<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cloud Security Newsletter</title>
    <description>Bringing you relevant Cloud Security News, Interviews &amp; Expert Knowledge so you don’t have to spend hours looking for it.</description>
    
    <link>https://www.cloudsecuritynewsletter.com/</link>
    <atom:link href="https://rss.beehiiv.com/feeds/hEEMTXlHVR.xml" rel="self"/>
    
    <lastBuildDate>Sun, 12 Jul 2026 03:38:08 +0000</lastBuildDate>
    <pubDate>Thu, 09 Jul 2026 22:22:44 +0000</pubDate>
    <atom:published>2026-07-09T22:22:44Z</atom:published>
    <atom:updated>2026-07-12T03:38:08Z</atom:updated>
    
      <category>Artificial Intelligence</category>
      <category>Cybersecurity</category>
      <category>Technology</category>
    <copyright>Copyright 2026, Cloud Security Newsletter</copyright>
    
    <image>
      <url>https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/publication/logo/5d030314-3f63-40f3-97b8-c426d73fea15/Mascots-Pose1-NoCircle.png</url>
      <title>Cloud Security Newsletter</title>
      <link>https://www.cloudsecuritynewsletter.com/</link>
    </image>
    
    <docs>https://www.rssboard.org/rss-specification</docs>
    <generator>beehiiv</generator>
    <language>en-us</language>
    <webMaster>support@beehiiv.com (Beehiiv Support)</webMaster>

      <item>
  <title>🚨 FortiBleed Turns 430,000 Firewalls Into a Ransomware Feed: Why &quot;Exploitable&quot; Beats &quot;Reachable&quot;</title>
  <description>This week&#39;s news runs on one mechanic: a secret or key sitting one careless step from the internet, and the exploit that turns it into impact. FortiBleed credentials now feed INC and Lynx ransomware, a Langflow cross-tenant IDOR steals other tenants&#39; cloud keys, and fake payment SDKs harvest CI/CD secrets. Harry Wetherald of Maze explains why the question that matters is no longer &quot;is this reachable&quot; but &quot;is this exploitable&quot;.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/70797052-0db0-4486-9623-0b6d457da3ae/Screenshot_2026-07-09_at_10.51.44_PM.png" length="2395084" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/reachable-vs-exploitable</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/reachable-vs-exploitable</guid>
  <pubDate>Thu, 09 Jul 2026 22:22:44 +0000</pubDate>
  <atom:published>2026-07-09T22:22:44Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><h2 class="heading" style="text-align:left;" id="hello-from-the-cloudverse"><span style="background-color:#28EEDA;"><b>Hello from the Cloud-verse!</b></span></h2><p class="paragraph" style="text-align:left;">This week’s Cloud Security Newsletter topic<b>: Reachable vs. Exploitable — The Distinction That Decides What You Actually Fix </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" rel="noopener noreferrer nofollow">(continue reading)</a> </p><hr class="content_break"><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://links.cloudsecuritypodcast.tv/maze-code-to-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable"><span class="button__text" style=""> This issue is sponsored by Maze </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/70797052-0db0-4486-9623-0b6d457da3ae/Screenshot_2026-07-09_at_10.51.44_PM.png?t=1783633945"/></a><div class="image__source"><span class="image__source_text"><p>This image was generated by AI. It&#39;s still experimental, so it might not be a perfect match!</p></span></div></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;">The week did not hand us a single marquee breach. It handed us five variations on the same failure: the credential or key an attacker wants is now reachable, and the only question left is whether the surrounding context makes it exploitable. FortiBleed turned tens of thousands of exposed FortiGate firewalls into a working credential feed for two ransomware crews. A Langflow authorization-bypass flaw let one operator read other tenants&#39; flows and walk off with their LLM and AWS keys. Fake Paysafe and Skrill SDKs sat in build pipelines returning fake success while reading AWS and GitHub tokens out of the environment.</p><p class="paragraph" style="text-align:left;">That mechanic is exactly what <b>Harry Wetherald</b>, co-founder and CEO of <b>Maze</b>, spends his days on. His argument: reachability tells you a vulnerability <i>might</i> be exploitable; exploitability tells you an attacker actually has everything needed to trigger it — and reasoning across code and cloud context to answer the second question is the shift AI finally makes possible.<i>[</i><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">⚡ TL;DR for Busy Readers</h2><ul><li><p class="paragraph" style="text-align:left;">🚨 <b>FortiBleed is now a ransomware pipeline.</b> SOCRadar tied the mass FortiGate credential theft (~430,000 firewalls targeted) to the INC and Lynx crews. Reset FortiGate admin and VPN credentials and enforce MFA today — the exposure already happened at config-read time.</p></li><li><p class="paragraph" style="text-align:left;">🚨 <b>A CVSS 6.1 flaw did the real damage.</b> CISA&#39;s July 7 KEV batch includes Langflow&#39;s cross-tenant IDOR (CVE-2026-55255), used to steal other tenants&#39; LLM and AWS keys, alongside a CVSS 10.0 ColdFusion flaw exploited within hours. Patch by July 10; pull exposed Langflow behind auth and rotate every reachable key.</p></li><li><p class="paragraph" style="text-align:left;"><b>Fake payment SDKs raided build pipelines.</b> 17 typosquatted Paysafe/Skrill/Neteller packages on npm and PyPI harvested AWS, GitHub, and npm tokens from CI runners. Audit runner env-var scopes; move build secrets to short-lived OIDC.</p></li><li><p class="paragraph" style="text-align:left;"><b>Your own bucket can be turned against you.</b> Unit 42 detailed a global-namespace bucket-hijacking flaw that reroutes live data streams to an attacker-owned bucket with a reused name. Never delete-and-forget a bucket name referenced anywhere.</p></li><li><p class="paragraph" style="text-align:left;"><b>ADFS can hand over a live signing key.</b> Mandiant showed active ADFS token-signing keys recoverable from machine DPAPI, enabling MFA-bypassing SAML forgery. Audit AutoCertificateRollover state and certificate drift.</p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="this-weeks-top-5-security-headlines">📰 <b>THIS WEEK&#39;S TOP 5 SECURITY HEADLINES</b></h2><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-forti-bleed-credentialtheft-campa"><b>1.  FortiBleed credential-theft campaign confirmed as a ransomware pipeline for INC and Lynx</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://www.bleepingcomputer.com/news/security/fortibleed-credential-theft-campaign-linked-to-lynx-ransomware/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer</a> <br><b>Reporting:</b> <a class="link" href="https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">SOCRadar STRU</a> · <a class="link" href="https://www.recordedfuture.com/blog/critical-fortibleed-campaign?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Recorded Future</a> · <a class="link" href="https://www.securityweek.com/fortibleed-campaign-linked-to-inc-lynx-ransomware-attacks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">SOCRadar&#39;s threat research unit tied the mass FortiGate credential-theft campaign known as FortiBleed to the INC and Lynx ransomware operations. This is the first confirmed link between the harvesting and downstream ransomware deployment. Investigators found an operator with FortiBleed infrastructure access logged into both the INC and Lynx negotiation panels, and INC victims overlapping with FortiBleed data. The campaign is assessed to have targeted more than 430,000 internet-facing FortiGate firewalls, deployed packet sniffers on roughly 19,000 devices, and cracked configuration-file hashes into verified working administrator credentials for tens of thousands of systems.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">The FortiGate SSL-VPN is the identity edge for most hybrid enterprises, and a cracked admin credential there is not a vulnerability to patch because it is a valid login that survives patching. The credential inventory is now demonstrably feeding two active ransomware crews, turning &quot;we have MFA-less VPN admins&quot; from a hygiene finding into a named, in-progress ransomware precursor.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders: </b>Reset all administrative and VPN credentials on internet-facing FortiGate devices, enforce MFA on every admin and remote-access account, and pull VPN auth logs for anomalous admin logins and any sign of packet-capture tooling.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-cisa-adds-four-exploited-flaws-to"><b>2. </b><b>CISA adds four exploited flaws to KEV, including a Langflow cross-tenant IDOR that steals LLM and AWS keys</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">CISA KEV alert</a> <br><b>Reporting:</b> <a class="link" href="https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a> <br><b>Analysis:</b> <a class="link" href="https://www.sysdig.com/blog/understanding-langflow-cve-2026-55255-and-why-higher-cvss-vulnerabilities-arent-always-the-most-exploited?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Sysdig</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">On July 7 CISA added four actively exploited flaws to the KEV catalog with a July 10 federal deadline: Adobe ColdFusion path traversal CVE-2026-48282 (CVSS 10.0), two JoomShaper/PageBuilder unauthenticated file-upload RCEs (CVE-2026-56290 and CVE-2026-48908, both CVSS 10.0), and Langflow authorization-bypass IDOR CVE-2026-55255 (CVSS 6.1). Sysdig reported a single operator chaining the Langflow IDOR with an unauthenticated RCE (CVE-2026-33017) against internet-exposed instances between June 22 and June 25, using the cross-tenant IDOR to read other tenants&#39; flows and steal their LLM-provider and AWS keys. The ColdFusion flaw was exploited within hours of disclosure.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">The CVSS ordering is inverted from the risk — the 6.1 Langflow bug, not the 10.0s, is the one that handed an attacker a live credential set for someone else&#39;s cloud account. An AI-orchestration platform is a credential vault, and a cross-tenant IDOR against it is a supply route into every cloud those flows touch.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders</b><b>:</b> Patch all four by July 10; for Langflow, pull any internet-exposed instance behind authentication immediately and rotate every LLM-provider and cloud key any hosted flow could reach — treat exposed instances as already harvested.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">🛠 <b>If you only do one thing this week:</b> Find every internet-exposed AI-orchestration or agent platform (Langflow and anything like it), put it behind authentication, and rotate every LLM and cloud key it could reach. This week&#39;s Langflow story is the proof that a &quot;medium&quot; CVSS flaw on a credential-holding platform is the one that actually converts to cloud compromise — reachable became exploitable the moment those keys were sitting there.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-fake-paysafe-skrill-and-neteller-"><b>☁️ 3. </b><b>Fake Paysafe, Skrill and Neteller SDKs on npm and PyPI harvest CI/CD secrets</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://socket.dev/blog/npm-pypi-campaign-typosquats-popular-secure-payment-apps?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Socket</a> <br><b>Reporting:</b> <a class="link" href="https://www.bleepingcomputer.com/news/security/fake-paysafe-skrill-sdks-on-npm-and-pypi-steal-credentials/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer</a> · <a class="link" href="https://thehackernews.com/2026/07/threatsday-cloud-bucket-hijacking.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b><br>Socket flagged a coordinated cluster of 17 malicious packages — 13 on npm, 4 on PyPI, typosquatting the Paysafe, Skrill and Neteller payment SDKs, published July 7. The packages expose the expected payment APIs and return fake success responses while collecting environment variables and exfiltrating them, including via an Ngrok endpoint and an AWS-hosted C2. Captured variables include PAYSAFE_API_KEY, AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN and NPM_TOKEN. The npm packages were flagged as malicious within roughly six minutes of publication, each shipping four rapid versions with per-version obfuscation keys to defeat hash-based tracking.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b><br>The target is not the payment platform, it is the CI runner, a package that pretends to process payments while reading AWS and GitHub tokens out of the build environment turns a routine install into cloud-credential exfiltration. The six-minute flag time helps teams using package firewalls and does nothing for teams that pull latest on every build, because the payload runs at install.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders</b><br>Block the named packages, audit CI/CD environment-variable scopes so a compromised install cannot read cloud or registry tokens, and move build-time secrets to short-lived OIDC tokens rather than static keys in the runner environment.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-unit-42-details-a-cloud-buckethij">🏥<b> 4. </b><b>Unit 42 details a cloud bucket-hijacking flaw that reroutes your data to an attacker-owned bucket</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Palo Alto Networks Unit 42</a> <br><b>Reporting:</b> <a class="link" href="https://thehackernews.com/2026/07/threatsday-cloud-bucket-hijacking.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">Unit 42 described a bucket-hijacking technique affecting major cloud providers, which it characterizes as a fundamental architectural issue rather than a single-vendor bug. Because storage-bucket names occupy a globally unique namespace, an attacker who learns the name of a decommissioned or deletable bucket can delete it and immediately recreate it under their own account with the same name, that was silently rerouting any data stream still writing to that name (critical logs, telemetry, sensitive data) into attacker-controlled storage. Unit 42 notes the echo of Aqua Security&#39;s 2024 &quot;Bucket Monopoly&quot; method and says there is no evidence of in-the-wild abuse to date.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">The trust assumption being broken is that a bucket you configured as a destination stays yours. Global-namespace reuse means a name you stop owning can become someone else&#39;s inbound pipe without a single credential being stolen, which reframes bucket naming and lifecycle from housekeeping into a data-exfiltration control.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders</b><br>Inventory every hard-coded bucket destination in logging, backup, and data pipelines; never delete-and-forget a bucket whose name is referenced anywhere, and adopt naming with account-scoped random suffixes so a released name cannot be re-registered as a data sink.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-mandiant-recovers-active-adfs-tok"><b>🛡️ 5. </b><b>Mandiant recovers active ADFS token-signing keys from machine DPAPI, enabling MFA-bypassing SAML forgery</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Mandiant / Google Cloud Threat Intelligence</a> <br><b>Reporting:</b> <a class="link" href="https://securitybrief.com.au/story/mandiant-finds-way-to-recover-active-adfs-signing-keys?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">SecurityBrief</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">Mandiant disclosed that in ADFS deployments where AutoCertificateRollover is disabled and certificates are rotated manually, configuration drift can leave an active token-signing key exposed in machine-scoped DPAPI while the Windows Internal Database still references a stale certificate. An attacker who recovers that live private key can forge SAML assertions for any user in the federated environment, reaching ADFS-tied applications including Microsoft 365 and Entra ID while bypassing MFA. The technique avoids touching LSASS and the live ADFS process, reducing the telemetry most monitoring relies on. Mandiant frames it as an evolution of the Golden SAML attack.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">This turns a documentation-level operational detail — &quot;we rotate ADFS certs by hand&quot; into a full cloud-identity compromise, because the forged SAML token is trusted by every downstream cloud app federating through ADFS. The MFA bypass is the sharp edge: the control most enterprises treat as their identity backstop is not in the path when the assertion itself is signed with a valid key.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders:</b><a class="link" href="https://workspaceupdates.googleblog.com/2026/03/ransomware-detection-and-file-restoration-for-Google-Drive-now-generally-available.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow"> </a><br>Audit ADFS for AutoCertificateRollover state and any drift between the certificate the service is actively signing with and the record in the configuration database; where manual rotation is used, confirm no orphaned active signing key remains recoverable from machine DPAPI.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-supplychain-attacks-shift-to-ai-d"><b>6. </b><b> European Commission presents an Action Plan on Cybersecurity and Artificial Intelligence</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://commission.europa.eu/news-and-media/news/new-eu-plan-address-risks-and-opportunities-advanced-ai-cybersecurity-2026-07-07_en?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">European Commission</a> <br><b>Reporting:</b> <a class="link" href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1544?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Commission press corner</a> · <a class="link" href="https://www.mlex.com/mlex/artificial-intelligence/articles/2498071/eu-cybersecurity-ai-action-plan-focuses-on-implementation-not-new-legislation?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">MLex</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> On July 7 the European Commission presented its Action Plan on Cybersecurity and Artificial Intelligence, framed around defending against AI-accelerated attacks and enabling safe use of AI in security. It directs the Commission to strengthen Europe&#39;s capacity to evaluate AI models before they enter the EU market in line with the AI Act, to work with ENISA on a European Blueprint for secure access to advanced AI systems for cybersecurity, and to stand up a secure platform to test AI for cybersecurity by the end of 2026. Analysts note the plan emphasizes implementing existing frameworks rather than new legislation.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b>  Pre-market model evaluation tied to the AI Act moves AI security from a vendor-attestation question to a market-access condition, which changes procurement for any cloud or security platform shipping model capabilities into the EU. Expect model-provenance and secure-access-to-AI questions to surface in supervisory conversations the way DORA incident-reporting expectations did this year.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders:</b> If you operate in or sell into the EU, map which AI capabilities in your cloud stack will fall under AI Act pre-market evaluation, and track the ENISA secure-access Blueprint as an input to AI governance and vendor assessment.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="reachable-vs-exploitable-the-distin"><b>Reachable vs. Exploitable — The Distinction That Decides What You Actually Fix</b></h3><p class="paragraph" style="text-align:left;">Two of this week&#39;s stories are token problems wearing different clothes. Azure CLI issued tokens through an OAuth flow that never met the policy; SimpleHelp accepted tokens it never verified were signed. Kahn&#39;s episode is the conceptual layer under both: as autonomous agents multiply, the same two questions is this identity real, and is this access still appropriate — stop being solved by static permissions and start requiring standards built for identities whose goals change every day. The through-line for the week is that the management and identity plane is where the damage now lands, and agent identity is the version of that problem heading straight for every enterprise that shipped an agent this quarter. [<a class="link" href="https://www.cloudsecuritypodcast.tv/videos/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Listen to the full episode →</a>] </p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="featured-experts-this-week"><b>Featured Experts This Week </b>🎤</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/harrywetherald/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow"><b>Harry Wetherald</b></a><a class="link" href="https://www.linkedin.com/in/harrywetherald/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow"> </a>— Co-founder & CEO, <a class="link" href="https://mazehq.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Maze</a></p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Reachability:</b> Whether an attacker can at least get to the vulnerability — in cloud, roughly whether it can be reached from the network; in code, whether the vulnerable function is actually active rather than dead code. Signals only that something <i>might</i> be exploitable.</p></li><li><p class="paragraph" style="text-align:left;"><b>Exploitability:</b> Whether all the context is present for an attacker to actually trigger the specific vulnerability (e.g., can a triggering request pass input sanitization and surrounding controls). The deeper determination AI now automates.</p></li><li><p class="paragraph" style="text-align:left;"><b>Cross-tenant IDOR:</b> An Insecure Direct Object Reference where an authenticated user references another tenant&#39;s object (here, another Langflow tenant&#39;s flow ID) to read data — in CVE-2026-55255, other tenants&#39; LLM and AWS keys.</p></li><li><p class="paragraph" style="text-align:left;"><b>FortiBleed:</b> The name for the mass credential-compromise campaign against internet-facing FortiGate firewalls, extracting configuration files and cracking stored credential hashes, now linked to INC and Lynx ransomware.</p></li><li><p class="paragraph" style="text-align:left;"><b>Golden SAML:</b> An attack in which a stolen ADFS token-signing key is used to forge SAML assertions for any federated user, bypassing MFA; Mandiant&#39;s machine-DPAPI key recovery is an evolution of it.</p></li><li><p class="paragraph" style="text-align:left;"><b>Bucket hijacking (global-namespace reuse):</b> Re-registering a released, globally unique storage-bucket name under an attacker account to silently receive data still being written to that name.</p></li><li><p class="paragraph" style="text-align:left;"><b>SCA / SAST:</b> Software Composition Analysis (third-party/dependency code, e.g., CVEs) and Static Application Security Testing (your own code). Maze Code ships one product for each.</p></li><li><p class="paragraph" style="text-align:left;"><b>&quot;Security brain&quot;:</b> Wetherald&#39;s term for a persistent, enriched, cached context layer plus threat model and human-defined priorities that a coding agent queries before and while writing code — his proposed successor to &quot;shift left.&quot;</p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <b><a class="link" href="https://links.cloudsecuritypodcast.tv/maze-code-to-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Maze</a></b></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Reachable vs. Exploitable, and the AI-Native AppSec Program</b></p><p class="paragraph" style="text-align:left;">Harry Wetherald has spent two years building AI agents that reason across code and cloud. The through-line: the tooling finally exists to answer the question that actually matters, but only for teams that treat reliability and cost as first-class engineering problems rather than vendor talking points.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-reachable-means-the-code-is-alive"><b>1. Reachable means &quot;the code is alive.&quot; Exploitable means &quot;the attacker has everything they need.&quot;</b></h3><p class="paragraph" style="text-align:left;">Wetherald&#39;s opening move is to separate two words the industry uses interchangeably. Reachability is a blunt filter; exploitability is the full-context judgment call.</p><p class="paragraph" style="text-align:left;">&quot;So that difference really is a difference between reachable, but is the code alive i, in the simplest terms? And exploitable is, is all the context kind of there for the attacker to actually be able to trigger the specific vulnerability?&quot;</p><p class="paragraph" style="text-align:left;">In code, that means first filtering out dead code, then testing whether a request that triggers the vulnerability can actually pass input sanitization and the controls around the application. The same logic applies in cloud and it maps directly onto this week&#39;s Langflow story, where &quot;reachable&quot; and &quot;exploitable&quot; were only a set of exposed keys apart.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-untuned-ai-is-confidently-wrong-t"><b> 2. </b><i> </i><b>Untuned AI is confidently wrong, the failure mode moved from &quot;obvious false positive&quot; to &quot;detailed, plausible false positive&quot;</b></h3><p class="paragraph" style="text-align:left;">Old rule-based scanners drowned teams in obvious noise. Out-of-the-box models are more accurate on a first pass but wildly inconsistent run to run, and their errors now arrive wrapped in convincing detail.</p><p class="paragraph" style="text-align:left;">&quot;they give very confident but sometimes wrong results &#39;cause they&#39;ll go very deep in an investigation, take one wrong turn along the way, and then give you the wrong answer.&quot;</p><p class="paragraph" style="text-align:left;">The fix is training agents to run investigations reliably and to catch their own mistakes, plus heavy monitoring and validation on top. Run the same agent on the same data in a poorly built system, Wetherald notes, and it can return a different answer five times out of ten.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-the-frontier-labs-security-tools-"><b>3. The frontier labs&#39; security tools test as inferior and more expensive</b></h3><p class="paragraph" style="text-align:left;">One of the sharper takes in the conversation. Wetherald argues the lab-built security offerings are side projects that can&#39;t match tools honed for a year or two on a specific domain, and — unusually — they cost more, because the labs&#39; incentive is to sell tokens.</p><p class="paragraph" style="text-align:left;">&quot;what we&#39;ve seen from Claude Code Security and from other, the Google and, and OpenAI equivalents is when you test them, they&#39;re far inferior to the more domain-specific tools that people have spent a year, two years honing, refining, training, et cetera.