full Cross-Tenant Compromises
Five critical Azure cross-tenant privilege escalation vulnerabilities in API Connections (Logic Apps) were found via path traversal in DynamicInvoke, undocumented Dynamic* endpoints, and the host.api.RuntimeUrl parameter, yielding $200,000 in bug bounties.
|
|
Sponsor
Stop reinventing your first year of security
Companies at the same stage need the same foundations: SSO, offboarding, patch cadence, logging, incident response. You still have to work out the order and write the plan from scratch. PrimeOutpost ships that first year as a sequenced roadmap with playbooks, fitted to your industry, headcount and stack.
We are taking on a few design partners: full product free, plus a 30-minute onboarding call, in return for honest feedback.
Apply as a design partner
|
|
|
Tools
VulnHunter
Agentic AI security scanner that hunts exploitable vulnerabilities like an adversary, proves them with executable PoCs, and fixes them test-first.
Zurp
Meta bug bounty research tools, in Burp Suite and in your coding agent. You can also check out the companion blog post.
EntraGoat
A Deliberately Vulnerable Entra ID Environment.
|
|
From the cloud providers
#AWS
Building your AI vulnerability harness
The article describes a three-layer pipeline that narrows scanner findings through multi-scanner agreement, AST-based structural verification against code, and deployment context from IaC controls such as WAF rules. It outputs a small, prioritized set of evidenced findings, which still needs human review. You can also check out Part 2.
#AZURE
3 lessons from frontier AI vulnerability research
FORGE Lab reports 140 Windows CVEs and 155 validated open-source reports. Three lessons: measure the full pipeline, not just findings; spend reasoning only where it removes uncertainty; and make validation and remediation a continuous learning loop.
|
|
Thanks for reading!
|
If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! 👌 If you have questions, comments, or feedback, let me know on Twitter ( @lancinimarco / @CloudSecList), or at feedback.cloudseclist.com! Thanks, Marco
|
|
|