&quot;</p><p class="paragraph" style="text-align:left;">His buying advice: evaluate them the way you once evaluated bundled Microsoft or Google security — fine if &quot;good enough&quot; for the use case, but if security is strategic, go to specialists and avoid locking into one lab.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-cost-is-accuracy-the-case-for-100"><b>4. </b><i> </i><b>Cost IS accuracy, the case for 100x optimization, not 20%</b></h3><p class="paragraph" style="text-align:left;">Because customers have a fixed budget ceiling, every place you cut cost without losing accuracy frees budget to spend on deeper analysis elsewhere. Cost engineering isn&#39;t a margin lever; it&#39;s the accuracy lever.</p><p class="paragraph" style="text-align:left;">&quot;if you run Mythos, uh, on every PR for a 10,000-person software company, it comes out as $52 million a year.&quot;</p><p class="paragraph" style="text-align:left;">Wetherald&#39;s grounding story: the first Maze cloud run at a Fortune 100 customer extrapolated to roughly &quot;$4 million a week&quot; — about the company&#39;s total funding at the time — which forced cost to become a core product constraint. The takeaway for buyers is to ask how a vendor cuts cost by ~100x (dynamic routing across expensive and cheap models, or no model at all for some steps), not by a token percentage.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-the-numberone-buyer-red-flag-is-a"><b>5. The number-one buyer red flag is a black box</b></h3><p class="paragraph" style="text-align:left;">Because LLM-based tools inherently produce long chains of reasoning, a modern AI security product that behaves like an opaque box has no excuse. Auditability — &quot;how did you reach that decision&quot; — is the thing to demand.</p><p class="paragraph" style="text-align:left;">&quot;If you&#39;re talking to an, like, AI-based product and it looks like a black box and it&#39;s not telling you in really clear detail what it&#39;s doing, I would run a mile.&quot;</p><p class="paragraph" style="text-align:left;">His second buyer test: ask what the vendor built on top of the out-of-the-box models. If anyone could replicate it by pointing a frontier model at a codebase with a few prompts, the vendor has added nothing.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="6-tear-down-the-app-seccloud-wall-a"><b>6. Tear down the AppSec/cloud wall — and put a &quot;security brain&quot; behind the coding agent</b></h3><p class="paragraph" style="text-align:left;">Wetherald argues the historic separation of AppSec and cloud security was an artifact of tooling, not of the risk — the same underlying issue is often handled by two teams. LLMs act as a translator across the two domains, so the wall should come down.</p><p class="paragraph" style="text-align:left;">&quot;We shouldn&#39;t be sat here in five years&#39; time and going, our AppSec and our cloud security program runs completely separately.&quot;</p><p class="paragraph" style="text-align:left;">Looking forward, he sees coding agents (Cursor, Claude Code, Devin) needing a security &quot;brain&quot; to call — an enriched, cached context layer plus the org&#39;s threat model and priorities — rather than each agent crawling raw data in the moment it writes code. That, in his view, is the useful successor to &quot;shift left.&quot;</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="7-response-works-when-one-platform-"><b>7. Fully delegate the verifiable decisions; keep humans on remediation — for now</b></h3><p class="paragraph" style="text-align:left;">Where a decision is logically verifiable, Wetherald wants humans out of the loop, because it has to run across potentially millions of findings.</p><p class="paragraph" style="text-align:left;">&quot;where it&#39;s kinda logically verifiable, so exploitability ... in both camps, cloud and AppSec ... I don&#39;t think we should be having humans in the loop of that decision.&quot;</p><p class="paragraph" style="text-align:left;">Remediation is where teams still want a human on the final step. The path to more automation is data-driven, not a switch: if an action has succeeded several times, consider automating the next one, starting with simple, well-understood code and cloud fixes.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>📚 RELATED RESOURCES 🎧</b></h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">CISA Known Exploited Vulnerabilities Catalog</a> — authoritative list of what&#39;s being exploited; the July 7 additions carry a July 10 deadline</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Palo Alto Networks Unit 42 — Cloud Bucket Hijacking Risks</a> — the global-namespace reuse technique in detail</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Mandiant — Recovering Active ADFS Signing Keys via Machine DPAPI</a> — the Golden SAML evolution and detection guidance</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://socket.dev/blog/npm-pypi-campaign-typosquats-popular-secure-payment-apps?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Socket — npm/PyPI Payment-SDK Typosquat Campaign</a> — package list and IOCs</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://commission.europa.eu/news-and-media/news/new-eu-plan-address-risks-and-opportunities-advanced-ai-cybersecurity-2026-07-07_en?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">European Commission — Action Plan on Cybersecurity and AI</a> — the policy backdrop to the week&#39;s AI-exposure stories</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://links.cloudsecuritypodcast.tv/maze-code-to-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Maze</a> — Harry Wetherald&#39;s company; recently launched Maze Code (SCA + SAST-style AI agents)</p></li></ul><h3 class="heading" style="text-align:left;" id="podcast-episode"><b>Podcast Episode</b></h3><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a><b>  : </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/the-hidden-cost-of-blackbox-ai-bridging-cloud-and-code-security?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow"><b>Episode with Harry Wetherald</b></a></p></li></ul><hr class="content_break"><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔<b> </b><span style="color:rgb(20, 19, 34);"> </span>When you triage a finding, do you stop at &quot;reachable&quot; or do you actually confirm it&#39;s exploitable before it costs your team a week?<br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=fortibleed-turns-430-000-firewalls-into-a-ransomware-feed-why-exploitable-beats-reachable" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=f1cb8789-023c-483b-ab50-b7295a9d74e7&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🔑 MFA Was On and Attackers Walked Around It: Securing the Agent Control Plane with Open Source</title>
  <description>This week&#39;s cloud security news clustered around one shape: attacks on the management and identity plane, the systems that administer other systems. Five of six stories hit administrative interfaces, and in two of them MFA was configured and still routed around. We pair that with Ely Kahn, Chief Product Officer at Okta, on why long-lived overprivileged tokens are the agent-era breach, and how open standards like Cross-App Access (XAA), SPIFFE, and intent-based authorization are converging to answer who an AI agent is and what it can reach. </description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/60057179-8b59-4723-937c-6490358fa685/Screenshot_2026-07-01_at_5.30.01_PM.png" length="780476" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/mfa-agent-control-plane</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/mfa-agent-control-plane</guid>
  <pubDate>Wed, 01 Jul 2026 19:34:00 +0000</pubDate>
  <atom:published>2026-07-01T19:34:00Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><h2 class="heading" style="text-align:left;" id="hello-from-the-cloudverse"><span style="background-color:#28EEDA;"><b>Hello from the Cloud-verse!</b></span></h2><p class="paragraph" style="text-align:left;">This week’s Cloud Security Newsletter topic<b>: Agent Identity and the Control Plane — Why &quot;MFA Is On&quot; Stopped Being the Right Question</b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" rel="noopener noreferrer nofollow">(continue reading)</a> </p><hr class="content_break"><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://links.cloudsecuritypodcast.tv/maze-code-to-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source"><span class="button__text" style=""> This issue is sponsored by Maze </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/60057179-8b59-4723-937c-6490358fa685/Screenshot_2026-07-01_at_5.30.01_PM.png?t=1782923420"/></a><div class="image__source"><span class="image__source_text"><p>This image was generated by AI. It&#39;s still experimental, so it might not be a perfect match!</p></span></div></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;">The week did not produce one dramatic incident. It produced a cluster with a single tell: SimpleHelp remote management, Cisco Unified Communications Manager, Kemp LoadMaster, Oracle PeopleSoft&#39;s environment-management hub, and the Azure CLI login path all took direct fire in five days. These are not customer-facing apps. They are the interfaces that administer other systems, and the reader&#39;s exposure this week is less about any one CVE than about which admin surfaces are internet-reachable and whether their authentication actually covers every path in.</p><p class="paragraph" style="text-align:left;">Underneath that runs a sharper thread. In the Azure CLI spray and the SimpleHelp bypass, multi-factor authentication was present and got skipped anyway, not brute-forced but routed around, through a deprecated OAuth flow in one case and a forged, unsigned identity token in the other. That is the exact failure mode Ely Kahn spends this episode on — the Chief Product Officer at Okta, who joined five months ago specifically to work on agent identity after co-founding Sqrrl (acquired by AWS), launching AWS Security Hub, and serving as CPO at SentinelOne. His argument: the building blocks of identity have not changed, but the environment has, and the place teams keep getting hurt is the long-lived, overprivileged token.<i>[</i><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">⚡ TL;DR for Busy Readers</h2><ul><li><p class="paragraph" style="text-align:left;"><b>Nissan employee data breached via Oracle PeopleSoft zero-day (CVE-2026-35273)</b>: the victim-disclosure phase of a management-hub flaw — HR system-of-record for four countries reached through one internet-exposed admin component. Confirm no PSEMHUB instance is externally reachable.</p></li><li><p class="paragraph" style="text-align:left;">🚨 <b>Azure CLI password spray hit 78 accounts by routing around Conditional Access</b>: 81M attempts against the ROPC OAuth flow that issues tokens without an interactive MFA prompt. Set Conditional Access to All cloud apps / All client app types and block ROPC.</p></li><li><p class="paragraph" style="text-align:left;">🚨 <b>SimpleHelp RMM OIDC bypass (CVE-2026-48558) added to KEV, July 2 deadline</b>: the tool checked that a token existed but never checked it was signed by the real issuer — a supplier-shaped blast radius across every downstream customer. Patch above 5.5.15 and rotate reachable cloud/AI keys.</p></li><li><p class="paragraph" style="text-align:left;"><b>Cisco Unified CM SSRF (CVE-2026-20230) actively exploited, federal deadline already passed June 28</b>: blast radius decided by a config flag (WebDialer enabled), not a version number. Query for WebDialer enablement, not just patch level.</p></li><li><p class="paragraph" style="text-align:left;"><b>Kemp LoadMaster pre-auth RCE (CVE-2026-8037) now has a public exploit</b>: root on a load balancer is a position above the apps it fronts. No confirmed in-the-wild exploitation yet — patch or restrict the management API before scanning catches up.📰 <b>THIS WEEK&#39;S TOP 5 SECURITY HEADLINES</b></p></li></ul><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-nissan-discloses-employee-data-br"><b>1.  Nissan discloses employee data breach from the Oracle PeopleSoft zero-day (CVE-2026-35273)</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://www.bleepingcomputer.com/news/security/nissan-discloses-employee-data-breach-linked-to-oracle-zero-day-attacks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer</a> <br>Reporting: <a class="link" href="https://www.securityweek.com/nissan-employee-data-breached-in-oracle-peoplesoft-hack/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek</a>, <a class="link" href="https://www.infosecurity-magazine.com/news/nissan-oracle-peoplesoft-zero-day/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">Infosecurity Magazine</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">Nissan North America notified current and former employees that attackers exploiting Oracle PeopleSoft zero-day CVE-2026-35273 accessed personnel records. The flaw is a CVSS 9.8 unauthenticated SSRF-to-RCE bug in the PeopleTools Environment Management Hub (PSEMHUB); Oracle shipped emergency mitigations on June 10. Nissan filed its breach notification June 25, with public reporting on June 29. Researchers attribute the campaign to a cluster tracked as UNC6240, linked to the ShinyHunters extortion group; exposed data spans employees in the US, Canada, Mexico, and Brazil and may include payroll, banking, and government ID numbers.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;"> The CVE itself was covered in the June 18 brief; this is the victim-disclosure phase, where the enterprise cost of a management-hub flaw becomes visible. PSEMHUB administers PeopleSoft environments, so one exposed instance handed attackers the HR system of record for four countries. The exploitation window (May 27 to June 9) closed before Oracle&#39;s June 10 mitigation, so patch-on-disclosure was already too late for anyone internet-exposed. Programs that inventory only production customer apps and treat internal HR/ERP admin components as low priority keep learning about these through a breach-notification letter.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders: </b> Confirm whether any PeopleSoft PSEMHUB instance is reachable from outside your management network; if PeopleTools is at 8.61/8.62, verify the June 10 Oracle mitigation is applied and hunt for SSRF-pattern requests to PSEMHUB back to late May.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-azure-cli-passwordspray-campaign-"><b>2. </b><b>Azure CLI password-spray campaign compromised 78 accounts by routing around Conditional Access</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://www.huntress.com/blog/lshiy-password-spray-attack?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">Huntress</a> <br>Reporting: <a class="link" href="https://thehackernews.com/2026/07/azure-cli-password-spray-hits-at-least.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a>, <a class="link" href="https://www.securityweek.com/massive-password-spray-campaign-targeting-azure-cli/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">Huntress documented an automated password-spray campaign against Microsoft&#39;s Azure CLI login path, running more than 81 million attempts between June 12 and June 26 from an IPv6 range operated by LSHIY LLC (AS32167). At least 78 accounts across roughly 64 organizations were compromised. The attackers replayed breach-corpus username and password pairs against the Resource Owner Password Credentials (ROPC) OAuth flow, which posts credentials straight to the /token endpoint and issues tokens without an interactive MFA prompt.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">This is MFA that was configured and still bypassed. The Conditional Access policies at the affected orgs were real but scoped, enforced for admin portals or named apps rather than &quot;All cloud apps&quot; and &quot;All client app types,&quot; and ROPC lives in the gap. The control did not fail as code; it failed as coverage. This is the news-side proof of what Kahn argues in the interview: the question stopped being &quot;is MFA on?&quot; and became &quot;which authentication flows can reach a token without ever hitting the policy?&quot;</p><p class="paragraph" style="text-align:left;"><b>Action for defenders</b><b>:</b> In Entra, set Conditional Access to All cloud apps / All client app types, enable the userStrongAuthClientAuthNRequired tenant setting to block ROPC outright, then pull sign-in logs for ROPC/legacy-auth token grants over the June 12–26 window.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">🛠 <b>If you only do one thing this week:</b> Pull your Entra sign-in logs for ROPC and legacy-auth token grants over the June 12–26 window, then flip Conditional Access to All cloud apps / All client app types. Both this week&#39;s identity incidents (Azure CLI and SimpleHelp) succeeded by reaching a token through a path the policy never covered — closing the uncovered flow is the 30-minute action that maps directly to the week&#39;s editorial thesis.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-simple-help-rmm-oidc-bypass-cve-2"><b>☁️ 3. </b><b>SimpleHelp RMM OIDC bypass (CVE-2026-48558) added to KEV, exploited to drop the Djinn stealer</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">CISA KEV</a> <br>Reporting: <a class="link" href="https://www.helpnetsecurity.com/2026/06/30/simplehelp-vulnerability-exploited-cve-2026-48558/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">Help Net Security</a> <br>Analysis: <a class="link" href="https://arcticwolf.com/resources/blog/cve-2026-48558-critical-authentication-bypass-vulnerability-in-simplehelp-rmm-exploited-for-credential-theft-and-malware-delivery/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">Arctic Wolf</a>, <a class="link" href="https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">Horizon3.ai</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b><br>CISA added CVE-2026-48558 to the KEV catalog on June 29 with a July 2 deadline. The flaw is an OIDC authentication bypass in SimpleHelp RMM (versions 5.5.15 and earlier, plus 6.0 pre-releases): when OIDC is enabled, the software does not verify the cryptographic signature on identity tokens, so a remote unauthenticated attacker can forge a token, land a fully authenticated technician session, and bypass MFA in some configurations. Blackpoint Cyber documented attackers using the forged session to deploy a Node.js loader (TaskWeaver) and a new credential stealer (Djinn).</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b><br>RMM is a supplier-shaped blast radius. SimpleHelp is widely used by MSPs and IT-service providers, so one forged technician token is not one endpoint but every downstream customer that provider reaches. The failure is precise: the tool checked that a token existed but never checked it was signed by the real issuer, so MFA sat behind a step the attacker could skip. This is Kahn&#39;s identity-proof point made concrete knowing a session is who it claims to be is the whole game, and reporting that the forged access harvested cloud and AI API keys turns a remote-support compromise directly into cloud-account access.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders</b><br>If you run SimpleHelp, patch above 5.5.15 immediately and rotate any cloud/AI provider keys reachable from serviced endpoints; if a vendor uses SimpleHelp to support you, ask them today which version they run and whether they have hunted for TaskWeaver/Djinn indicators.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-cisco-unified-cm-ssrf-cve-2026202">🏥<b> 4. </b><b>Cisco Unified CM SSRF (CVE-2026-20230) added to CISA KEV with a June 28 federal deadline</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://www.cisa.gov/news-events/alerts/2026/06/25/cisa-adds-two-known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">CISA KEV alert (2026-06-25)</a> <br>Reporting: <a class="link" href="https://www.bleepingcomputer.com/news/security/cisa-sets-urgent-deadline-to-fix-cisco-flaw-exploited-in-attacks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer</a>, <a class="link" href="https://thehackernews.com/2026/06/cisco-unified-cm-flaw-exploited-after.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">CISA added CVE-2026-20230, a CVSS 8.6 server-side request forgery bug in Cisco Unified Communications Manager, to the KEV catalog on June 25 and set a June 28 remediation deadline for federal agencies under BOD 26-04. Cisco patched the flaw on June 3; the SSRF targets the WebDialer service and lets an unauthenticated attacker write arbitrary files to the underlying OS, which chains to root-level code execution. The security firm Defused reported in-the-wild exploitation beginning the weekend of June 21–22, after a public write-up exposed the file-write path.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">The exploit reached active use only after a proof-of-concept made the SSRF-to-file-write step concrete - a live example of the disclosure-to-exploitation gap collapsing once someone publishes the hard part. Blast radius here is set by a configuration flag, not a version number: only deployments with WebDialer enabled are exploitable, and WebDialer is off by default. That inverts the usual triage. A program sorting purely by CVSS will either over-rotate on patched-but-not-vulnerable hosts or miss the enabled ones.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders</b><br>Query your Unified CM estate for WebDialer enablement rather than version alone; where it is on and not needed, disable it, and confirm the June 3 Cisco patch is applied on any host exposing the service.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-public-exploit-chain-drops-for-cr"><b>🛡️ 5. </b><b>Public exploit chain drops for critical Progress Kemp LoadMaster pre-auth RCE (CVE-2026-8037)</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">watchTowr Labs</a> <br>Reporting: <a class="link" href="https://thehackernews.com/2026/06/progress-kemp-loadmaster-flaw-could-let.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a>, <a class="link" href="https://cybersecuritynews.com/critical-progress-kemp-loadmaster-vulnerability/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">Cyber Security News</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">On June 29, watchTowr Labs published a full technical write-up and working exploit chain for CVE-2026-8037, a CVSS 9.8 pre-authentication RCE in Progress Kemp LoadMaster. The bug is an uninitialized-memory/string-termination flaw in the escape_quotes() function meant to sanitize input before it reaches a shell command; anyone who can reach the appliance API can run arbitrary commands as root with no credentials. Progress published its advisory on June 4 (the flaw was reported by Syed Ibrahim Ahmed of TrendAI Research) and says it has no reports of exploitation, but a working PoC is now public.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">A load balancer sits in front of application traffic and terminates sessions, so root on the LoadMaster is a position above the apps it fronts, not beside them. The clock started June 29: the vendor advisory sat for three-plus weeks at low urgency, and the watchTowr publication is the event that converts it into a mass-scan target because it hands attackers the exact primitive. This is the pre-exploitation window in real time — patch status, not incident response, is still the lever, but only until scanning catches up. To be precise: there is no confirmed in-the-wild exploitation yet, so treat this as a public-PoC story, not an active-exploitation one.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders:</b><a class="link" href="https://workspaceupdates.googleblog.com/2026/03/ransomware-detection-and-file-restoration-for-Google-Drive-now-generally-available.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow"> </a><br>Treat any internet-reachable Kemp LoadMaster management API as urgent: apply the Progress fix from the June 4 advisory, and if patching lags, restrict API access to a management network now rather than waiting for exploitation reports.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-supplychain-attacks-shift-to-ai-d"><b>6. </b><b>Aflac Japan discloses breach affecting 4.38 million customers</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://www.securityweek.com/aflac-japan-data-breach-impacts-4-38-million/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek</a> <br>Reporting: <a class="link" href="https://www.japantimes.co.jp/business/2026/06/30/aflac-hack-4-million/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">The Japan Times</a>, <a class="link" href="https://securityaffairs.com/194488/data-breach/hackers-steal-data-of-4-38-million-aflac-japan-customers.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">Security Affairs</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> Aflac Life Insurance Japan, the Japan subsidiary of US insurer Aflac, disclosed on June 30 that attackers reached its customer website and related systems, exposing data on about 4.38 million customers and roughly 40,000 agencies. Intruders accessed systems repeatedly between June 15 and June 25, when a traffic surge revealed the activity. Exposed records include names, addresses, dates of birth, and policy details, plus bank account numbers used for premium payments for about 230,000 customers; credit card and national ID numbers were not affected, and Aflac says its US systems are not involved.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b>  For this reader base the signal is subsidiary-and-parent risk, not the raw record count. A US-headquartered insurer&#39;s non-US subsidiary was breached on infrastructure the parent likely does not administer or monitor directly, yet the parent&#39;s name carries the disclosure. The month of dwell between first access (June 15) and detection-by-load-surge (June 25) is the tell: detection came from a performance anomaly rather than a security control, which is what happens when a subsidiary sits outside the parent&#39;s monitoring perimeter. The banking data for 230,000 customers is the part that turns this from notification into fraud exposure.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders:</b> If your org has subsidiaries or acquired entities on separately managed stacks, confirm they feed the same detection and logging pipeline as the parent; a load-driven discovery a month in is evidence the perimeter did not extend to them.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="agent-identity-who-the-agent-is-wha"><b>Agent identity: who the agent is, what it can reach, what it&#39;s doing and how do you offboard it?</b></h3><p class="paragraph" style="text-align:left;">Two of this week&#39;s stories are token problems wearing different clothes. Azure CLI issued tokens through an OAuth flow that never met the policy; SimpleHelp accepted tokens it never verified were signed. Kahn&#39;s episode is the conceptual layer under both: as autonomous agents multiply, the same two questions — is this identity real, and is this access still appropriate — stop being solved by static permissions and start requiring standards built for identities whose goals change every day. The through-line for the week is that the management and identity plane is where the damage now lands, and agent identity is the version of that problem heading straight for every enterprise that shipped an agent this quarter. [<a class="link" href="https://www.cloudsecuritypodcast.tv/videos/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">Listen to the full episode →</a>] </p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="featured-experts-this-week"><b>Featured Experts This Week </b>🎤</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/elykahn/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow"><b>Ely Kahn</b></a> — Chief Product Officer, Okta</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Non-human / AI-agent identity</b>: the identity assigned to a software agent or workload rather than a person. Kahn&#39;s point is that the building blocks (least privilege, governance, monitoring) are the same as for humans, but agents get new goals constantly, so static permission models break.</p></li><li><p class="paragraph" style="text-align:left;"><b>ROPC (Resource Owner Password Credentials)</b>: an OAuth flow that posts a username and password straight to the token endpoint and returns a token without an interactive MFA prompt — the flow the Azure CLI campaign abused to sit in the gap left by scoped Conditional Access.</p></li><li><p class="paragraph" style="text-align:left;"><b>OIDC (OpenID Connect)</b>: an identity layer on top of OAuth. The SimpleHelp flaw was an OIDC bypass: the software accepted identity tokens without checking their cryptographic signature, so a forged token passed as authentic.</p></li><li><p class="paragraph" style="text-align:left;"><b>XAA (Cross-App Access)</b>: as Kahn describes it, &quot;an extension of OAuth&quot; and an open standard led by Okta with partners including Anthropic, letting apps and agents &quot;securely pass the baton to one another&quot; without static master keys or per-action consent pop-ups. Now built into the MCP server protocol. Developer resource: <a class="link" href="https://xaa.dev?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">xaa.dev</a>.</p></li><li><p class="paragraph" style="text-align:left;"><b>ID-JAG (identity assertion grant)</b>: the mechanism under XAA that puts an identity provider in the middle of app-to-app interactions and grants access without consent pop-ups.</p></li><li><p class="paragraph" style="text-align:left;"><b>SPIFFE</b>: gives every workload or agent a unique, verifiable digital identity, cryptographically encoded into a short-lived document (typically an X.509 certificate) used to prove identity within an environment.</p></li><li><p class="paragraph" style="text-align:left;"><b>Intent-based security</b>: a model with zero standing privilege where, at tool-invocation time, an assessment checks whether the tool call aligns with the agent&#39;s intent; a dynamic permission is generated for that single call and revoked on completion.</p></li><li><p class="paragraph" style="text-align:left;"><b>Guardian agents</b>: agents that assess whether a given tool invocation is acceptable and aligned to what the monitored agent was set up to do — the enforcement mechanism when human approval can&#39;t scale.</p></li><li><p class="paragraph" style="text-align:left;"><b>Kill switch / universal logout</b>: an Okta capability, originally for human identities and now extended to agents, to cut off a compromised agent&#39;s access immediately and universally.</p></li><li><p class="paragraph" style="text-align:left;"><b>MCP (Model Context Protocol)</b>: the standardized way agents connect to external tools and data; Kahn notes XAA is now part of the MCP server protocol maintained by Anthropic.</p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <a class="link" href="https://links.cloudsecuritypodcast.tv/maze-code-to-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow"><b>Maze</b></a></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>Agent Identity and the Control Plane</b></p><p class="paragraph" style="text-align:left;">Kahn frames agent identity as a paradox: in the mechanics it is not new, and in the environment it is completely new. &quot;In some ways it&#39;s not different at all in that you need, uh, least privileged identities. You need to govern those identities through things like IGA. You need to provision access to privileged resources through things like PAM.&quot; The building blocks — IGA, PAM, ISPM, ITDR — carry over. What breaks is the assumption underneath them.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-the-breach-is-the-longlived-overp"><b>1. The breach is the long-lived, overprivileged token</b></h3><p class="paragraph" style="text-align:left;">Human roles are stable enough to tolerate static permissions. Agents are not. &quot;You&#39;re giving them new problems to solve all of the time, and the most effective agents are the ones that are gonna be very autonomous. And it&#39;s very hard to predefine every permission that autonomous agent may need.&quot; The workaround teams reach for is the dangerous one:</p><p class="paragraph" style="text-align:left;">&quot;People give agents long-lived, broadly scoped permissions to basically do anything that they may need to do in the future, and this is where companies can get into trouble.&quot;</p><p class="paragraph" style="text-align:left;">Kahn&#39;s example is a recent one he keeps unnamed on purpose. &quot;There was a big one in April, a vibe coding company had their entire source code&quot; stolen:</p><p class="paragraph" style="text-align:left;">&quot;They had their entire source code stolen basically because of an attacker found a token, a long-lived, overprivileged token associated with the agent that they were using, this was a third-party agent, and then used that to move into the company, move laterally, and ultimately get access to that source code.&quot;</p><p class="paragraph" style="text-align:left;">That is the same primitive as this week&#39;s Azure CLI and SimpleHelp stories: a credential that outlived its need and reached further than it should have.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-assume-breach-on-agents-because-p"><b> 2. Assume breach on agents, because prompt injection isn&#39;t going away</b></h3><p class="paragraph" style="text-align:left;">Kahn&#39;s reason that identity is &quot;suddenly invited to the cool kids&#39; table&quot; is blunt:</p><p class="paragraph" style="text-align:left;">&quot;I think the reason for this is agents will be breached. I don&#39;t think this problem of prompt injection is, is gonna go away anytime soon. And we have to assume breach on agents.&quot;</p><p class="paragraph" style="text-align:left;">Ashish Rajan, who started his own career in identity, agreed from the research side:</p><p class="paragraph" style="text-align:left;">&quot;prompt injection is almost an impossible problem to solve with the way we use systems today.&quot;</p><p class="paragraph" style="text-align:left;">The consequence is a shift in where the effort goes. If you cannot reliably stop the agent from being manipulated, you contain what a manipulated agent can do. In Kahn&#39;s words, &quot;ensuring that they have secure, least privilege identities is the highest ROI security action that you can do.&quot;</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-xaa-is-the-middle-path-between-ma"><b>3. XAA is the middle path between master keys and consent-popup fatigue</b></h3><p class="paragraph" style="text-align:left;">Ask an agent to check Slack, read a calendar, and update a project board, and historically developers had two bad options:</p><p class="paragraph" style="text-align:left;">&quot;Either give that AI agent a permanent master key, like a static API key, which is, as we know, very unsafe if leaked... or bombard the user with constant annoying, &#39;Do you give permission?&#39; pop-ups every single time the AI tries to do something.&quot;</p><p class="paragraph" style="text-align:left;">Cross-App Access is Kahn&#39;s answer: predefine which apps an agent may reach, then let an identity provider broker access via ID-JAG without per-action prompts. It operates on behalf of a human at the intersection of the human&#39;s and the agent&#39;s permissions — &quot;so it&#39;ll always be least privilege&quot; — or fully autonomously with the agent&#39;s own identity. Kahn is emphatic that this is not proprietary lock-in: &quot;this is an open standard. It can be used by anyone,&quot; and it is now part of the Anthropic-maintained MCP server protocol.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-spiffe-and-xaa-solve-different-ha"><b>4. SPIFFE and XAA solve different halves of the same puzzle</b></h3><p class="paragraph" style="text-align:left;">Teams that already run SSO and SAML ask which new standard to pick. Kahn&#39;s answer is that it is not a choice:</p><p class="paragraph" style="text-align:left;">&quot;SPIFFE is, you know, is this, what&#39;s the identity of this agent?... versus XAA is really about what resources can that agent connect to.&quot;</p><p class="paragraph" style="text-align:left;">SPIFFE proves identity inside your environment with a short-lived X.509 credential; XAA governs what that proven agent can reach across apps, which fits SaaS-heavy estates. Kahn also flags newer cross-company work — a Linux Foundation initiative modeled on DNS that would give each agent a &quot;passport ID&quot; that works across domains.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-authorization-has-four-maturity-l"><b>5. Authorization has four maturity levels, and the top one has no standing privilege</b></h3><p class="paragraph" style="text-align:left;">Kahn lays out a ladder. Service-account API keys with broad access sit at the bottom (&quot;that&#39;s where we need to move away from as quickly as possible because the blast radius is so big&quot;). Coarse-grained scopes with short-lived ephemeral tokens are next — how XAA works. Fine-grained access that honors data sensitivity and labels comes after. The top rung is aspirational:</p><p class="paragraph" style="text-align:left;">&quot;the agent has zero standing privilege. No access is given to the agent in terms of standing privileges. And instead, at tool invocation time, an assessment is made as to whether that agent is trying to make a tool call that is aligned with the intent of that agent. And then a dynamic permission is generated and granted for that agent to make just that single tool call, and then is revoked once it&#39;s completed.&quot;</p><p class="paragraph" style="text-align:left;">Because human approval cannot scale to autonomous-agent volume, Kahn expects &quot;guardian agents that are assessing whether that tool invocation is acceptable or not.&quot;</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="6-nobody-is-offboarding-agents-and-"><b>6. Nobody is offboarding agents and there needs to be a kill switch</b></h3><p class="paragraph" style="text-align:left;">Rajan raised the gap directly: &quot;I don&#39;t know anyone who&#39;s talking about offboarding an AI agent... People just make agents and they walk away from it.&quot; Kahn&#39;s answer runs on two tracks. Governance-side, agent offboarding &quot;does look a lot like human off-boarding&quot; — joiner/mover/leaver reviews, access campaigns, and analysis of toxic permission combinations, with AI layered in to flag agents that hold scopes they never use. Runtime-side, there is the kill switch:</p><p class="paragraph" style="text-align:left;">&quot;once you&#39;ve identified that there is malicious or suspicious behavior, you want an ability to cut off agent access immediately and universally. And this is where the idea of a kill switch comes into play.&quot;</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="7-response-works-when-one-platform-"><b>7. The MVP governance bar is three questions</b></h3><p class="paragraph" style="text-align:left;">For a CISO adding agents to an existing identity program, Kahn reduces the bar to three questions: where are my agents (known and shadow, including browser-level and locally installed agents and their MCP servers), what can they connect to (XAA and agentic identity governance), and what are they doing (runtime monitoring through an agent or MCP gateway that logs every tool invocation and feeds anomaly detection). If a team can only start in two places, he is specific:</p><p class="paragraph" style="text-align:left;">&quot;knowing where your agents are and importing them into a registry. And then secondly, ensuring that you&#39;re at least assigning those AI agents coarse-grained scopes, and not using API access keys with broad permissions.&quot;</p><p class="paragraph" style="text-align:left;">Which lands back where the week started: the reachable, overprivileged, unverified credential is the exposure, whether it belongs to an admin interface or an agent.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>📚 RELATED RESOURCES 🎧</b></h2><p class="paragraph" style="text-align:left;"><b>AppSec & DevSecOps Guidance</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.huntress.com/blog/lshiy-password-spray-attack?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">Huntress — Azure CLI password-spray research</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">CISA Known Exploited Vulnerabilities Catalog</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cisa.gov/news-events/alerts/2026/06/25/cisa-adds-two-known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">CISA KEV alert, June 25, 2026 (Cisco Unified CM)</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">watchTowr Labs — Kemp LoadMaster pre-auth RCE write-up</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/nissan-discloses-employee-data-breach-linked-to-oracle-zero-day-attacks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer — Nissan / Oracle PeopleSoft breach</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://arcticwolf.com/resources/blog/cve-2026-48558-critical-authentication-bypass-vulnerability-in-simplehelp-rmm-exploited-for-credential-theft-and-malware-delivery/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">Arctic Wolf — SimpleHelp CVE-2026-48558 analysis</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/aflac-japan-data-breach-impacts-4-38-million/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek — Aflac Japan breach</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.okta.com/en-gb/solutions/cross-app-access/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow"><b>Okta - Cross App Access</b></a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://xaa.dev/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">https://xaa.dev/</a> </p></li></ul><h3 class="heading" style="text-align:left;" id="podcast-episode"><b>Podcast Episode</b></h3><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a><b>  : </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow"><b>Episode with Ely Kahn</b></a></p></li></ul><hr class="content_break"><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔<b> </b><span style="color:rgb(20, 19, 34);"> </span>Do you know which authentication flows in your tenant can reach a token without ever hitting your MFA policy?<br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=mfa-was-on-and-attackers-walked-around-it-securing-the-agent-control-plane-with-open-source" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=7b5b7a27-1c5f-490b-b5d1-577aa10cc3c3&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🚨 The Klue OAuth Token Breach: Why Stolen Credentials Now Get Used in Seconds, Not Days</title>
  <description>A forgotten OAuth token at Klue exposed Salesforce CRM data across a string of security vendors this week, while AI models surfaced a 29-year-old Squid proxy bug and OpenAI shipped a model built to find and patch vulnerabilities. Varonis incident responder Simon Biggs explains why automated post-compromise activity now lands seconds after a token is stolen, why attacks have flipped from encryption-first to data-first, and why the only durable defense is logging and classification done before the breach. </description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/74f50e96-30c2-486b-b101-84588f9c72b1/Screenshot_2026-06-24_at_10.45.30_PM.png" length="1084571" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/data-first-attacks</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/data-first-attacks</guid>
  <pubDate>Wed, 24 Jun 2026 21:55:58 +0000</pubDate>
  <atom:published>2026-06-24T21:55:58Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><h2 class="heading" style="text-align:left;" id="hello-from-the-cloudverse"><span style="background-color:#28EEDA;"><b>Hello from the Cloud-verse!</b></span></h2><p class="paragraph" style="text-align:left;">This week’s Cloud Security Newsletter topic<b>: Data-first attacks break forensic assumption and logging is the only fix that scales</b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" rel="noopener noreferrer nofollow">(continue reading)</a> </p><hr class="content_break"><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days"><span class="button__text" style=""> This issue is sponsored by Varonis </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/74f50e96-30c2-486b-b101-84588f9c72b1/Screenshot_2026-06-24_at_10.45.30_PM.png?t=1782337569"/></a><div class="image__source"><span class="image__source_text"><p>This image was generated by AI. It&#39;s still experimental, so it might not be a perfect match!</p></span></div></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;">The pattern across this week&#39;s incidents is hard to miss: bug discovery is moving at AI speed while the damage still runs through old, ordinary plumbing — an abandoned OAuth token, a decades-old C bug, stolen RDP credentials. That gap is exactly where Simon Biggs spends his time. Biggs is a cyber incident response specialist on the forensics team at Varonis, with roughly 15 years in the field, starting in UK cyber law enforcement and later doing consultancy IR at NCC Group. Ashish Rajan sat down with him at Infosecurity Europe to ask the question on everyone&#39;s mind this year: is there actually a wave of sophisticated AI attacks, and what does forensics look like when the attacker is automating?</p><p class="paragraph" style="text-align:left;">His answer is more useful than the hype. AI is not unlocking the impossible — it is lowering the barrier to entry and compressing the timeline. The defensive consequence is concrete and unglamorous: if you can&#39;t trace a clear path from your data back to an endpoint, and you haven&#39;t classified your data in advance, you won&#39;t be able to tell a customer, a regulator, or a contractually-armed third party what was taken.<i>[</i><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/ai-powered-forensics-how-attackers-automate-breaches?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">⚡ TL;DR for Busy Readers</h2><ul><li><p class="paragraph" style="text-align:left;"><b>Klue OAuth breach → Salesforce CRM theft:</b> A forgotten, never-revoked OAuth token let attackers exfiltrate CRM data from Klue&#39;s customers, with extortion group &quot;Icarus&quot; claiming the theft. Pull your Salesforce Connected Apps OAuth usage and revoke any integration without an owner.</p></li><li><p class="paragraph" style="text-align:left;"><b>AI is finding old bugs faster than you can patch them:</b> &quot;Squidbleed&quot; (a 1997 Squid proxy flaw) was surfaced with help from Anthropic&#39;s Mythos model the same week OpenAI shipped GPT-5.5-Cyber. Treat disclosure-to-exploit windows as effectively zero for perimeter assets.</p></li><li><p class="paragraph" style="text-align:left;"><b>PixelSmash (CVE-2026-8461) puts RCE in your media-processing tier:</b> Any service that transcodes or thumbnails uploaded media via FFmpeg/libavcodec is exposed pre-auth. Inventory what links libavcodec and patch to 8.1.2.</p></li><li><p class="paragraph" style="text-align:left;"><b>Attacks are now data-first, not encryption-first:</b> Biggs sees crafted SQL queries pulling credentials and PII within minutes of access. Without database and egress logging, forensics can&#39;t tell you what left.</p></li><li><p class="paragraph" style="text-align:left;"><b>Prepare before the breach:</b> Data classification and a clean audit path from data to endpoint are the difference between &quot;your data is out of scope&quot; and &quot;we don&#39;t know.&quot; Run a dry-run IR exercise on one critical data store this week.</p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="this-weeks-security-news">📰 <b>THIS WEEK&#39;S TOP 5 SECURITY HEADLINES</b></h2><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-klue-o-auth-breach-feeds-icarus-e"><b>1. Klue OAuth breach feeds &#39;Icarus&#39; extortion across multiple security vendors</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer</a> <br>Reporting: <a class="link" href="https://techcrunch.com/2026/06/22/klue-hack-results-in-data-breach-at-several-cybersecurity-firms/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">TechCrunch</a>, <a class="link" href="https://thehackernews.com/2026/06/salesforce-disables-klue-app.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a>, <a class="link" href="https://www.csoonline.com/article/4187907/klue-breach-exposed-salesforce-crm-data-through-stolen-oauth-tokens.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">CSO Online</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">Competitive-intelligence vendor Klue was compromised through a long-lived OAuth credential created years earlier for an abandoned integration and never revoked. The attacker pivoted into Klue&#39;s infrastructure, harvested the OAuth tokens Klue used to connect to customers&#39; Salesforce tenants, and ran automated REST API queries to enumerate and exfiltrate CRM records. Salesforce disabled the Klue Battlecards integration on June 11. By June 22, reported victims included Huntress, Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity [VERIFY — victim names from secondary reporting]. A group calling itself Icarus, active since late April, claimed the theft and sent 48-hour extortion emails.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">Initial access was not a zero-day or a phished password — it was a forgotten OAuth token with no expiry. The detection surface is your third-party integration inventory, not your endpoint telemetry. A Salesforce-connected app holds standing API access to CRM data, so one compromised vendor becomes direct CRM exfiltration across its entire customer base without ever touching a customer&#39;s perimeter. That several reported victims are themselves security vendors makes the point: blast radius follows the integration graph, not the maturity of the target.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders: </b> Pull the full list of authorized connected apps in Salesforce (Setup → Connected Apps OAuth Usage), revoke tokens for any integration without an active business owner, and apply token expiry and IP restrictions to the rest.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-pixel-smash-f-fmpeg-decoder-flaw-"><b>2. </b><b>PixelSmash: FFmpeg decoder flaw (CVE-2026-8461) turns one video file into RCE</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">JFrog Vulnerability Research</a> <br>Reporting: <a class="link" href="https://www.securityweek.com/ffmpeg-pixelsmash-flaw-allows-rce-on-video-players-media-servers-nas-appliances/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">JFrog disclosed a heap out-of-bounds write in FFmpeg&#39;s MagicYUV decoder, CVE-2026-8461 (CVSS 8.8). A crafted AVI, MKV, or MOV file processed by any application linked against libavcodec can corrupt heap metadata and hijack an internal FFmpeg callback pointer. JFrog demonstrated a full chain overwriting the <a class="link" href="https://AVBuffer.free?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">AVBuffer.free</a> pointer with system() to run arbitrary commands, including RCE against Jellyfin. Confirmed-affected software includes Kodi, mpv, ffmpegthumbnailer (used by GNOME, KDE, XFCE), Jellyfin, Emby, Nextcloud, Immich, PhotoPrism, and OBS Studio. FFmpeg shipped the fix in version 8.1.2 on June 17.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">The vulnerable path runs wherever media gets transcoded or thumbnailed automatically — upload pipelines, NAS appliances, and self-hosted apps like Nextcloud and Immich that decode user-supplied files with no human in the loop. Exploitation is pre-authentication and server-side for any service ingesting media, so the exposure sits in your file-processing tier, not on user desktops. FFmpeg is a transitive dependency most teams don&#39;t track, so the question is &quot;which of my running services link libavcodec,&quot; not &quot;do we use FFmpeg.&quot;</p><p class="paragraph" style="text-align:left;"><b>Action for defenders</b><b>:</b> Inventory services that decode or thumbnail uploaded media, confirm the bundled libavcodec/FFmpeg version, and apply 8.1.2 or your distro&#39;s backport. Where immediate patching isn&#39;t possible, restrict the decoders and container formats FFmpeg will accept.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">🛠 <b>If you only do one thing this week:</b> Run a 30-minute inventory of where stolen credentials or user-supplied files get standing access in your environment — Salesforce Connected Apps and any media-decoding service that links libavcodec. Revoke ownerless OAuth tokens and confirm your FFmpeg builds are at 8.1.2. Both of this week&#39;s worst stories (Klue, PixelSmash) start in places most teams never inventory.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-squidbleed-cve-202647729-a-1997-s"><b>☁️ 3. </b><b>&#39;Squidbleed&#39; (CVE-2026-47729): a 1997 Squid proxy bug, surfaced by an AI model</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://blog.calif.io/p/squidbleed-cve-2026-47729?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Calif.io research blog</a> <br>Reporting: <a class="link" href="https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a>, <a class="link" href="https://www.securityweek.com/decades-old-squid-proxy-flaw-squidbleed-can-expose-user-data/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b><br><a class="link" href="https://Calif.io?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Calif.io</a> publicly disclosed a heap over-read in Squid&#39;s FTP gateway, CVE-2026-47729, that returns raw heap memory to a requester including other users&#39; Authorization headers, cookies, and API keys. The bug traces to a 1997 commit. Calif credits Anthropic&#39;s Claude Mythos Preview model with flagging the root-cause quirk. PoC code is public; as of June 22 no in-the-wild exploitation had been reported. Reporting on the fixed version conflicts: some coverage cites Squid 7.6, other coverage points to 7.7 </p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b><br>Squid sits as a shared egress and caching proxy in front of many enterprise and cloud networks, so a memory disclosure here crosses user and tenant boundaries — one user&#39;s request can leak another&#39;s session token inside the component meant to broker trust. The Heartbleed comparison is about shape, not scale: passive, hard-to-detect leakage with no crash and no log entry. The discovery method is the second story a 29-year-old bug that survived decades of human review was surfaced by a model.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders</b><br>Inventory FortiSandbox appliances and confirm a fixed build, restrict WEB UI and management access to an admin segment, and hunt for the vendor/Defused indicators across the June window.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-open-ai-ships-gpt-55-cyber-for-au">🏥<b> 4. </b><b>OpenAI ships GPT-5.5-Cyber for automated vulnerability finding and patching</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://openai.com/index/gpt-5-5-with-trusted-access-for-cyber/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">OpenAI</a> <br>Reporting: <a class="link" href="https://www.infosecurity-magazine.com/news/openai-daybreak-gpt-5-5-cyber/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Infosecurity Magazine</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">OpenAI released GPT-5.5-Cyber under its Daybreak program, a model tuned to find vulnerabilities, validate exploitability, and generate patches in one workflow. OpenAI reported benchmark scores of 85.6% on CyberGym, 39.5% on ExploitGym, and 69.8% on SEC-bench Pro [VERIFY — vendor-reported]. Access is restricted to vetted defenders under added monitoring. OpenAI also updated its Codex Security plugin, which it says has scanned over 30 million commits across more than 30,000 codebases since March.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">This lands the same week Squidbleed showed a competing model finding a real 29-year-old bug, so the &quot;AI finds and fixes vulnerabilities&quot; claim now has production data points on both ends of the lifecycle. The consequence is asymmetry: the same exploit-generation capability that speeds your triage also lowers the cost of weaponizing a fresh disclosure, which compresses patch windows.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders</b><br>Treat disclosure-to-exploit windows as shorter by default in your patch SLAs. If you run an AppSec program, evaluate gated defensive models against your current SAST and triage baseline rather than assuming parity.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-accenture-takes-majority-stake-in"><b>🛡️ 5. </b><b>Accenture takes majority stake in Dragos, buys runZero and NetRise in ~$4.1B OT push</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://newsroom.accenture.com/news/2026/accenture-to-strengthen-critical-infrastructure-defense-with-end-to-end-cybersecurity-platform-in-age-of-ai-driven-cyber-threats-and-geopolitical-risk?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Accenture Newsroom</a> <br>Reporting: <a class="link" href="https://www.securityweek.com/accenture-to-acquire-majority-stake-in-dragos-all-of-runzero-netrise-in-4-1-billion-ot-cybersecurity-push/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek</a>, <a class="link" href="https://industrialcyber.co/news/accenture-expands-ot-cybersecurity-capabilities-with-dragos-stake-acquires-runzero-and-netrise/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Industrial Cyber</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">Accenture announced it will take a majority stake in OT security firm Dragos (valued around $3.25B) and acquire runZero and NetRise outright, for a combined enterprise value near $4.1B [VERIFY — combined figure varies across sources]. The three together generate roughly $208M in annual recurring revenue, with the transactions expected to close in August or September 2026. Announced June 18, just outside the strict window, but included as the period&#39;s structurally significant M&A.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">A systems integrator buying its way to a majority stake in the leading independent OT threat-intel vendor changes the buying calculus for asset owners. OT security shifts from a best-of-breed product decision toward a bundled integrator engagement — a procurement-structure change, not a logo swap. For cloud security leads with IT/OT convergence in scope, the open question is whether Dragos&#39;s roadmap and vendor neutrality survive inside a services firm.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders:</b><a class="link" href="https://workspaceupdates.googleblog.com/2026/03/ransomware-detection-and-file-restoration-for-Google-Drive-now-generally-available.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow"> </a><br>If you run Dragos, runZero, or NetRise, get contract-renewal and roadmap-continuity questions to your account team now. If you&#39;re evaluating OT monitoring, weigh integrator lock-in in the decision.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-supplychain-attacks-shift-to-ai-d"><b>6. </b><b>New &#39;Prinz Eugen&#39; ransomware encrypts newest files first and skips the ransom note</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://www.bleepingcomputer.com/news/security/new-prinz-eugen-ransomware-prioritizes-recent-files-for-encryption/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer</a> <br>Reporting: <a class="link" href="https://www.scworld.com/brief/new-prinz-eugen-ransomware-targets-recent-files-avoids-ransom-notes?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">SC Media</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> BleepingComputer reported a new Go-based ransomware, Prinz Eugen, that prioritizes the most recently modified files for encryption (alphabetical order on timestamp ties) and leaves no ransom note on the host. ThreatDown found hands-on-keyboard operators using legitimate RMM tooling and living-off-the-land binaries, with likely initial access through stolen RDP credentials and manual execution of a payload named servertool.exe. It uses ChaCha20-Poly1305 with Argon2id-derived keys and is not run as ransomware-as-a-service. At least five victims were identified, including Standard Bank, which refused a 1-BTC demand.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> Encrypting recently modified files first inverts the usual recovery assumption: high-value in-flight working data is hit before bulk archives, so an early detect-and-kill response that would normally cap damage can still lose the data that matters most. No ransom note and no affiliate model means the usual leak-site and negotiation-portal indicators are absent, so detection has to come from RMM and LOLbin behavior. The RDP-credential entry point and living-off-the-land tradecraft are exactly the &quot;acting like users&quot; pattern Biggs describes as the new normal.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders:</b> Audit external RDP exposure and remote-access MFA, add detection for unexpected RMM tools and for servertool.exe executed by non-admin processes, and confirm backups capture active working directories at a tight enough interval to survive recent-files-first encryption.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="datafirst-attacks-broke-the-forensi"><b>Data-first attacks broke the forensic assumption</b></h3><p class="paragraph" style="text-align:left;">The throughline of this week&#39;s news is the throughline of the episode: attackers don&#39;t need new capabilities, they need speed and reach, and AI gives them both. Biggs&#39;s sharpest observation is that the goal of the attack has changed. &quot;Attacks predominantly used to be... encryption first, right?... Now it&#39;s data first, practically no encryption.&quot; That single shift rewrites the incident response playbook. When the objective is exfiltration rather than encryption, the question your lawyers, regulators, and contractually-armed partners will ask is not &quot;is it back up?&quot; but &quot;what left, and whose was it?&quot;</p><p class="paragraph" style="text-align:left;">Here is the uncomfortable part, and the thing senior teams most often get wrong: forensics frequently cannot answer that question on its own. Windows artifacts show where an attacker moved and what they touched on a box, but they rarely prove what data went out the door. Without database query logging, without firewall egress that ties back to a specific endpoint, and without data classification done in advance, the honest answer to &quot;was my data taken?&quot; becomes &quot;we don&#39;t know&quot; — and that is the answer that ends customer relationships. The fix isn&#39;t a new product category. It&#39;s the unglamorous preparation work: a clean audit path from data to endpoint, and a first-pass classification of your CRMs and cloud storage so you can rule data in or out fast.[<a class="link" href="https://www.cloudsecuritypodcast.tv/videos/ai-powered-forensics-how-attackers-automate-breaches?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Listen to the full episode →</a>] </p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="featured-experts-this-week"><b>Featured Experts This Week </b>🎤</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/simon-j-biggs/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow"><b>Simon Biggs</b></a> — Cyber Incident Response Specialist, Varonis</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><b>OAuth token (standing API access):</b> A long-lived credential that grants an integration ongoing API access without re-authentication. In the Klue breach, a token created for an abandoned integration and never revoked became the initial access path into customer Salesforce tenants.</p></li><li><p class="paragraph" style="text-align:left;"><b>Data-first attack:</b> An exfiltration-led intrusion with &quot;practically no encryption,&quot; replacing the older encryption-first ransomware model (Biggs).</p></li><li><p class="paragraph" style="text-align:left;"><b>Living off the land (LOLbins):</b> Attackers acting like legitimate users — using compromised credentials and built-in/legitimate tooling instead of dropping malware — which shrinks the detection opportunity. Seen this week in the Prinz Eugen ransomware tradecraft.</p></li><li><p class="paragraph" style="text-align:left;"><b>BloodHound / Metasploit / Kali Linux:</b> Prepackaged offensive tool sets that historically lowered the barrier to entry. BloodHound maps Active Directory attack paths; Biggs uses these as the analogy for what AI now does on the fly.</p></li><li><p class="paragraph" style="text-align:left;"><b>Shadow AI:</b> Users routing around sanctioned, locked-down models to less-secure alternatives — &quot;a massive risk&quot; (Biggs).</p></li><li><p class="paragraph" style="text-align:left;"><b>Prompt injection:</b> Crafted input that makes an AI assistant carry out an unintended instruction. Varonis Threat Labs found a prompt-injection flaw in Microsoft Copilot.</p></li><li><p class="paragraph" style="text-align:left;"><b>Mythos:</b> Anthropic&#39;s Claude Mythos Preview model, credited this week with helping surface the Squidbleed Squid proxy bug; named by Biggs as a strong example of AI-assisted vulnerability research.</p></li><li><p class="paragraph" style="text-align:left;"><b>Heap out-of-bounds write / over-read:</b> Memory-safety bugs underlying both PixelSmash (write → RCE) and Squidbleed (over-read → secret disclosure).</p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <b><a class="link" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Varonis</a></b></p><p class="paragraph" style="text-align:center;"><i>AI Security Requires More Than Visibility. It Requires Control. </i></p><p class="paragraph" style="text-align:left;"><i>Security leaders are under pressure to enable AI innovation while managing a rapidly expanding attack surface across cloud, identity, and data layers. AI agents and copilots can introduce new access paths, automated high-impact actions, and accelerate threat timelines. </i></p><p class="paragraph" style="text-align:left;"><i><a class="link" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Varonis Atlas</a></i><i> helps organizations secure AI end-to-end - from understanding usage and enforcing guardrails to detecting suspicious activity and reducing risk dynamically. watch the recording </i><i><a class="link" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(17, 85, 204)">to learn how Varonis Atlas</a></i><i> can help security teams operationalize AI security at scale. </i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><hr class="content_break"><p class="paragraph" style="text-align:left;">A single-guest conversation that doubles as a field report from someone who works real breaches. The throughline: AI changes the speed and reach of attacks, not their fundamental nature — and the defensive answer is preparation, not a new control category.</p><h3 class="heading" style="text-align:left;" id="1-ai-lowers-the-barrier-and-raises-"><b>1: AI lowers the barrier and raises the speed — it is not a new class of attack</b></h3><p class="paragraph" style="text-align:left;">Biggs&#39;s front-line read cuts against the year&#39;s loudest marketing. AI increases scale and volume and lowers the skill required, but he is not seeing goals that were previously unachievable.</p><p class="paragraph" style="text-align:left;">&quot;But is AI driving something that&#39;s completely unseen? No, that&#39;s not what I&#39;m seeing on the front line... I just think that it&#39;s lowering that technical barrier to entry. They&#39;re getting quicker. They&#39;re able to achieve better outcomes quicker during an attack.&quot; — Simon Biggs</p><p class="paragraph" style="text-align:left;">Existing layered controls still work, and they matter more, because they slow attackers moving faster through the same paths.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-postcompromise-automation-now-hap"><b> 2: Post-compromise automation now happens with no hands on the keyboard</b></h3><p class="paragraph" style="text-align:left;">The clearest AI signal Biggs sees is timing — automated action arrives in seconds.</p><p class="paragraph" style="text-align:left;">&quot;<i>We&#39;re seeing sort of Microsoft Graph queries coming in like minutes, seconds after that token&#39;s been r- stolen via relay. That is unusual. Like that suggests there&#39;s no hands on the keyboard and, these AI kits are out there and are being used en masse, which is a big sea change...</i>&quot; — Simon Biggs</p><p class="paragraph" style="text-align:left;">This is the practitioner mirror of the Klue story above: a stolen token is exercised almost immediately. Signature-based detection fails against ephemeral, briefly-lived phishing infrastructure on cloud and containerized platforms.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-ai-is-the-new-metasploit-blood-ho"><b>3: AI is the new &quot;Metasploit/BloodHound&quot; — it removes the operator&#39;s expertise</b></h3><p class="paragraph" style="text-align:left;">Ashish Rajan framed the shift directly: &quot;<i>it&#39;s almost like what Metasploit did for Script Kiddies. Is this something similar?</i>&quot; — Ashish Rajan</p><p class="paragraph" style="text-align:left;">Biggs agreed, and took it further. Where chaining BloodHound output into Metasploit once required real expertise, models now pull the whole workflow together.</p><p class="paragraph" style="text-align:left;">&quot;So you don&#39;t actually have to be able to code, you don&#39;t actually have to really understand Active Directory... you can kinda get there without really any major technical skill, which is quite scary b- because that used to be, like a red team capability.&quot; — Simon Biggs</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-attacks-flipped-from-encryptionfi"><b>4: Attacks flipped from encryption-first to data-first</b></h3><p class="paragraph" style="text-align:left;">&quot;<i>Attacks predominantly used to be... encryption first, right?... Now it&#39;s data first, practically no encryption.</i>&quot; — Simon Biggs</p><p class="paragraph" style="text-align:left;">Response planning has to center on what data left, not what got encrypted. Biggs describes attackers taking a database schema, returning, and running a crafted query within minutes to pull credentials, payment contracts, and PII — behavior that used to be the preserve of nation-states and now shows up in ordinary ransom breaches.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-forensics-can-rarely-tell-you-wha"><b>5: Forensics can rarely tell you </b><i><b>what</b></i><b> was taken — and most teams overestimate it</b></h3><p class="paragraph" style="text-align:left;">&quot;<i>something I think people overestimate the ability of forensics to do is forensics to tell you what data&#39;s been taken... there&#39;s not many forensic artifacts that... will definitively tell you.</i>&quot; — Simon Biggs</p><p class="paragraph" style="text-align:left;">Windows forensics shows movement, not egress. Without database logging and per-endpoint firewall attribution, the answer to a lawyer&#39;s &quot;did it leave?&quot; is a hunch and lawyers don&#39;t notify on hunches. As Biggs puts it, &quot;it&#39;s part of the incident response lifecycle, the preparation stage. That&#39;s where the battle is, is won or lost.&quot;</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="6-the-defensive-playbook-is-the-sam"><b>6: The defensive playbook is the same fundamentals — run the attacker&#39;s models against yourself</b></h3><p class="paragraph" style="text-align:left;">There are no magic new controls. Shadow-AI discovery, permissions hygiene, inventory and auditing, and automated response are the same problems as shadow IT and excessive permissions, extended to a new platform. The agent &quot;is just an extension of the user&quot; and should be audited as one.</p><p class="paragraph" style="text-align:left;">&quot;<i>I&#39;m an advocate of saying run BloodHound or run Metasploit. So... come from the point of view of the attacker and see what you find. I think it&#39;s the same. Like, run the same models, do the same thing to your environment and see what it finds.</i>&quot; — Simon Biggs</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="7-a-idriven-research-widens-the-tar"><b>7: AI-driven research widens the target surface, and same-day PoCs collapse patch windows</b></h3><p class="paragraph" style="text-align:left;">&quot;<i>from something getting released in the patch, people have working proof of concepts the same day. In a lot of cases we&#39;re seeing proof of concepts for things that aren&#39;t even patched yet or aren&#39;t even announced as vulnerabilities.</i>&quot; — Simon Biggs</p><p class="paragraph" style="text-align:left;">The economics have shifted with it: &quot;You&#39;re not necessarily buying zero days for $50,000, $100,000. Somebody could get that in their bedroom. If they can afford the tokens.&quot; For perimeter assets, treat the disclosure-to-exploit window as effectively zero. PixelSmash and Squidbleed this week are the live examples.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="7-response-works-when-one-platform-"><b>8: Stolen data will be weaponized in new ways because AI lets attackers post-process at scale</b></h3><p class="paragraph" style="text-align:left;">&quot;<i>this information that&#39;s taken is gonna be weaponized in new and novel ways... what AI allows attackers to do is post-process data. So getting 10 terabytes of data is overwhelming... But now with AI, actually, they could be post-processing that data and... finding new and novel ways of monetizing it.</i>&quot; — Simon Biggs</p><p class="paragraph" style="text-align:left;">The liability follows. Third-party contracts increasingly require breach notification inside tight windows (often 72 hours, ahead of regulators like the ICO), and bigger partners &quot;<i>will come down heavy.</i>&quot; An up-front classification pass on CRMs and cloud storage — which Biggs calls an &quot;easy win&quot; — lets you rule a terabyte out of scope instead of notifying everyone on a hunch.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="practical-takeaways-for-cloud-secur"><b>Practical Takeaways for Cloud Security Leaders</b></h3><p class="paragraph" style="text-align:left;">Three things a senior team can act on: get a clean, queryable audit path from each critical data store back to an endpoint (logs that resolve to a real entity, not just an aggregator IP); do a first-pass data classification on CRMs and cloud storage so breach scope is answerable in minutes, not weeks; and run a dry-run IR exercise with someone offensive plus your blue team to find where the forensic trail dead-ends before an attacker does.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>📚 RELATED RESOURCES 🎧</b></h2><p class="paragraph" style="text-align:left;"><b>AppSec & DevSecOps Guidance</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Klue OAuth breach reporting — BleepingComputer</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">PixelSmash / CVE-2026-8461 research — JFrog</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.calif.io/p/squidbleed-cve-2026-47729?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Squidbleed / CVE-2026-47729 research — Calif.io</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://openai.com/index/gpt-5-5-with-trusted-access-for-cyber/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">GPT-5.5-Cyber announcement — OpenAI</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://newsroom.accenture.com/news/2026/accenture-to-strengthen-critical-infrastructure-defense-with-end-to-end-cybersecurity-platform-in-age-of-ai-driven-cyber-threats-and-geopolitical-risk?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Accenture / Dragos OT acquisition — Accenture Newsroom</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/new-prinz-eugen-ransomware-prioritizes-recent-files-for-encryption/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Prinz Eugen ransomware reporting — BleepingComputer</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.varonis.com/varonis-threat-labs?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Varonis Threat Labs - Blog</a></p></li></ul><h3 class="heading" style="text-align:left;" id="podcast-episode"><b>Podcast Episode</b></h3><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a><b>  : </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/ai-powered-forensics-how-attackers-automate-breaches?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow"><b>Episode with Simon Biggs</b></a></p></li></ul><hr class="content_break"><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔<b> </b><span style="color:rgb(20, 19, 34);"> </span> If you were breached today, could you prove what data left — or would the honest answer be &quot;we don&#39;t know&quot;?<br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-klue-oauth-token-breach-why-stolen-credentials-now-get-used-in-seconds-not-days" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=10ce256c-ca3e-482c-bccc-5316168b39b7&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>The Control Plane Was the Target This Week. Your AI SOC Might Miss Why.</title>
  <description>This week&#39;s exploited flaws sat in the management and trust plane itself — a SIEM (Splunk), a malware sandbox (FortiSandbox), a hosting control panel (LiteSpeed/cPanel), an SD-WAN controller (Cisco), and the HR system of record (Oracle PeopleSoft) — while the supply chain moved into AI developer tooling. We feature insights from Aqsa Taylor of Exaforce on &quot;vibe hunting&quot; and why an AI SOC that lacks context can hurt as much as help. </description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a3055ffe-8716-4b3d-89f4-20518c0d9f10/Screenshot_2026-06-18_at_3.45.56_PM.png" length="3757653" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/control-plane-targeted-ai-soc-context</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/control-plane-targeted-ai-soc-context</guid>
  <pubDate>Thu, 18 Jun 2026 13:49:39 +0000</pubDate>
  <atom:published>2026-06-18T13:49:39Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><h2 class="heading" style="text-align:left;" id="hello-from-the-cloudverse"><span style="background-color:#28EEDA;"><b>Hello from the Cloud-verse!</b></span></h2><p class="paragraph" style="text-align:left;">This week’s Cloud Security Newsletter topic<b>: The AI SOC is only as good as the data it reasons over </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" rel="noopener noreferrer nofollow">(continue reading)</a> </p><hr class="content_break"><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why"><span class="button__text" style=""> This issue is sponsored by Varonis </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a3055ffe-8716-4b3d-89f4-20518c0d9f10/Screenshot_2026-06-18_at_3.45.56_PM.png?t=1781790412"/></a><div class="image__source"><span class="image__source_text"><p>This image was generated by AI. It&#39;s still experimental, so it might not be a perfect match!</p></span></div></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;">The pattern this week was uncomfortable: the systems an enterprise runs to see, operate, or protect everything else were the ones under attack. A pre-auth RCE chain landed in Splunk, the box your IR team would use to spot an intruder. FortiSandbox, the appliance that detonates files you don&#39;t trust, came under active exploitation. And Oracle PeopleSoft, the system of record for HR and payroll data, was exploited by ShinyHunters before any patch existed. When the exploited surface is the control plane, the blast radius isn&#39;t one host — it&#39;s the tooling you&#39;d otherwise use to find and contain the others.</p><p class="paragraph" style="text-align:left;">That makes this week&#39;s episode well-timed. Ashish Rajan sat down with <a class="link" href="https://www.linkedin.com/in/aqsa-taylor/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow"><b>Aqsa Taylor</b></a>, Chief Security Evangelist at Exaforce (and formerly a product lead on Twistlock and Prisma Cloud), for a conversation about &quot;vibe hunting&quot; applying AI agents to threat hunting the way vibe coding applies them to development and what actually separates an AI SOC that earns trust from one that buries a real alert. Her throughline connects directly to the news: the AI is only as good as the data and context it reasons over. (Disclosure: Exaforce sponsored this episode.)<i>[</i><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/the-4-pillars-of-ai-soc-from-threat-hunting-to-vibe-hunting?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">⚡ TL;DR for Busy Readers</h2><ul><li><p class="paragraph" style="text-align:left;">🚨 <b>Oracle&#39;s patch arrived after the compromise had already begun.</b> Review logs back to late May, not just the disclosure date.</p></li><li><p class="paragraph" style="text-align:left;"><b>A critical Splunk flaw exposed a surprising reality:</b> deployment topology may matter more than patch status when assessing exposure.</p></li><li><p class="paragraph" style="text-align:left;"><b>FortiSandbox exploitation turned a security control into the attack surface itself.</b></p></li><li><p class="paragraph" style="text-align:left;"><b>Cisco SD-WAN and LiteSpeed joined CISA&#39;s KEV list</b>, continuing a trend of attackers targeting management and control systems.</p></li><li><p class="paragraph" style="text-align:left;"><b>AI developer tooling became the latest supply-chain target</b>, with compromised packages and fake AI assistants hunting for API keys.</p></li><li><p class="paragraph" style="text-align:left;">🎯 <b>The pattern matters more than the CVEs:</b> attackers spent this week targeting the systems used to manage, detect, analyse, and govern everything else.</p></li><li><p class="paragraph" style="text-align:left;">🤖 <b>From this week&#39;s podcast:</b> Aqsa Taylor (Exaforce) explains why AI SOC platforms fail without context, why &quot;vibe hunting&quot; is gaining traction, and why the future of detection depends more on the data model than the model itself.</p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="this-weeks-security-news">📰 <b>THIS WEEK&#39;S TOP 5 SECURITY HEADLINES</b></h2><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-oracle-people-soft-zeroday-cve-20"><b> </b><b>1. Oracle PeopleSoft zero-day (CVE-2026-35273) exploited by ShinyHunters before disclosure</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">CISA KEV Catalog</a> <br>Reporting: <a class="link" href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Oracle Security Alert</a> · <a class="link" href="https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer</a> · <a class="link" href="https://www.helpnetsecurity.com/2026/06/11/oracle-peoplesoft-under-attack-cve-2026-35273/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Help Net Security</a> <br>Analysis: <a class="link" href="https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Rapid7</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">Oracle issued an out-of-band alert for CVE-2026-35273 (CVSS 9.8), a server-side request forgery flaw in PeopleSoft PeopleTools 8.61 and 8.62 that is remotely exploitable without authentication and can lead to remote code execution. Mandiant and the Google Threat Intelligence Group attributed pre-disclosure exploitation to ShinyHunters (UNC6240), with activity running roughly May 27 to June 9 — before any patch existed. CISA added it to KEV on June 12 with a federal deadline of June 15. Stolen data was published on the ShinyHunters leak site. </p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">PeopleSoft is the system of record for HR and financial data at large institutions, so an unauthenticated SSRF-to-RCE converts directly into bulk exfiltration of the most regulated data an enterprise holds, plus a credential-harvesting foothold into federated identity systems. Exploitation predated the advisory by about two weeks, so log review back to late May matters more than racing the June 15 clock.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders: </b>Confirm PeopleTools is patched per Oracle&#39;s alert; pull web-tier and Integration Broker logs for SSRF patterns and anomalous outbound requests from late May onward, and treat any PeopleSoft-adjacent service-account credentials touched in that window as exposed.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-splunk-enterprise-preauth-rce-cha">🚨<b> 2. </b><b>Splunk Enterprise pre-auth RCE chain (CVE-2026-20253) is exposed by default on AWS</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://orca.security/resources/blog/cve-2026-20253-splunk-enterprise-rce-unauthenticated-file-operations/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Orca Security</a> <br>Reporting: <a class="link" href="https://cybersecuritynews.com/splunk-enterprise-pre-auth-rce-chain-exposes/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">CyberSecurityNews</a> · <a class="link" href="https://thecyberexpress.com/cve-2026-20253-critical-splunk-enterprise/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">The Cyber Express</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">Researchers disclosed CVE-2026-20253 (CVSS 9.8), an unauthenticated RCE chain in Splunk Enterprise 10 and later that abuses a misconfigured PostgreSQL sidecar. The sidecar isn&#39;t always enabled on-prem but runs by default in Splunk Enterprise on AWS, so cloud deployments are exposed out of the box. Exploitation allows file creation/destruction on the host, code execution inside the Splunk environment, and SSRF pivoting to internal resources. Splunk has released a fix. </p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">The SIEM holds credentials and network reach into nearly every system it monitors, so pre-auth RCE on Splunk is a detection-and-response decapitation — the attacker lands inside the tool your IR team would use to spot them. The default-on AWS exposure is the operative detail: &quot;we didn&#39;t enable that service&quot; is right on-prem and wrong in cloud, making deployment topology the thing to check first.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders</b><b>:</b> Identify Splunk Enterprise 10+ instances on AWS, apply the fix, and until patched, restrict network reach to the PostgreSQL sidecar and keep the management interface on a hardened admin path</p><hr class="content_break"><p class="paragraph" style="text-align:left;">🛠 <b>If you only do one thing this week:</b> Take 30 minutes to map which of your security and detection tooling — SIEM, sandbox, log pipeline, AI gateway — is reachable from anything other than a hardened admin path, and on which platform. This week&#39;s Splunk and FortiSandbox flaws both turn on deployment topology, and the episode&#39;s core point is the same: the tool you&#39;d use to catch the intruder is exactly what&#39;s being targeted.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-fortinet-forti-sandbox-flaws-unde"><b>☁️ 3. </b><b>Fortinet FortiSandbox flaws under active exploitation</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://cyberscoop.com/fortinet-fortisandbox-vulnerabilities-exploits/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">CyberScoop</a> <br>Reporting: <a class="link" href="https://www.securityweek.com/fortinet-ivanti-patch-critical-vulnerabilities/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek</a> · <a class="link" href="https://thehackernews.com/2026/06/ivanti-fortinet-and-sap-release-patches.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a> <br>Analysis: <a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">CISA KEV</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b><br>Threat-intel firm Defused reported active exploitation of a pair of FortiSandbox flaws Fortinet disclosed earlier this year — 49 exploitation events from 11 IPs over six days, traced to nine countries. Reporting ties the activity to an OS-command-injection flaw (CVE-2026-39808) and a path-traversal flaw (CVE-2026-39813), the latter confirmed exploited June 15. Fortinet separately patched a WEB UI command-injection flaw, CVE-2026-25089 (CVSS 9.1); SOCRadar reported ~30,000 exposed Fortinet firewalls. </p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b><br>FortiSandbox detonates files an organization doesn&#39;t trust, so code execution on the sandbox hands the attacker a privileged position inside the pipeline meant to contain malicious code — the containment tool becomes the execution environment. For hybrid estates feeding cloud-bound mail and file flows through FortiSandbox, a compromised appliance can poison verdicts and pass malware as clean into cloud workloads downstream.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders</b><br>Inventory FortiSandbox appliances and confirm a fixed build, restrict WEB UI and management access to an admin segment, and hunt for the vendor/Defused indicators across the June window.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-cis-as-june-15-kev-additions-lite">🏥<b> 4. </b><b>CISA&#39;s June 15 KEV additions: LiteSpeed cPanel root escalation and a second Cisco SD-WAN flaw</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://www.cisa.gov/news-events/alerts/2026/06/15/cisa-adds-two-known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">CISA Alert (June 15)</a> <br>Reporting: <a class="link" href="https://thehackernews.com/2026/06/cisa-flags-litespeed-cpanel-plugin-flaw.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a> · <a class="link" href="https://www.bleepingcomputer.com/news/security/cisa-warns-of-another-actively-exploited-cpanel-plugin-flaw/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer</a> · <a class="link" href="https://securityaffairs.com/193684/security/u-s-cisa-adds-cisco-catalyst-and-litespeed-cpanel-plugin-flaws-to-its-known-exploited-vulnerabilities-catalog.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">SecurityAffairs</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">CISA added two actively exploited flaws to KEV on June 15. CVE-2026-54420 (CVSS 8.5) is a symlink-handling flaw in the LiteSpeed cPanel plugin (before v2.4.8; LiteSpeed WHM Plugin before 5.3.2.0) that lets a user with FTP or web-shell access escalate to root on shared-hosting servers running CloudLinux or CageFS; the federal deadline was June 18. The second add, CVE-2026-20262 in Cisco Catalyst SD-WAN Manager, is an arbitrary-file-write / path-traversal flaw distinct from the command-injection flaw (CVE-2026-20245) covered in the June 10 brief.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">A symlink-to-root flaw on CloudLinux/CageFS breaks the per-tenant isolation shared hosting sells as its core control, so one tenant with a web shell reaches every other tenant on the box — a multi-tenant blast radius on the hosting tier many SaaS and agency workloads still run on. A second Cisco SD-WAN Manager flaw in two weeks means the controller is under sustained probing; reopen that item if you closed it after June 10.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders</b><br>Upgrade the LiteSpeed WHM/cPanel plugin and review hosting-server logs for symlink-abuse indicators; for Cisco SD-WAN Manager, confirm both CVE-2026-20245 and CVE-2026-20262 remediations and restrict management-plane access to a hardened jump path.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-supplychain-attacks-shift-to-ai-d"><b>🛡️ 5. </b><b>Supply-chain attacks shift to AI developer tooling: Mastra npm namespace and fake JetBrains plugins</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://thehackernews.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a> <br>Reporting: <a class="link" href="https://www.helpnetsecurity.com/2026/06/11/owasp-prompt-injection-ai-security-failures/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Help Net Security</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">Two near-simultaneous supply-chain compromises aimed at AI development tooling. Roughly 144 npm packages under the Mastra namespace were compromised after a single account mass-published 140-plus malicious packages within a short window on June 17. Separately, a coordinated JetBrains Marketplace campaign published at least 15 malicious plugins posing as AI coding assistants that exfiltrate AI-provider API keys to attacker-controlled servers.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">The credential these campaigns steal is the AI-provider API key, now a billing-and-data primitive — a leaked key buys model access on the victim&#39;s account and the data flowing through it. Targeting the AI-coding-assistant supply chain means the malicious code lands inside the developer&#39;s agentic toolchain, which already has filesystem, repo, and often cloud-credential reach. It&#39;s the news-side mirror of what Aqsa Taylor describes below: attacks that ride GitHub and package registries and look like normal developer activity until you have repo-layer context.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders:</b><a class="link" href="https://workspaceupdates.googleblog.com/2026/03/ransomware-detection-and-file-restoration-for-Google-Drive-now-generally-available.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow"> </a><br>Inventory Mastra packages and AI-coding-assistant IDE plugins across engineering, rotate any AI-provider API keys reachable from dev machines or CI in the June 17 window, and add AI-provider keys to the secret-scanning and short-TTL policies you apply to cloud credentials.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-supplychain-attacks-shift-to-ai-d"><b>🛡️ 6. </b><b>Databricks acquires Panther Labs, consolidating the security-data layer for AI-era detection</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://techstartups.com/2026/06/16/databricks-acquires-panther-labs-in-cybersecurity-push-to-take-on-crowdstrike-and-splunk/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Tech Startups</a> <br>Reporting: <a class="link" href="https://www.infosecurity-magazine.com/news-features/cybersecurity-ma-roundup-june-2026/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Infosecurity Magazine</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> Databricks agreed to acquire Panther Labs, a cloud-native security-data and detection platform whose customers include Anthropic. Reporting frames it as Databricks&#39; third cybersecurity acquisition and a move to compete with CrowdStrike and Cisco-owned Splunk as enterprises rebuild detection for AI-driven threats. Financial terms were not disclosed.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> A data-platform vendor buying a SIEM-class detection layer points at where security operations is consolidating — onto the same lakehouse that already holds the enterprise&#39;s analytics data. For architects it reframes a procurement question (which SIEM) into a data-gravity question: if detection moves to where the data already lives, tool-selection independence narrows toward whoever owns the lakehouse. It rhymes with the episode&#39;s argument that the AI SOC is defined by its data model, not its label.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders:</b> If Panther or Databricks is in your stack, map current detection-content and data-residency dependencies now, so a post-acquisition consolidation doesn&#39;t quietly relocate where your security telemetry lives or who governs access to it.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="the-ai-soc-is-only-as-good-as-the-d"><b>The AI SOC is only as good as the data it reasons over.</b></h3><p class="paragraph" style="text-align:left;">This week&#39;s news kept hitting the tools security teams rely on — the SIEM, the sandbox, the package registry developers trust — and that is exactly the surface Aqsa Taylor&#39;s argument is about. The pitch for &quot;AI SOC&quot; is everywhere; by her count there are more than 54 startups in the category, plus every legacy SIEM and SOAR rebadging into it. Her test for separating signal from marketing isn&#39;t the model but the data: what config, identity, code, and posture context does the platform fold in before it tells you what&#39;s a false positive? As she put it, &quot;AI can help, but it can also hurt without the right context.&quot; The same week attackers compromised npm and JetBrains plugins that look like ordinary developer activity, that&#39;s not abstract — it&#39;s the difference between a tool that catches the anomaly and one that waves it through. [<a class="link" href="https://www.cloudsecuritypodcast.tv/videos/the-4-pillars-of-ai-soc-from-threat-hunting-to-vibe-hunting?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Listen to the full episode →</a>] </p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="featured-experts-this-week"><b>Featured Experts This Week </b>🎤</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/aqsa-taylor/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow"><b>Aqsa Taylor</b></a> — Chief Security Evangelist, Exaforce</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Vibe hunting</b> — &quot;If you&#39;re using AI for code development, it&#39;s vibe coding. If you&#39;re using AI for threat hunting in SOC, vibe hunting.&quot; The analyst&#39;s skill stays; AI makes the hunt faster and higher-confidence.</p></li><li><p class="paragraph" style="text-align:left;"><b>AI SOC</b> — A contested umbrella label. SIEM and SOAR vendors now market themselves as AI SOC too, so the category name tells you little; the data the AI reasons over tells you everything.</p></li><li><p class="paragraph" style="text-align:left;"><b>The four pillars</b> — Detection, investigation, triage, response. Triage is the commoditized layer; the differentiated value is level-two investigation and, carefully, response.</p></li><li><p class="paragraph" style="text-align:left;"><b>Semantic / real-time knowledge graph</b> — A &quot;living graph&quot; fusing events with configuration, identity, code, and posture context, retaining business-context exceptions over time.</p></li><li><p class="paragraph" style="text-align:left;"><b>Peer-group baselining</b> — Judging a user&#39;s behavior against their team&#39;s baseline, not only their own.</p></li><li><p class="paragraph" style="text-align:left;"><b>MFA fatigue / &quot;spray and pray&quot;</b> — Flooding a user with auth attempts so they approve one MFA prompt; response is session/token revocation and blast-radius containment.</p></li><li><p class="paragraph" style="text-align:left;"><b>ITDR / ISPM</b> — Identity threat detection and response / identity security posture management.</p></li><li><p class="paragraph" style="text-align:left;"><b>CNAPP</b> — Cloud-native application protection platform, where code-repo and posture context typically live before it reaches the SOC.</p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <b><a class="link" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Varonis</a></b></p><p class="paragraph" style="text-align:center;"><i>AI Security Requires More Than Visibility. It Requires Control. </i></p><p class="paragraph" style="text-align:left;"><i>Security leaders are under pressure to enable AI innovation while managing a rapidly expanding attack surface across cloud, identity, and data layers. AI agents and copilots can introduce new access paths, automated high-impact actions, and accelerate threat timelines. </i></p><p class="paragraph" style="text-align:left;"><i><a class="link" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Varonis Atlas</a></i><i> helps organizations secure AI end-to-end - from understanding usage and enforcing guardrails to detecting suspicious activity and reducing risk dynamically. watch the recording </i><i><a class="link" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(17, 85, 204)">to learn how Varonis Atlas</a></i><i> can help security teams operationalize AI security at scale. </i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-vibe-hunting-came-from-the-soc-fl"><b>1. &quot;Vibe hunting&quot; came from the SOC floor, not the marketing team</b></h3><p class="paragraph" style="text-align:left;">Aqsa is explicit that the term originated with her company&#39;s own MDR team during a live hunt, then stuck because it mirrored vibe coding. The substance underneath is automation agents that update detection logic continuously as indicators publish, instead of an analyst manually chasing blogs and Substacks.</p><p class="paragraph" style="text-align:left;">&quot;If you&#39;re using AI for code development, it&#39;s vibe coding. If you&#39;re using AI for threat hunting in SOC, vibe hunting.&quot; — Aqsa Taylor</p><p class="paragraph" style="text-align:left;">Point agents at trusted IOC sources so detection logic updates as indicators land, while checking the environment&#39;s exposure window from configuration and posture data — not only from inbound events.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-ai-without-context-can-hurt-not-j"><b>2. AI without context can hurt, not just help</b></h3><p class="paragraph" style="text-align:left;">The sharpest take is a warning, not a pitch. An AI layer that just wraps event severity can bury a real alert among false positives, because it lacks the context to judge what matters.</p><p class="paragraph" style="text-align:left;">&quot;AI can help, but it can also hurt without the right context.&quot; — Aqsa Taylor</p><p class="paragraph" style="text-align:left;">Her example is the HackerBot Claw campaign: not a code vulnerability but malicious pull requests, where a payload manipulated Claude&#39;s auto-merge instructions and altered a README. PR-change requests aren&#39;t something traditional scanners alert on — the same repo-layer blind spot this week&#39;s Mastra and JetBrains compromises exploited.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-fix-the-data-model-before-you-tru"><b>3. Fix the data model before you trust the agents</b></h3><p class="paragraph" style="text-align:left;">Trust in AI agents depends on the underlying data model, not the model&#39;s raw intelligence. A more powerful frontier model doesn&#39;t remove the need for context.</p><p class="paragraph" style="text-align:left;">&quot;even before we move into AI, I think the data model on which the AI runs is so important to be able to then trust the AI agents&quot; — Aqsa Taylor</p><p class="paragraph" style="text-align:left;">She contrasts a static prompt-with-Claude approach — which works only on the data you feed it — against a &quot;proactive model&quot; where the data is a living graph that surfaces exposure on its own.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-the-hardest-detections-look-exact"><b>4. The hardest detections look exactly like normal activity</b></h3><p class="paragraph" style="text-align:left;">The detection problem worth solving is the legitimate-looking behavior. Aqsa&#39;s example is a North Korean &quot;fake employee&quot; with valid access who exfiltrates by copying a sensitive file and sharing the copy.</p><p class="paragraph" style="text-align:left;">&quot;They could copy the contents and then share the copied file with external, and you would not see that as a shared event because you&#39;re seeing the main file.&quot; — Aqsa Taylor</p><p class="paragraph" style="text-align:left;">Catching that requires SaaS-layer visibility across Google Workspace, GitHub, Okta, and Slack, plus peer-group baselining: comparing a new hire&#39;s behavior to their team&#39;s, not just their own short history.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-ai-soc-is-a-crowded-label-interro"><b>5. &quot;AI SOC&quot; is a crowded label — interrogate the data, not the badge</b></h3><p class="paragraph" style="text-align:left;">When Ashish notes buyers face 50-plus vendors, Aqsa&#39;s answer is to stop selecting on the label.</p><p class="paragraph" style="text-align:left;">&quot;there&#39;s over 54 in the startup world ... in AI SOC. And then I&#39;m not even counting all the traditional platforms who have pivoted to AI SOC messaging more recently.&quot; — Aqsa Taylor</p><p class="paragraph" style="text-align:left;">The buying question to ask instead: what factors — config, identity, code, location — does the platform weigh when it reduces false positives, and is it proactive enough to run its own detections rather than waiting on upstream providers?</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="6-ai-doesnt-change-the-threats-it-c"><b>6. AI doesn&#39;t change the threats; it changes the volume and the timeline</b></h3><p class="paragraph" style="text-align:left;">Across the four pillars, most platforms only do triage — enriching upstream events. The real value is reaching the judgment of an experienced level-two analyst.</p><p class="paragraph" style="text-align:left;">&quot;where defenders really need help with AI and where AI can give a lot more is level two threat investigation.&quot; — Aqsa Taylor</p><p class="paragraph" style="text-align:left;">She expects 2026 to be when teams move past level-one and level-two triage into investigation and, carefully, response — but only after the first three pillars build trust. Response agents are real (she cites customer testimonials recorded during an RSA panel), but they earn autonomy.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="7-response-works-when-one-platform-"><b>7. Response works when one platform owns the whole kill chain</b></h3><p class="paragraph" style="text-align:left;">The response pillar becomes viable when the foundation pillars feed it — so the platform runs detection, identity mapping, blast-radius, and containment without hopping between ITDR, threat-hunting, and SOAR tools.</p><p class="paragraph" style="text-align:left;">&quot;we saw a credential stuffing attempt where there were like 390 authentication attempts across 14 accounts.&quot; — Aqsa Taylor</p><p class="paragraph" style="text-align:left;">In that MFA-fatigue case, tying the detection to identity risk (who clicked phishing before), impact radius (which sensitive files the account can reach), and recent sharing activity — then revoking sessions — collapses a multi-tool workflow into one chain.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="7-response-works-when-one-platform-"><b>8. </b>Don&#39;t build it yourself — equip your defenders instead</h3><p class="paragraph" style="text-align:left;">Both host and guest land on the same build-versus-buy conclusion. Ashish frames the trap from a CISO&#39;s chair:</p><p class="paragraph" style="text-align:left;">&quot;I am actually employing people to build a product in my own company. Is that what I&#39;m going towards?&quot; — Ashish Rajan</p><p class="paragraph" style="text-align:left;">Aqsa agrees: DIY with Claude can help with smaller scripts, but it doesn&#39;t remove the context, accuracy, and confidence-scoring burden — &quot;it&#39;s almost like you&#39;re changing the effort, but you&#39;re still putting effort.&quot; Her recommended starting point: begin with level-one triage on top of your existing SIEM using a dedicated platform, and &quot;start from data&quot; by asking what the platform weighs before you trust its verdicts.</p><p class="paragraph" style="text-align:left;">&quot;You need to make sure that you&#39;re equipping your defenders, your team, with the same advantage that the attackers have.&quot; — Aqsa Taylor</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="practical-takeaways-for-cloud-secur"><b>Practical Takeaways for Cloud Security Leaders</b></h3><ul><li><p class="paragraph" style="text-align:left;">Map which security tooling (SIEM, sandbox, AI gateway) is reachable outside a hardened admin path, and on which platform — this week&#39;s flaws turn on topology.</p></li><li><p class="paragraph" style="text-align:left;">Rotate AI-provider API keys reachable from dev machines and CI, and scan for them like cloud credentials.</p></li><li><p class="paragraph" style="text-align:left;">When evaluating an AI SOC, ask what data (config, identity, code, location) it weighs — not whether it says &quot;AI.&quot;</p></li><li><p class="paragraph" style="text-align:left;">Start with level-one triage on your existing SIEM; treat the full four-pillar model as the destination, not the first project.</p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>📚 RELATED RESOURCES 🎧</b></h2><p class="paragraph" style="text-align:left;"><b>AppSec & DevSecOps Guidance</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">CISA Known Exploited Vulnerabilities Catalog</a> — authoritative exploitation status for this week&#39;s CVEs</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Oracle Security Alert — PeopleSoft CVE-2026-35273</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Rapid7 — Active exploitation of the PeopleSoft zero-day</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://orca.security/resources/blog/cve-2026-20253-splunk-enterprise-rce-unauthenticated-file-operations/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Orca Security — Splunk Enterprise RCE (CVE-2026-20253)</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cisa.gov/news-events/alerts/2026/06/15/cisa-adds-two-known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">CISA Alert — June 15 KEV additions</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cyberscoop.com/fortinet-fortisandbox-vulnerabilities-exploits/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">CyberScoop — FortiSandbox exploitation</a></p></li></ul><h3 class="heading" style="text-align:left;" id="podcast-episode"><b>Podcast Episode</b></h3><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a><b>  : </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/the-4-pillars-of-ai-soc-from-threat-hunting-to-vibe-hunting?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow"><b>Episode with Aqsa</b></a></p></li></ul><hr class="content_break"><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔<b> </b><span style="color:rgb(20, 19, 34);"> </span>When did a &quot;normal-looking&quot; action — a copied file, a pull request — turn out to be the incident? What gave it away?<br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-control-plane-was-the-target-this-week-your-ai-soc-might-miss-why" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=28af2ea9-444a-4393-adfc-e4317bcc155a&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🚨 Three Exploited Flaws, No Patch Coming - Murali Rathinasamy on Why Micro-Segmentation Is the Destination, Not the Project </title>
  <description>This week four actively exploited flaws hit the gear that brokers access — CheckPoint VPN, Cisco SD-WAN Manager, Arista EOS, and the LiteLLM AI gateway — and forthree of them the vendor answer is a mitigation, not a patch. We feature insightsfrom Murali Rathinasamy, Senior Director of Product at Cisco, on hybrid meshfirewall, micro-segmentation, and why compensating controls at the network layerare becoming the primary fix, not the fallback.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/53bd17b3-093e-4876-bcd5-68354c974bcc/Screenshot_2026-06-11_at_12.26.37_AM.png" length="844870" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/three-exploited-flaws-no-patch-coming-micro-segmentation-compensating-controls</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/three-exploited-flaws-no-patch-coming-micro-segmentation-compensating-controls</guid>
  <pubDate>Wed, 10 Jun 2026 23:30:32 +0000</pubDate>
  <atom:published>2026-06-10T23:30:32Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><h2 class="heading" style="text-align:left;" id="hello-from-the-cloudverse"><span style="background-color:#28EEDA;"><b>Hello from the Cloud-verse!</b></span></h2><p class="paragraph" style="text-align:left;">This week’s Cloud Security Newsletter topic<b>: Segmentation for the week the patches didn&#39;t come — hybrid mesh firewall and staged micro-segmentation </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" rel="noopener noreferrer nofollow">(continue reading)</a> </p><hr class="content_break"><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project"><span class="button__text" style=""> This issue is sponsored by Varonis </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/53bd17b3-093e-4876-bcd5-68354c974bcc/Screenshot_2026-06-11_at_12.26.37_AM.png?t=1781134138"/></a><div class="image__source"><span class="image__source_text"><p><i>This image was generated by AI. It&#39;s still experimental, so it might not be a perfect match!</i></p></span></div></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;">This week&#39;s Cloud Security Newsletter topic: Segmentation for the week the patches didn&#39;t come — hybrid mesh firewall and staged micro-segmentation. </p><p class="paragraph" style="text-align:left;">No single breach carried this week. The pattern did: a cluster of actively exploited vulnerabilities in control-plane infrastructure, several added to CISA&#39;s KEV catalog within 48 hours, and vendors increasingly responding with ACLs and config changes instead of code. If your triage starts with &quot;is there a patch,&quot; this was the week that question stopped working. </p><p class="paragraph" style="text-align:left;">That makes the timing of this week&#39;s episode useful. Ashish Rajan sat down with Murali Rathinasamy, Senior Director of Product at Cisco, for a conversation about hybrid mesh firewall: what the category actually is, where it differs from CNAPP, and a staged approach to micro-segmentation that starts with blocking ports your own traffic data says you never use. (Disclosure: Cisco sponsored this episode. This week&#39;s news also includes an actively exploited Cisco SD-WAN flaw, covered on its merits below.)<i>[</i><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/native-cloud-firewalls-falling-short-in-a-multicloud-world?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">⚡ TL;DR for Busy Readers</h2><ul><li><p class="paragraph" style="text-align:left;"><b>Check Point VPN auth bypass (CVE-2026-50751, CVSS 9.3)</b> ran exploited for about a month before the June 8 hotfix, with a Qilin ransomware affiliate among the users. Apply the hotfix and retire IKEv1 now. </p></li><li><p class="paragraph" style="text-align:left;"><b>Cisco SD-WAN Manager zero-day (CVE-2026-20245)</b> is exploited with no patch or mitigation available. Restrict management-plane access to a hardened jump path and rotate netadmin credentials today. </p></li><li><p class="paragraph" style="text-align:left;"><b>LiteLLM RCE (CVE-2026-42271)</b> is the first KEV-listed AI-gateway flaw. Patch to ≥1.83.7, block the <code>/mcp-rest/test/*</code> endpoints, and rotate every model-provider key the proxy held. </p></li><li><p class="paragraph" style="text-align:left;"><b>Arista EOS tunnel flaw (CVE-2026-7473)</b>: exploited, no patch planned, and it bypasses the VXLAN/GRE segmentation your fabric design assumes. ACLs are the permanent fix. </p></li><li><p class="paragraph" style="text-align:left;"><b>From the episode</b>: treat full micro-segmentation as the destination, not the project. Start agentless, block what observed traffic shows is unused (SMB 445 first), and save agents for crown jewels.</p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="this-weeks-security-news">📰 <b>THIS WEEK&#39;S TOP 5 SECURITY HEADLINES</b></h2><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-lite-llm-rce-chain-exploited-in-t"><b> </b><b>1. LiteLLM RCE chain exploited in the wild; CISA adds first AI-gateway flaw to KEV</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">CISA KEV Catalog</a> <br>Reporting: <a class="link" href="https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a> · <a class="link" href="https://www.helpnetsecurity.com/2026/06/09/litellm-vulnerability-under-active-attack-cisa-warns-cve-2026-42271/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Help Net Security</a> <br>Analysis: <a class="link" href="https://Horizon3.ai?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Horizon3.ai</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">CISA added CVE-2026-42271, a command-injection flaw in BerriAI&#39;s LiteLLM proxy (CVSS 8.7), to the KEV catalog on June 8, citing active exploitation. Two MCP-server preview endpoints accepted a full server config in the request body and spawned the supplied command as a subprocess on the proxy host. <a class="link" href="https://Horizon3.ai?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Horizon3.ai</a> chained it with CVE-2026-48710, a Starlette host-header validation bypass, to reach unauthenticated RCE. Fixed in LiteLLM 1.83.7 and Starlette 1.0.1.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">The LLM proxy is where enterprises now concentrate model-provider API keys, internal endpoint credentials, and the routing config for every AI app behind it. A shell on that host means the blast radius is every model credential the gateway holds, not one application. This is the first KEV-listed AI-gateway RCE, and it reframes the LLM proxy as a tier-0 identity asset that belongs in the same patch SLA as a domain controller.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders:</b> Inventory LiteLLM deployments, confirm version ≥1.83.7, block the two /mcp-rest/test/* endpoints at the reverse proxy if you cannot patch immediately, then rotate any model-provider keys the proxy stored.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-check-point-vpn-auth-bypass-explo">🚨<b> 2. </b><b>Check Point VPN auth bypass exploited for a month; Qilin affiliate among the users</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Check Point advisory</a> <br>Reporting: <a class="link" href="https://www.bleepingcomputer.com/news/security/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer</a> · <a class="link" href="https://www.securityweek.com/check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek</a> <br>Analysis: <a class="link" href="https://www.rapid7.com/blog/post/etr-critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Rapid7</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">Check Point disclosed CVE-2026-50751 on June 8, a CVSS 9.3 logic flaw in certificate validation that lets a remote, unauthenticated attacker establish a Remote Access or Mobile Access VPN session without a valid password. It affects deployments using the deprecated IKEv1 protocol and Spark firewalls. Check Point traces exploitation to May 7 (vendor&#39;s own assessment) and ties it to at least one Qilin ransomware intrusion that used Rclone for exfiltration. CISA set a June 11 federal KEV deadline. A related flaw, CVE-2026-50752, affects IKEv1 site-to-site certificate validation.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">Roughly a month of in-the-wild use before a fix existed, and the entry point is the appliance fronting the corporate network. A ransomware affiliate gets the same network position as an authenticated remote employee, minus the credential. The IKEv1 dependency makes this a configuration-debt story: the exposed set is everyone who never migrated to IKEv2, so remediation is an architecture audit, not just a hotfix.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders</b><b>:</b> Apply the hotfix. If you cannot, switch Remote Access VPN to IKEv2-only, make machine-certificate authentication mandatory, enable IPS, and hunt logs for the published VPS-hosted source IPs.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-cisco-catalyst-sdwan-manager-zero"><b>☁️ 3. </b><b>Cisco Catalyst SD-WAN Manager zero-day exploited; no patch available</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Cisco Security Advisory</a> <br>Reporting: <a class="link" href="https://www.helpnetsecurity.com/2026/06/05/cisco-sd-wan-cve-2026-20245-0-day-exploited/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Help Net Security</a> · <a class="link" href="https://www.bleepingcomputer.com/news/security/new-cisco-sd-wan-flaw-exploited-in-zero-day-attacks-to-gain-root/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer</a> · <a class="link" href="https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b><br>Cisco confirmed active exploitation of CVE-2026-20245 (CVSS 7.8) in Catalyst SD-WAN Manager, a command-injection flaw that lets an authenticated attacker with netadmin privileges execute commands as root by uploading a crafted file. Google Mandiant reported it, and Cisco observed attackers pushing configuration changes down to edge devices. No patch or mitigation is available. The netadmin role can be obtained via stolen credentials or by chaining earlier SD-WAN flaws (CVE-2026-20182, CVE-2026-20127).</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b><br>SD-WAN Manager is the control plane for branch and cloud-edge connectivity. Root on the manager is not one box; it is the ability to rewrite routing and policy on every managed edge device, which is pre-positioning capability rather than a single-host compromise. With no patch on offer, the defensive question shifts from &quot;when do we deploy the fix&quot; to &quot;who can reach the manager&#39;s CLI at all.&quot;</p><p class="paragraph" style="text-align:left;"><b>Action for defenders</b><br>Restrict management-plane access to a hardened jump path, audit netadmin accounts and rotate their credentials, and review edge-device config history for unexpected pushes.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">🛠 <b>If you only do one thing this week:</b> List which of the four exploited access-broker products you run — Check Point IKEv1 VPN, Catalyst SD-WAN Manager, Arista tunnel-decap endpoints, LiteLLM — and for each one write down either the patch version deployed or the named compensating control and its owner. Thirty minutes, and it converts this week&#39;s thesis (the patch isn&#39;t coming; compensate at the network layer) into a checklist your team can act on.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-service-now-discloses-unauthentic">🏥<b> 4. </b><b>ServiceNow discloses unauthenticated API flaw used to query customer instance data</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://www.bleepingcomputer.com/news/security/servicenow-discloses-security-incident-exposing-customer-data/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer</a> <br>Reporting: <a class="link" href="https://hackread.com/servicenow-security-incident-exposing-customer-data/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Hackread</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">ServiceNow disclosed on June 9 that attackers exploited an unauthenticated-access flaw in one of its API endpoints to run queries against customer instances. Observed activity traces to June 2–3; ServiceNow remediated hosted instances on June 5 with no customer action required. Community reporting points to a Scripted REST Resource deployed with requires_authentication=false. The bulletin centers impact on the Australia platform release and older releases with certain config changes.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">This is a multi-tenant SaaS auth bypass in the provider&#39;s own platform code, not a customer misconfiguration, so &quot;harden your instance&quot; would not have prevented it. Because the vendor fixed it server-side, most affected customers will see no signal unless they go looking. &quot;The provider patched it for you&quot; and &quot;you have no exposure&quot; are different claims; log review is the only way to know which one applies to you.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders</b><br>Pull instance logs for requests to the affected endpoint and the published indicator IP (51.159.98.241) across the June 2–5 window, and confirm with your account team whether your release was in the impacted set.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-google-patches-fifth-actively-exp"><b>🛡️ 5. </b><b>Google patches fifth actively exploited Chrome zero-day of the year</b></h3><p class="paragraph" style="text-align:left;">Primary source: <a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">CISA KEV</a> <br>Reporting: <a class="link" href="https://www.helpnetsecurity.com/2026/06/09/google-chrome-zero-day-cve-2026-11645/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Help Net Security</a> · <a class="link" href="https://www.bleepingcomputer.com/news/security/google-patches-fifth-chrome-zero-day-bug-exploited-in-attacks-this-year/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer</a> · <a class="link" href="https://thehackernews.com/2026/06/chrome-v8-zero-day-cve-2026-11645.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a></p><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">Google patched CVE-2026-11645, an out-of-bounds read/write in the V8 JavaScript engine allowing arbitrary code execution in the browser sandbox via a crafted HTML page. An exploit exists in the wild; CISA added it to KEV on June 9. It is the fifth actively exploited Chrome zero-day of 2026 and, because the bug is in Chromium, it also affects Edge, Opera, and other Chromium-based applications. Fixed in Chrome 149.0.7827.102/.103.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">The exposure is not just user browsers. Chromium is embedded across cloud workloads, headless automation, and CI rendering, so &quot;patch the browser&quot; understates where the engine runs. The instances that stay exploitable after every desktop updates are the build pipelines and serverless functions shipping a bundled Chromium nobody patches on Google&#39;s cadence.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders:</b><a class="link" href="https://workspaceupdates.googleblog.com/2026/03/ransomware-detection-and-file-restoration-for-Google-Drive-now-generally-available.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow"> </a><br>Force-update managed Chrome/Edge fleets, then inventory container images and Lambda/Cloud Run layers that bundle Chromium or Puppeteer and rebuild against the patched version.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="segmentation-for-the-week-the-patch"><b>Segmentation for the week the patches didn&#39;t come!</b></h3><p class="paragraph" style="text-align:left;">Three of this week&#39;s exploited flaws shipped with no patch, and the vendor guidance in each case was a network-layer control: ACLs on Arista fabric, access restriction on SD-WAN Manager, protocol migration on Check Point. That is compensating-control work, and it lands on whoever owns segmentation. Murali Rathinasamy&#39;s argument on the podcast is that this work stalls for a predictable reason. As he put it: &quot;Micro-segmentation always stalls in the phase of how do I know what I need to go protect, and what policy should I go use?&quot; His staged answer, starting from observed traffic and agentless enforcement rather than a multi-year agent rollout, is the practical core of this edition&#39;s insights section. [<a class="link" href="https://www.cloudsecuritypodcast.tv/videos/native-cloud-firewalls-falling-short-in-a-multicloud-world?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Listen to the full episode →</a>] </p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="featured-experts-this-week"><b>Featured Experts This Week </b>🎤</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/muralirs/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow"><b>Murali Rathinasamy</b></a><b> - </b>Senior Director of Product, Cisco </p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Hybrid mesh firewall</b> — As the guest describes it: the evolution after perimeter and next-gen firewalls, recognizing that enterprise networks now span data centers and clouds. A distributed set of enforcement points (physical, virtual, container, cloud-native; inline and out-of-band) managed uniformly: &quot;uniformly managing this entire distribution of inline and out-of-band detection and threat capabilities.&quot; A category, not a single product.</p></li><li><p class="paragraph" style="text-align:left;"><b>Micro-segmentation</b> — Locking down communication at the level of individual VMs, containers, and devices. The guest&#39;s framing: the end state where &quot;every individual VM, every individual container, every individual device is really locked down.&quot;</p></li><li><p class="paragraph" style="text-align:left;"><b>North-south vs east-west</b> — Perimeter traffic (inspection, decryption, DLP, WAF-style inbound protection) versus traffic between internal workloads (segmentation territory).</p></li><li><p class="paragraph" style="text-align:left;"><b>Compensating control</b> — A control that reduces exploitability when fixing the flaw itself isn&#39;t possible: a virtual-patch rule, step-up MFA in front of a vulnerable app, or an ACL where no patch is coming. The connective tissue between this week&#39;s news and the episode.</p></li><li><p class="paragraph" style="text-align:left;"><b>KEV (Known Exploited Vulnerabilities) catalog</b> — CISA&#39;s list of flaws with confirmed active exploitation, carrying federal remediation deadlines. Four of this week&#39;s stories involve KEV additions inside one 48-hour stretch.</p></li><li><p class="paragraph" style="text-align:left;"><b>Blue-green upgrade</b> — Standing up the new version alongside the old and cutting traffic over, eliminating upgrade downtime. The operational expectation cloud teams now hold firewalls to, per the RCSI example.</p></li><li><p class="paragraph" style="text-align:left;"><b>IKEv1</b> — The deprecated IPsec key-exchange protocol whose continued use defines the exposed population for CVE-2026-50751.</p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <b><a class="link" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Varonis</a></b></p><p class="paragraph" style="text-align:center;"><i>AI Security Requires More Than Visibility. It Requires Control. </i></p><p class="paragraph" style="text-align:left;"><i>Security leaders are under pressure to enable AI innovation while managing a rapidly expanding attack surface across cloud, identity, and data layers. AI agents and copilots can introduce new access paths, automated high-impact actions, and accelerate threat timelines. </i></p><p class="paragraph" style="text-align:left;"><i><a class="link" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Varonis Atlas</a></i><i> helps organizations secure AI end-to-end - from understanding usage and enforcing guardrails to detecting suspicious activity and reducing risk dynamically. watch the recording </i><a class="link" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(17, 85, 204)"><i>to learn how Varonis Atlas</i></a><i> can help security teams operationalize AI security at scale. </i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-cloud-and-onprem-are-one-network-"><b>1. Cloud and on-prem are one network; treating them as islands is the root failure</b></h3><p class="paragraph" style="text-align:left;">The tooling split, CNAPP and CSPM for cloud and appliance firewalls for on-prem, forces a divide that the org chart doesn&#39;t actually have. The same network security team usually owns both halves.</p><p class="paragraph" style="text-align:left;">&quot;What we&#39;ve seen in the industry is the challenge is that customers will often think about their cloud security as one island in one pocket of the world, but then their on-prem is a different pocket of the world. Really though no enterprise thinks about them separately. It&#39;s all one hybrid network, and wherever the application are and wherever the users are, they wanna pro- uh, protect that in totality.&quot; — Murali Rathinasamy</p><p class="paragraph" style="text-align:left;">The practical version of this insight: asking an on-prem firewall admin to also master CNAPP, CSPM, and per-cloud native tooling for only half their environment is a skills tax most teams can&#39;t pay. Royal College of Surgeons in Ireland (RCSI) is the worked example below.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-ai-agents-look-like-users-but-don"><b>2. AI agents look like users but don&#39;t behave like users</b></h3><p class="paragraph" style="text-align:left;">Murali&#39;s sharpest AI observation is about identity, not models. Agents inherit a user&#39;s identity and then access things in patterns no human baseline predicts.</p><p class="paragraph" style="text-align:left;">&quot;You now have new applications because at the end of the day, everyone is now an application developer because they can go and create their own applications. These agents now can sort of look like a user, but they&#39;re doing things in ways that users don&#39;t do. So even traditional behavioral analysis tools may not work because you&#39;ll see user Murali traditionally uses this application, and now his agents are going all over the place.&quot; — Murali Rathinasamy</p><p class="paragraph" style="text-align:left;">This pairs directly with the LiteLLM story above. If agents defeat behavioral baselines and the AI gateway concentrates credentials, the controls that still work are the structural ones: segmentation that limits what an agent can reach, and inspection at the choke point between workload and model.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-the-singlecloud-security-story-co"><b>3. The single-cloud security story collapses at enterprise reality</b></h3><p class="paragraph" style="text-align:left;">A former AWS product manager arguing against all-in on cloud-native firewalling carries some weight:</p><p class="paragraph" style="text-align:left;">&quot;As a former AWS product manager, I would tell you that I would&#39;ve said the exact same thing. &#39;Hey, you&#39;re in the AWS ecosystem. We have, we&#39;ve got the best in class services. Go and use ours entirely.&#39; However, the reality for all the enterprises I work with, literally all of the enterprises that I work with is none of them are one cloud provider. A, none of them are one cloud provider. All of them have at least two cloud providers, and then B, they all have on-prem deployments as well.&quot; — Murali Rathinasamy</p><p class="paragraph" style="text-align:left;">His decision lens is ownership: if a centralized security team is responsible for every workload everywhere, per-cloud native tooling means re-skilling that team on each platform and stitching policy visibility across VPCs, Azure, and GCP by hand. Where cloud providers win, he concedes, is scalability; where customers tell him they&#39;re not there yet is security feature depth.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-rcsi-virtual-firewalls-in-the-clo"><b>4. RCSI: virtual firewalls in the cloud fail on operations, not security</b></h3><p class="paragraph" style="text-align:left;">RCSI, a 200-year-old institution , ran Cisco FTD on-prem and lifted virtual firewalls into the cloud, then hit route-table plumbing, transit gateway config, self-managed scaling, and upgrade downtime.</p><p class="paragraph" style="text-align:left;">&quot;What RCSI realized was like, hey, this is just not a scalable model. Like, any time I need to do a software upgrade for the firewall, I have to go take downtime? My cloud application teams are like, &#39;That&#39;s crazy.&#39; Like, no cloud team really thinks about downtime to do an upgrade. It&#39;s always a blue-green upgrade.&quot; — Murali Rathinasamy</p><p class="paragraph" style="text-align:left;">The fix wasn&#39;t a different security product; it was operating the same firewall like a cloud service (orchestrated deployment, auto-scaling, blue-green upgrades via Multicloud Defense). The lesson generalizes beyond Cisco: when network security tooling can&#39;t match the operational bar cloud teams hold everything else to, the security tool loses the argument.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-microsegmentation-stalls-on-what-"><b>5. Micro-segmentation stalls on &quot;what do I protect?&quot; — make it the destination, not the project</b></h3><p class="paragraph" style="text-align:left;">Ashish&#39;s framing set up the episode&#39;s most useful exchange:</p><p class="paragraph" style="text-align:left;">&quot;Micro-segmentation. It&#39;s probably the most spoken, yet least implemented space of the industry.&quot; — Ashish Rajan</p><p class="paragraph" style="text-align:left;">Murali&#39;s response is the staged model. First, recognize you&#39;ve already started: a perimeter firewall is one segment, and most enterprises already firewall crown jewels or cloud boundaries. Second, use observed traffic to cut obvious attack surface agentlessly, without touching applications:</p><p class="paragraph" style="text-align:left;">&quot;While we, you know, uh, enterprises talk quite a bit about segmentation and micro-segmentation, at the end of the day, micro-segmentation always stalls in the phase of how do I know what I need to go protect, and what policy should I go use?&quot; — Murali Rathinasamy</p><p class="paragraph" style="text-align:left;">His concrete examples: Windows Server SMB (445) is among the most exploited ports in a data center and almost never legitimately used; block it. SSH should only originate from jump hosts; block 22 from everywhere else. A large healthcare provider in California (unnamed) deployed micro-segmentation agents only on its EMR, the crown jewels, and used existing Cisco firewalls agentlessly for everything else, cutting the lateral path from systems like payroll to the EMR.</p><p class="paragraph" style="text-align:left;">&quot;Worry about the north star of true micro-segmentation where every individual VM, every individual container, every individual device is really locked down. Think of that as the destination, don&#39;t think of that as the journey.&quot; — Murali Rathinasamy</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="6-ai-doesnt-change-the-threats-it-c"><b>6. AI doesn&#39;t change the threats; it changes the volume and the timeline</b></h3><p class="paragraph" style="text-align:left;">&quot;To me, like the AI world is really more about, it&#39;s not a different set of threats. It, it&#39;s the same sort of threats, it&#39;s just a much higher volume of those threats on a much shorter timeline, right?&quot; — Murali Rathinasamy</p><p class="paragraph" style="text-align:left;">That reframe has a budget implication: the answer to AI-era threats is mostly not new threat categories or new tools, it&#39;s shrinking time-to-control on the ones you have. On the prompt layer specifically, his point is architectural: there is already a firewall between your users or workloads and the LLM, so that&#39;s where inspection belongs, including prompt-injection detection and blocking responses that leak what they shouldn&#39;t.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="7-compensating-controls-are-the-ans"><b>7. Compensating controls are the answer to software you can&#39;t patch</b></h3><p class="paragraph" style="text-align:left;">The quote that could have been written about this week&#39;s news: &quot;<i>Cisco is, uh, working very closely with Mythos on being able to identify vulnerabilities in our own software to patch them very quickly, and we&#39;re realizing that Mythos is the new reality in the world of all CISOs and CIOs, CTOs have known that all software is gonna have vulnerabilities. It&#39;s really about how do you close those vu- vulnerabilities quickly and use compensating controls to make sure that they&#39;re not, uh, exploited w- before you can kind of fix it.</i>&quot; — Murali Rathinasamy</p><p class="paragraph" style="text-align:left;">For COTS applications and legacy systems (his example: MRI machines on Windows XP-era software), patching is not in your control. The realistic play is a virtual-patch rule for a Log4j-style flaw, or step-up MFA in front of an app you know is vulnerable, while the vendor or app team builds the fix. Set against Arista&#39;s &quot;no patch planned&quot; and Cisco SD-WAN&#39;s &quot;no patch available,&quot; this stopped being a vendor talking point and became the week&#39;s operating reality.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="practical-takeaways-for-cloud-secur"><b>Practical Takeaways for Cloud Security Leaders</b></h3><ul><li><p class="paragraph" style="text-align:left;"><b>Embed AppSec in the engineering loop not after it.</b> If your team is still receiving code and generating tickets, you are operating legacy AppSec. Start conversations with engineering about where security testing can run inside the CI/CD pipeline itself.</p></li><li><p class="paragraph" style="text-align:left;"><b>Shift from false positive tolerance to true positive precision.</b> A 90% false positive rate is a testing architecture problem, not a signal problem. Test inside the development environment to eliminate WAF and CDN interference.</p></li><li><p class="paragraph" style="text-align:left;"><b>Treat AI agents as service identities, not applications.</b> Apply your IAM governance framework to every agentic workload before production deployment. Default permissions are almost always too broad. BYOSA on Vertex AI; scoped service accounts everywhere else.</p></li><li><p class="paragraph" style="text-align:left;"><b>Audit your CI/CD supply chain assumptions today.</b> Pin GitHub Actions to full commit SHAs, not floating tags. Assume any runner that executed Trivy, LiteLLM, Telnyx, or Axios between March 19–31 is compromised until proven otherwise.</p></li></ul><p class="paragraph" style="text-align:left;"><b>Position security as a business enabler for AI transformation.</b> CISOs who approach AI as purely a risk management exercise will be sidelined. Those who help engineering teams ship AI features securely and at speed will own one of the most important mandates in their organization.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>📚 RELATED RESOURCES 🎧</b></h2><p class="paragraph" style="text-align:left;"><b>AppSec & DevSecOps Guidance</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">CISA Known Exploited Vulnerabilities Catalog</a> — authoritative exploitation status for this week&#39;s CVEs</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Cisco Security Advisory — SD-WAN Manager CVE-2026-20245</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Check Point hotfix advisory — IKEv1 VPN flaws</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Arista Security Advisory 0137 — EOS tunnel decapsulation</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://Horizon3.ai?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Horizon3.ai</a><a class="link" href="https://horizon3.ai/attack-research/vulnerabilities/cve-2026-42271-chained-with-cve-2026-48710/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow"> — LiteLLM RCE chain analysis</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.rapid7.com/blog/post/etr-critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Rapid7 — Check Point VPN zero-day analysis</a></p></li></ul><h3 class="heading" style="text-align:left;" id="podcast-episode"><b>Podcast Episode</b></h3><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a><b> </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/native-cloud-firewalls-falling-short-in-a-multicloud-world?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow"><b>Episode with Murali</b></a></p></li></ul><hr class="content_break"><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔<b> </b><span style="color:rgb(20, 19, 34);"> </span>Which of your controls exist because a patch never shipped — and would you know if one quietly stopped working?<br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=three-exploited-flaws-no-patch-coming-murali-rathinasamy-on-why-micro-segmentation-is-the-destination-not-the-project" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=e1637a27-4d1e-4e37-81e7-b3c5f7bae39b&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Cloud-Credential Worm Hit Red Hat &amp; DoorDash&#39;s approach to Security at the Speed of Engineering</title>
  <description>A supply-chain worm forked open-sourced attack code into Red Hat’s npm namespace and harvested AWS, Google Cloud, Azure, and Kubernetes credentials at install time — the same week a PAN-OS GlobalProtect bypass and a cgroups container-escape flaw both hit CISA’s KEV deadline list. From a live AI Security Podcast recording in San Francisco, DoorDash’s Nick Reva and GRC engineer Shivani Doke make the case that the only control that survives AI-accelerated offense is one that runs at the speed of engineering: guardrails embedded in the pipeline, not gates bolted on after.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/76857144-f7da-4956-8a03-172c11f653d7/Screenshot_2026-06-04_at_12.21.15_AM.png" length="1710327" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/security-at-engineering-speed</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/security-at-engineering-speed</guid>
  <pubDate>Wed, 03 Jun 2026 23:25:19 +0000</pubDate>
  <atom:published>2026-06-03T23:25:19Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">This week&#39;s Cloud Security Newsletter topic: <b>Security at the Speed of Engineering — Guardrails, Not Gates </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" rel="noopener noreferrer nofollow">(continue reading)</a> </p><hr class="content_break"><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://links.cloudsecuritypodcast.tv/checkpoint-report-june2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering"><span class="button__text" style=""> This issue is sponsored by CheckPoint </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.aisecuritypodcast.com/videos/securing-ai-at-the-speed-of-engineering?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/76857144-f7da-4956-8a03-172c11f653d7/Screenshot_2026-06-04_at_12.21.15_AM.png?t=1780528922"/></a><div class="image__source"><span class="image__source_text"><p><i>This image was generated by AI. It&#39;s still experimental, so it might not be a perfect match!</i></p></span></div></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;">No single breach defined the week. What defined it was reuse and speed: offensive tooling getting mass-produced and recycled faster than defenders — or governments — can measure it, landing squarely on the identity edge and the container boundary. A credential-stealing worm rode a maintainer’s GitHub account straight past code review into Red Hat’s npm namespace. A three-year-old container-escape bug earned a fresh KEV listing the day after in-the-wild exploitation was reported. And Sophos pulled apart a ransomware crew’s AI-coordinated lab built to test malware against three named commercial EDRs.</p><p class="paragraph" style="text-align:left;">This week’s conversation features <b>Nick Reva</b>, who runs global security engineering at <b>DoorDash</b>, and <b>Shivani Doke</b>, a GRC engineer, recorded live in front of a San Francisco audience and hosted by <b>Ashish Rajan</b>. The thread running through both the news and the episode: AI lowers the barrier on both sides of the fight, so the durable controls are the ones embedded in the development lifecycle and validated continuously, with humans in the loop only at the decisions that matter. <i>[</i><a class="link" href="https://www.aisecuritypodcast.com/videos/securing-ai-at-the-speed-of-engineering?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">⚡ TL;DR for Busy Readers</h2><div class="codeblock"><pre><code>- Miasma worm hit Red Hat’s npm namespace. At least 32 
@redhat-cloud-services releases tampered to steal AWS/GCP/Azure 
keys, Kubernetes service-account tokens, and Vault tokens at 
install time. Rotate cloud and CI secrets on any host that 
pulled affected versions since June 1.

- Two KEV deadlines this week. PAN-OS GlobalProtect auth bypass
 (CVE-2026-0257, mitigate by June 1) and Linux cgroups v1 
container escape (CVE-2022-0492, due June 5). Triage by 
config and node image, not CVSS.

- AI-built EDR-evasion lab surfaced. Sophos documented a 
crew using AI agents to iterate payloads against Sophos, 
CrowdStrike, and Microsoft Defender. Treat EDR as a detection 
layer to validate, not trust.

- Prompt-injection metrics don’t compare across labs. No two 
of the four major AI providers measure injection resistance 
the same way. Demand a vendor’s test methodology before 
deploying agents in sensitive workflows.

- Reva + Doke’s frame: run security at engineering speed. 
Embed small security pods in product teams, surface findings 
on the pull request, triage AI-generated bug-bounty noise with 
AI, and reserve humans for the novel work.
</code></pre></div><h2 class="heading" style="text-align:left;" id="this-weeks-security-news"> <b>THIS WEEK&#39;S TOP SECURITY HEADLINES</b></h2><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-miasma-supply-chain-worm-compromi"><b> 1. </b><b>Miasma Supply-Chain Worm Compromises @redhat-cloud-services npm Packages and Harvests Cloud Credentials</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source: </b><a class="link" href="https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>Wiz Research</b></a><br><b>Reporting: </b><a class="link" href="https://www.bleepingcomputer.com/news/security/red-hat-npm-packages-compromised-to-steal-developer-credentials/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>BleepingComputer</b></a><b> · </b><a class="link" href="https://www.cybersecuritydive.com/news/dozens-red-hat-npm-packages-supply-chain-attack/821723/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>Cybersecurity Dive</b></a><b> · </b><a class="link" href="https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>Aikido</b></a><br><b>Analysis: </b><b><a class="link" href="https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Palo Alto Unit 42</a></b></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> Wiz Research reported on June 1 that at least 32 package releases under the @redhat-cloud-services npm namespace carried unauthorized modifications that didn’t match their source repositories. The payload is “Miasma,” a new variant of the Mini Shai-Hulud credential-stealing worm whose code TeamPCP previously open-sourced. A compromised Red Hat employee GitHub account was used to push malicious orphan commits to two RedHatInsights repositories, bypassing code review; the tampered packages ran obfuscated preinstall scripts at install time, attempting to collect GitHub Actions tokens; AWS, Google Cloud, and Azure credentials; HashiCorp Vault tokens; Kubernetes service-account tokens and kubeconfig files; npm and PyPI publishing tokens; SSH keys; Docker registry credentials; and .env files. Affected packages average ~80,000 weekly downloads. Wiz called the TeamPCP link TTP overlap, not definitive attribution.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> Once Shai-Hulud was open-sourced, the worm became commodity code anyone can fork — so “is this TeamPCP?” stops being the useful question. The intrusion rode a maintainer’s account and orphan commits past code review into a trusted vendor namespace, and the theft executes at npm install on developer and CI hosts, not at runtime. The credential target list reads like a cloud-platform team’s secret store.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-cisa-adds-panos-global-protect-au"><b>2. </b><b>CISA Adds PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) to KEV — June 1 Federal Deadline</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source: </b><a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>CISA KEV Catalog</b></a><b> · </b><a class="link" href="https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>Rapid7</b></a><br><b>Reporting: </b><a class="link" href="https://www.bleepingcomputer.com/news/security/palo-alto-globalprotect-vpn-auth-bypass-flaw-now-exploited-in-attacks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>BleepingComputer</b></a><b> · </b><a class="link" href="https://thehackernews.com/2026/05/pan-os-globalprotect-authentication.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>The Hacker News</b></a><br><b>Vendor advisory: </b><b><a class="link" href="https://security.paloaltonetworks.com/CVE-2026-0257?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Palo Alto Networks</a></b></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> CISA added CVE-2026-0257, an authentication bypass in PAN-OS and Prisma Access GlobalProtect, to the KEV catalog on May 29 with a June 1 federal mitigation deadline. Rapid7 MDR observed exploitation across multiple customers, earliest activity on May 17, and reported no successful lateral movement from affected devices. The flaw lets an unauthenticated remote attacker establish a VPN connection through the GlobalProtect gateway when authentication-override cookies are enabled alongside a specific certificate configuration.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> The bypass turns the remote-access gateway — the control meant to gate who reaches the network — into an unauthenticated entry path. Exposure depends on a specific configuration, not mere presence of the product, so CVSS-only triage won’t tell a team which appliances are actually reachable. The disclosure-to-KEV interval was short (exploitation observed May 17, listed May 29), ahead of normal monthly patch rhythms.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-cisa-adds-linux-kernel-cgroups-co"><b>3. </b><b>CISA Adds Linux Kernel cgroups Container-Escape Flaw (CVE-2022-0492) to KEV — Due June 5</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source: </b><a class="link" href="https://www.cisa.gov/news-events/alerts/2026/06/02/cisa-adds-two-known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>CISA alert</b></a><br><b>Reporting: </b><a class="link" href="https://www.securityweek.com/organizations-warned-of-exploited-linux-kernel-vulnerability/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>SecurityWeek</b></a><br><b>Analysis: </b><b><a class="link" href="https://unit42.paloaltonetworks.com/cve-2022-0492-cgroups/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Palo Alto Unit 42</a></b><b> · </b><b><a class="link" href="https://www.aquasec.com/blog/new-linux-kernel-vulnerability-escaping-containers-by-abusing-cgroups/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Aqua Security</a></b></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> On June 2, CISA added CVE-2022-0492 — a privilege-escalation flaw in the Linux kernel’s cgroups v1 control-groups feature — to the KEV catalog with a June 5 federal remediation deadline (the same alert added Android Framework zero-day CVE-2025-48595). The cgroups bug lets a process modify the release_agent file, which executes as root in the host namespace; combined with a new user namespace, it allows container escape to the host. Only cgroups v1 is affected. Technical details were published roughly three years ago, but in-the-wild exploitation was reported only recently — one day before CISA’s alert.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> A three-year-old kernel flaw earning a fresh KEV listing is the week’s quiet but pointed item: the payoff is escape from a container to its host, which on a shared Kubernetes node means crossing the tenancy boundary teams treat as a containment line. The operative signal is recency-of-exploitation, not recency-of-disclosure.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-sophos-uncovers-an-ai-coordinated"><b>4. </b><b>Sophos Uncovers an AI-Coordinated Lab Built to Test Malware Against Named EDRs</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source: </b><a class="link" href="https://www.bleepingcomputer.com/news/security/ai-built-ransomware-toolkit-automates-edr-evasion-ad-discovery/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>Sophos research (via BleepingComputer)</b></a><br><b>Reporting: </b><b><a class="link" href="https://www.helpnetsecurity.com/2026/06/02/ai-agents-edr-evasion-techniques/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Help Net Security</a></b><b> · </b><b><a class="link" href="https://cybersecuritynews.com/hackers-using-ai-red-team-tools/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">CyberSecurityNews</a></b></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> Sophos disclosed a threat actor’s Git repository containing an automated Active Directory discovery panel and a lab that iteratively develops and tests malware against Sophos, CrowdStrike, and Microsoft Defender EDR agents. Per Sophos, the framework used multiple AI agents coordinated by a Claude Opus 4.5 agent, connected via Model Context Protocol to Git repositories and built with tools including Cursor and Ludus, testing a Python payload tool’s ~80 modules and 70-plus evasion techniques across dedicated VMs. Sophos linked the activity to ransomware and data-theft operations but didn’t name the group. It also noted the lab’s own documentation claimed the evasion modules improved with refinement, but the test data didn’t support those claims — likely LLM hallucination in the attacker’s tooling.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> The signal isn’t “AI writes malware” — it’s that the crew built an automated test rig against three named commercial EDRs, compressing the develop-test-refine loop that previously demanded a skilled operator. The hallucination caveat runs in the defender’s favor: the self-reported evasion rates were inflated, so the real capability may trail what the repo advertises. Two of the three targeted EDRs are widely deployed across cloud-hosted endpoint estates.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-cross-lab-review-the-four-major-a"><b>5. </b><b>Cross-Lab Review: The Four Major AI Providers Measure Prompt Injection With Incompatible Metrics</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source: </b><a class="link" href="https://venturebeat.com/security/anthropic-browser-agent-hijacked-31-percent-before-safeguards-engaged?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>VentureBeat Security</b></a><br><b>Related coverage: </b><b><a class="link" href="https://venturebeat.com/security/prompt-injection-measurable-security-metric-one-ai-developer-publishes-numbers?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">VentureBeat</a></b></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> A VentureBeat comparison published June 1 found that Anthropic, OpenAI, Google, and Meta each released prompt-injection disclosures in 2026, but no two used the same metrics — different test conditions, attack types, and success-rate definitions, with no shared adversarial test suite. Anthropic reported browser-agent hijacking rates; other labs focused on indirect injection in tool-calling or document-summarization tasks. The review advised teams to treat each lab’s numbers on their own terms and to request methodology before deploying agents in sensitive workflows.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> Enterprises evaluating AI agents have no common denominator — a “31% before safeguards engaged” figure from one lab and a tool-calling success rate from another aren’t comparable, so procurement can’t rank models on injection resistance the way it ranks a CVSS score. With agents now writing and testing offensive code (story 4) and propagating through package ecosystems (story 1), the measurement gap sits on a control teams increasingly depend on.</p><hr class="content_break"><h4 class="heading" style="text-align:left;" id="6-white-house-executive-order-sets-"><b>6. White House Executive Order Sets Voluntary Federal Review and Cyber-Capability Benchmarking for Frontier AI Models</b></h4><p class="paragraph" style="text-align:left;"><b>Primary source: </b><a class="link" href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>The White House</b></a><br><b>Reporting: </b><b><a class="link" href="https://rollcall.com/2026/06/02/executive-order-sets-voluntary-cyber-reviews-for-advanced-ai/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Roll Call</a></b><b> · </b><b><a class="link" href="https://www.cfr.org/articles/assessing-trumps-executive-order-on-ai-oversight?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Council on Foreign Relations</a></b></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> On June 2 the White House issued “Promoting Advanced Artificial Intelligence Innovation and Security.” It directs Treasury, the NSA, and CISA to design, within 60 days, a voluntary framework under which developers may submit a frontier model for federal evaluation; “covered frontier models” would be made available to the government for up to 30 days before public release. The order establishes a classified NSA-led benchmarking process for offensive cyber capabilities and a voluntary AI cybersecurity clearinghouse to coordinate vulnerability discovery and patching. It explicitly creates no mandatory licensing, preclearance, or permitting requirement.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> The load-bearing elements for security teams are the clearinghouse and the cyber-capability benchmark, not a compliance mandate — this is the government building a pre-release read on what frontier models can do offensively, the same measurement the Sophos lab (story 4) and the prompt-injection gap (story 5) show the private sector can’t yet produce consistently. Framing it as “increased regulatory scrutiny” overstates an order that imposes no obligation today.</p><hr class="content_break"><h4 class="heading" style="text-align:left;" id="7-cisco-restructures-vulnerability-"><b>7. Cisco Restructures Vulnerability Disclosure Around the AI-Compressed Exploit Gap, Adds Runtime Live Protect</b></h4><p class="paragraph" style="text-align:left;"><b>Primary source (reporting): </b><a class="link" href="https://www.axios.com/2026/06/02/cisco-revamps-vulnerability-disclosures-for-the-ai-era?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>Axios</b></a><b> · </b><a class="link" href="https://www.helpnetsecurity.com/2026/05/25/cisco-risk-based-vulnerability-disclosure-ai/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>Help Net Security</b></a><br><b>Vendor primary: </b><b><a class="link" href="https://blogs.cisco.com/security/strengthening-the-foundation-a-predictable-customer-focused-response-to-ai-accelerated-vulnerability-discovery?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Cisco — disclosure cadence</a></b><b> · </b><b><a class="link" href="https://blogs.cisco.com/news/shields-up-cisco-live-protect-closes-vulnerability-gap-with-compensating-controls?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Cisco — Live Protect</a></b></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> At Cisco Live 2026, Cisco said it will move to scheduled twice-monthly security advisories on the first and third Wednesdays of each month starting in July, with seven days’ advance notice of which technologies each release covers and a stronger risk-based emphasis on flaws under active exploitation. Cisco cited Talos data showing the interval between disclosure and first observed exploitation is compressing as attackers adopt AI automation. It also introduced Live Protect, which applies runtime compensating controls to shield a device against exploitation of a newly disclosed flaw — no reboot or upgrade required — while a permanent patch is staged.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> The disclosure-cadence change is the signal, not the product: a major infrastructure vendor is rebuilding how it releases advisories because the disclosure-to-exploitation window is shrinking — the same dynamic the PAN-OS (story 2) and cgroups (story 3) KEV timelines show this week. Predictable windows let teams pre-stage change windows, but they also concentrate patch load on dates adversaries can anticipate. Live Protect is a bet that runtime compensating controls, not patching speed alone, become the near-term answer.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="security-at-the-speed-of-engineerin"><b>Security at the Speed of Engineering — Guardrails, Not Gates</b></h3><p class="paragraph" style="text-align:left;">Every story above shares a clock problem. The Miasma worm executed at install time, the PAN-OS and cgroups flaws hit KEV faster than monthly patch cycles, the Sophos lab compressed the malware develop-test loop, and Cisco is rebuilding disclosure cadence specifically because the disclosure-to-exploitation window is shrinking. The week’s news is, in aggregate, a story about offense moving faster than the controls built to catch it.</p><p class="paragraph" style="text-align:left;">That is exactly the problem Nick Reva designs around at DoorDash. His answer isn’t a new product — it’s a placement decision: put small security teams inside the product teams, and make the security signal arrive where engineers already work, on the pull request, at the speed they ship. Shivani Doke makes the parallel case for governance: stop treating GRC as an annual document refresh and start embedding controls in the lifecycle, validated at runtime. Two halves of one argument about where a control has to live to survive a faster attacker. <i>[</i><a class="link" href="https://www.aisecuritypodcast.com/videos/securing-ai-at-the-speed-of-engineering?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><i>Listen to the full episode →</i></a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;"><b>Featured Experts This Week </b>🎤</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/nickreva/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>Nick Reva</b></a> — Global Security Engineering lead, DoorDash (previously Snapchat, SpaceX)</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/shivani-doke/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>Shivani Doke</b></a> — GRC Engineer</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Shift far left:</b> Nick Reva’s extension of “shift left” — embedding small (3–5 person) security tiger teams directly into the product teams building AI features, hardening each surface in its own context with guardrails rather than approval gates.</p></li><li><p class="paragraph" style="text-align:left;"><b>Forward-deployed security teams / pods:</b> Small embedded security teams that own the highest-priority product areas, credited on stage to Jason Chan’s “Netflix model.” Distinct from a central AppSec-tooling team that lacks per-team, per-month context.</p></li><li><p class="paragraph" style="text-align:left;"><b>Promptfoo:</b> An open-source prompt-injection testing framework Reva likened to Burp Suite for AI — packaged rules you tweak to test for prompt injection, model efficacy, and model ethics, run as an integration test on the pull request.</p></li><li><p class="paragraph" style="text-align:left;"><b>“Claude Kiddies”:</b> Reva’s coinage (a play on “script kiddies”) for low-skill actors who use AI to generate bug-bounty reports — and then to argue back against triage teams.</p></li><li><p class="paragraph" style="text-align:left;"><b>Security Knowledge Graph:</b> Reva’s runtime control-validation system built on the open-source Cartography framework — it aggregates cloud and endpoint telemetry into a node graph, checks whether a designed control is operating against live runtime data (via eBPF probes observing pod security and Docker exposure), and auto-routes drift to the owning team via Slack or Jira.</p></li><li><p class="paragraph" style="text-align:left;"><b>GRC engineering:</b> Shivani Doke’s discipline — moving GRC from point-in-time PDF-policy refreshes to controls embedded in the development lifecycle and validated continuously (runtime monitoring, RASP, attack-surface and supply-chain scanning, compliance enforced as code).</p></li><li><p class="paragraph" style="text-align:left;"><b>Nth-party / transitive vendor risk:</b> Third-party vendors carry their own vendors (fourth-, fifth-, Nth-party); a breach anywhere in the transitive dependency chain can expose your data. Current Nth-party monitoring tooling is immature.</p></li><li><p class="paragraph" style="text-align:left;"><b>Human-in-the-loop:</b> Reva’s design pattern for autonomous offensive/defensive agents — humans gate the critical decision points; the main-line work is mostly automated.</p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <a class="link" href="https://links.cloudsecuritypodcast.tv/checkpoint-report-june2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>CheckPoint</b></a></p><p class="paragraph" style="text-align:center;">77% have an AI strategy. Only 26% can enforce it.</p><p class="paragraph" style="text-align:left;">Enterprises are adopting AI faster than security can keep up. GenAI, copilots, and autonomous agents are getting greenlit at the top — then landing on teams with no way to see, govern, or stop them when something goes wrong.</p><p class="paragraph" style="text-align:left;">The strategy exists. The enforcement doesn&#39;t.</p><p class="paragraph" style="text-align:left;">Join Ashish Rajan with Check Point&#39;s David Haber and Paul Barbosa to work through where traditional security models fall short on AI, and what real-time enforcement actually takes across cloud, SaaS, endpoint, and hybrid.</p><p class="paragraph" style="text-align:center;">[<a class="link" href="https://links.cloudsecuritypodcast.tv/checkpoint-report-june2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Register here for to join the LIVE Event</a>]</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><hr class="content_break"><h4 class="heading" style="text-align:left;" id="1-shift-far-left-guardrails-not-gat"><b>1. Shift far left: guardrails, not gates</b></h4><p class="paragraph" style="text-align:left;">The reason the week’s news keeps beating monthly patch cycles is that the attacker’s loop now runs at engineering speed. Reva’s response is to move security to where the engineers already are. Beyond the familiar “shift left,” he frames it as “shift far left”: small security teams embedded inside the product teams building AI features.</p><p class="paragraph" style="text-align:left;"><i>“far left means you embed small teams, small tiger teams of security engineers into the development teams are working on the AI initiatives to harden the AI initiatives.”</i>  — Nick Reva</p><p class="paragraph" style="text-align:left;">The mechanism is deliberately not a gate. At a three-sided marketplace — dashers, merchants, customers — each surface carries a different AI experience and so a different threat model, and the control has to fit the way each team ships:</p><p class="paragraph" style="text-align:left;"><i>“the shift far left is establishing guardrails not gates into your product development story.”</i>  — Nick Reva</p><p class="paragraph" style="text-align:left;">Concretely, that means integrating Promptfoo into every repo where AI development happens, writing lint-style rules that look for prompt injections in the agent frameworks in use, and building middle-tier service layers that filter both the prompt and the response. The connection to this week’s news is direct: story 5’s finding that the four major labs can’t agree on how to measure prompt-injection resistance is the strategic version of the same problem Reva solves tactically — if you can’t buy a comparable injection metric, you test injection yourself, in your own pipeline, against your own tool-calling paths.</p><h4 class="heading" style="text-align:left;" id="2-make-the-security-signal-arrive-o"><b>2. Make the security signal arrive on the pull request</b></h4><p class="paragraph" style="text-align:left;">Guardrails beat gates because engineering teams move at engineering speed and won’t stop to ask permission. Reva’s design puts the security check inline, where an engineer is already looking:</p><p class="paragraph" style="text-align:left;"><i>“if, for example, an engineer opens up a PR on the repo for one of the… agent frameworks and Promptfoo runs as an integration test and gives them direct feedback on the PR, they’re gonna respond to it like, no, no engineer wants to ship… an agent framework that has prompt injection.”</i>  — Nick Reva</p><p class="paragraph" style="text-align:left;"><i>“You have to meet the team at the speed of that the team is operating at.”</i>  — Nick Reva</p><p class="paragraph" style="text-align:left;">He noted the open-source version of Promptfoo is powerful enough that buying the commercial tier hasn’t been necessary, though they make it fit their SDLC — and that the same framework does double duty for model-efficacy and model-ethics testing. This is the practitioner answer to Cisco’s story-7 bet: when the disclosure-to-exploitation window shrinks, the control has to be already running where the work happens, not staged for a future change window.</p><h4 class="heading" style="text-align:left;" id="3-scale-scarce-security-pods-with-a"><b>3. Scale scarce security pods with AI-assisted threat modeling</b></h4><p class="paragraph" style="text-align:left;">Headcount never matches engineering scale, so the move is to make a small number of forward-deployed engineers far more productive.</p><p class="paragraph" style="text-align:left;"><i>“I have 2,500 engineers and I have three of these security pods… I don’t have 10, I don’t have 20, I probably never will from a headcount perspective. So how do I make those three people like really good at their job?”</i>  — Nick Reva</p><p class="paragraph" style="text-align:left;">The experiment is AI-assisted threat modeling and product-security review — not generic ChatGPT, but context-specific models wired into the GitHub repos under review. The maturity sequence Reva described: make the human pods better first, iterate the model, then expose it to product teams as self-service.</p><p class="paragraph" style="text-align:left;"><i>“the idea is to make the forward deployed security engineer more productive. And then later the idea is to take this and give it to the product teams as like a Chrome extension… this agentic security review framework… we’ll have a virtual security engineer that’ll give you feedback that’s like really calibrated.”</i>  — Nick Reva</p><p class="paragraph" style="text-align:left;">An audience practitioner described the same shape from the other side: a “baseline automated prodsec” approach that democratizes a SAST/DAST/SCA/threat-model baseline so every feature gets immediate early feedback, with humans reserved for complex code reviews, complex threat models, and tabletop exercises, gated by risk-based acceptance criteria before production.</p><h4 class="heading" style="text-align:left;" id="4-security-decisions-are-business-d"><b>4. Security decisions are business decisions — fund and own them accordingly</b></h4><p class="paragraph" style="text-align:left;">The forward-deployed model only works if everyone agrees on who owns the call. Reva is blunt that the security team isn’t the decision-maker:</p><p class="paragraph" style="text-align:left;"><i>“We’re led to believe security decisions are a security team responsibility. They’re not, they’re a business decision ultimately… The security team is the fact finder about risk and we help them provide technical solutions to solve problems, right? But ultimately the business makes the decision on what we wanna do.”</i>  — Nick Reva</p><p class="paragraph" style="text-align:left;">The pod model itself he credits to a lineage:</p><p class="paragraph" style="text-align:left;"><i>“Jason Chan invented this idea of forward deployed security teams… that were deployed into the product areas in small tiger teams… And I’ve adopted this at DoorDash.”</i>  — Nick Reva</p><p class="paragraph" style="text-align:left;">The budgeting takeaway he offered: align the pod’s funding ask with whatever business line security reports into (DoorDash’s reports into Legal, which he said works fine), and treat AI risk as one novel, complex category of business risk the board must hear about — not a siloed security cost.</p><h4 class="heading" style="text-align:left;" id="5-claude-kiddies-ai-collapses-the-a"><b>5. “Claude Kiddies”: AI collapses the attacker skill floor — so triage with AI</b></h4><p class="paragraph" style="text-align:left;">Asked what AI attack actually keeps him up, Reva’s answer wasn’t novel malware. It was volume and the disappearance of the skill bar for low-end offense:</p><p class="paragraph" style="text-align:left;"><i>“the hobbyist level people are getting involved… There used to be like a… level of technical proficiency that you have to have to do this kind of work. It’s gone… ’cause they’re vibe coding the bug bounty reports.”</i>  — Nick Reva</p><p class="paragraph" style="text-align:left;">His coinage for them — a play on “script kiddies” — was the line of the night: they’re “Claude Kiddies.” An audience member noted curl recently closed its bug-bounty program over an influx of AI-generated reports. Reva’s response is symmetric, and maps onto the Sophos lab in story 4 (offense automated, defense automates back):</p><p class="paragraph" style="text-align:left;"><i>“if they’re using Claude to generate bug bounty reports, we have to use Claude to triage those reports.”</i>  — Nick Reva</p><p class="paragraph" style="text-align:left;">The nuance worth keeping: he argued bug bounties absolutely should still exist, because the genuinely novel, high-complexity vulnerabilities still won’t be found by automated pentest tooling, and “there shouldn’t be a race to the bottom in every category.” Triage the AI noise with AI; reserve human researchers for the consequential, novel work.</p><h4 class="heading" style="text-align:left;" id="6-humanintheloop-at-the-critical-de"><b>6. Human-in-the-loop at the critical decision points, automation on the main line</b></h4><p class="paragraph" style="text-align:left;">The bug-bounty discussion ran into the harder question: an autonomous offensive agent has no “rules of engagement” the way a human pentester does — you can’t easily tell it “this is far enough.” Reva’s model, which he tied to the Anthropic framing, is to gate the decisions that matter and automate the rest:</p><p class="paragraph" style="text-align:left;"><i>“it’s human in the loop for the critical decision points. And then… maybe like the main line aspects of it are… mostly automated, right?”</i>  — Nick Reva</p><p class="paragraph" style="text-align:left;">For teams deploying offensive or autonomous security agents, the design pattern is to place explicit human approval at the consequential points — scope expansion, exploitation, lateral movement — rather than trying to encode complete rules of engagement up front, and automate the routine work between those gates. It’s the same principle the story-6 executive order reaches for at national scale: build the measurement and the review checkpoint, don’t pretend full autonomy is safe.</p><h4 class="heading" style="text-align:left;" id="7-grc-engineering-move-off-the-annu"><b>7. GRC engineering: move off the annual PDF refresh and embed controls in the lifecycle</b></h4><p class="paragraph" style="text-align:left;">Shivani Doke’s half of the conversation reframes governance the same way Reva reframes appsec. The reputation problem, she argued, comes from GRC being a point-in-time, document discipline:</p><p class="paragraph" style="text-align:left;"><i>“that’s where the beef… against the GRC folks really comes because we mostly focus on having all these policies. There’s this annual policy refresh where we just make some edits in the Word document in the PDFs… But we have to move away from that towards… really embedding these security controls within our development life cycles.”</i>  — Shivani Doke</p><p class="paragraph" style="text-align:left;">On ownership, she rejects a one-team answer:</p><p class="paragraph" style="text-align:left;"><i>“who owns AI risk really depends on the use case.”</i>  — Shivani Doke</p><p class="paragraph" style="text-align:left;">A business unit that requests an AI-forward vendor owns that vendor’s risk (via third-party assessment, model cards, continuous scanning); an in-house fine-tuned or foundational model puts ownership on the IT or developer-experience team building it. The concrete GRC-engineering control she described: if policy says no AI-agent-authored code can be merged, implement an automated flag — a two-person control — that blocks that code in the pipeline rather than attesting it in a document. An audience practitioner added the audit-automation angle: run a “SOC 2 every morning at 10:00 AM” to check whether built controls are still intact, and tie breaks to business risk before they become audit risk.</p><h4 class="heading" style="text-align:left;" id="7-grc-engineering-move-off-the-annu"><b>7. Continuous validation across an Nth-party attack surface</b></h4><p class="paragraph" style="text-align:left;">The most cloud-relevant control of the night ties both speakers together. Reva offered his “Security Knowledge Graph” — built on the open-source Cartography framework — as GRC engineering in practice: aggregate cloud and endpoint telemetry into a node graph and check, at runtime, whether a designed control is actually operating.</p><p class="paragraph" style="text-align:left;"><i>“you can even take controls that you’ve designed and say, is this control operating based on real time runtime data? So you have like eBPF probes, like observing your pod security… you can actually do that at runtime to see if that control is implemented. And if it isn’t… then you can fire a Slack notification or a Jira ticket to that owning team.”</i>  — Nick Reva</p><p class="paragraph" style="text-align:left;">Doke supplied the reason that runtime validation now has to reach down the supply chain — the vendor surface is transitive:</p><p class="paragraph" style="text-align:left;"><i>“when you onboard a third party vendor, you’re also onboarding that third party vendor’s other dependencies, other vendors. So basically that becomes a transitive dependency. So if something happens to my data that’s been hosted on the third party’s cloud and the third party’s cloud security provider has a breach, then my data has been breached.”</i>  — Shivani Doke</p><p class="paragraph" style="text-align:left;">This is the conversation’s tightest link to the week’s lead story. The Miasma worm (story 1) is exactly an Nth-party compromise — a trusted vendor’s namespace, poisoned upstream, stealing Kubernetes service-account tokens at install time — and the cgroups escape (story 3) is exactly the pod-boundary failure Reva’s eBPF probes are watching for. Doke flagged that current Nth-party monitoring tooling is “not… state of the art” and can’t yet be fully relied on; the practical posture is to interrogate each vendor’s own AI dependencies and downstream sub-processors, and to validate the controls you depend on against live runtime data rather than a signed attestation.</p><h4 class="heading" style="text-align:left;" id="practical-takeaways-for-cloud-secur"><b>Practical takeaways for cloud security leaders</b></h4><p class="paragraph" style="text-align:left;">A few things senior cloud security leaders can act on in the next 30–60 days:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Put the security signal on the pull request. </b>Run prompt-injection testing (e.g., Promptfoo) as an integration test in every repo where AI development happens, so engineers get inline feedback rather than a gate they route around.</p></li><li><p class="paragraph" style="text-align:left;"><b>Test injection yourself — don’t buy a comparable metric. </b>The labs don’t agree on how to measure it, so run adversarial tests against your own tool-calling and retrieval paths before deploying an agent in a sensitive workflow.</p></li><li><p class="paragraph" style="text-align:left;"><b>Validate controls at runtime, not on paper. </b>Stand up control-validation against live telemetry (eBPF pod-security probes, cloud + endpoint graph) and auto-route drift to the owning team via Slack or Jira.</p></li><li><p class="paragraph" style="text-align:left;"><b>Triage AI bug-bounty noise with AI. </b>Use automation to clear the low-skill, AI-generated report volume and reserve human researchers for novel, high-complexity findings.</p></li><li><p class="paragraph" style="text-align:left;"><b>Reach down the supply chain. </b>Treat install-time scripts and transitive (Nth-party) dependencies as a credential-theft surface — monitor preinstall/postinstall execution and interrogate each vendor’s own AI dependencies and sub-processors.</p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="mental-model-the-vendor-list-was-th">🧠<b> </b>Mental Model — The Vendor List Was the Inventory. The Inventory Is Now the Vendor List.</h2><p class="paragraph" style="text-align:left;">For 20 years, security ran on gates: a review step that work had to pass through before it shipped. The gate worked because the attacker’s loop was slower than the approval cycle — there was time to stop, inspect, and sign off.</p><p class="paragraph" style="text-align:left;">That timing assumption is now inverted. The Miasma worm executed at install time, the KEV deadlines beat monthly patch cycles, the Sophos lab compressed the malware develop-test loop, and Cisco is rebuilding its disclosure cadence around a shrinking disclosure-to-exploitation window. When offense runs at engineering speed, a gate is just a place the attacker has already passed.</p><p class="paragraph" style="text-align:left;">The control that survives is the one already running where the work happens — on the pull request, in the pipeline, against live runtime telemetry — with a human reserved only for the consequential decision. Guardrails, not gates. Embed the control in the lifecycle, validate it continuously, and put the human at the point of risk acceptance, not at the door.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>📚 RELATED RESOURCES 🎧</b></h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Wiz Research — Miasma supply-chain attack on Red Hat npm packages</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Palo Alto Unit 42 — Monitoring npm supply-chain attacks</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">CISA Known Exploited Vulnerabilities (KEV) Catalog</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://unit42.paloaltonetworks.com/cve-2022-0492-cgroups/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Palo Alto Unit 42 — CVE-2022-0492 cgroups container-escape analysis</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.aquasec.com/blog/new-linux-kernel-vulnerability-escaping-containers-by-abusing-cgroups/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Aqua Security — Escaping containers by abusing cgroups</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bleepingcomputer.com/news/security/ai-built-ransomware-toolkit-automates-edr-evasion-ad-discovery/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Sophos research (via BleepingComputer) — AI-built ransomware toolkit automates EDR evasion</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">The White House — Promoting Advanced AI Innovation and Security (executive order)</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/promptfoo/promptfoo?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>Promptfoo</b></a><a class="link" href="https://github.com/promptfoo/promptfoo?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"> — open-source prompt-injection / LLM testing framework </a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/cartography-cncf/cartography?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>Cartography</b></a><a class="link" href="https://github.com/cartography-cncf/cartography?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"> — open-source asset/relationship security graph framework</a></p></li></ul><h3 class="heading" style="text-align:left;" id="podcast-episode"><b>Podcast Episode</b></h3><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.aisecuritypodcast.com/videos/securing-ai-at-the-speed-of-engineering?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow"><b>Full Episode with Nick Reva and Shivani Doke</b></a> — Complete transcript and audio for this week&#39;s featured conversation</p></li></ul><hr class="content_break"><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔 <i>Is your security signal arriving on the pull request, or still waiting at a gate the attacker already ran past?</i><br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=cloud-credential-worm-hit-red-hat-doordash-s-approach-to-security-at-the-speed-of-engineering" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=5a687b5d-97c9-45ee-8d62-1e9f8d5cf3ff&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🚨 Every Employee Vibe-Coding an App Is Now a Vendor - Igor and Jasper on Rebuilding TPRM for It</title>
  <description>The Netherlands blocked the first foreign acquisition of its national identity system host the same week the EU Tech Sovereignty Package landed. Two actively-exploited zero-days hit CISA&#39;s federal deadline. Lazarus Group went fully memory-resident against financial firms. And the two practitioners in this week&#39;s conversation — Lovable CISO Igor Andriushchenko and Athira CEO Jasper Mills — make the case that the third-party risk program most enterprises run today cannot see the AI-built apps already deployed inside the perimeter.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6633098c-afd2-4514-b79b-0dbac4ba43f7/Screenshot_2026-05-27_at_9.52.03_PM.png" length="1303054" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/vendor-inventory-already-wrong-second-party-risk-tprm</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/vendor-inventory-already-wrong-second-party-risk-tprm</guid>
  <pubDate>Wed, 27 May 2026 21:41:51 +0000</pubDate>
  <atom:published>2026-05-27T21:41:51Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">This week&#39;s Cloud Security Newsletter topic: <b>Third-Party Risk in the AI Era — Why Your Vendor Inventory Is Already Wrong </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" rel="noopener noreferrer nofollow">(continue reading)</a> </p><hr class="content_break"><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://links.cloudsecuritypodcast.tv/tamnoon-state-of-cloud-remediation-may2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it"><span class="button__text" style=""> This issue is sponsored by Tamnoon </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6633098c-afd2-4514-b79b-0dbac4ba43f7/Screenshot_2026-05-27_at_9.52.03_PM.png?t=1779915169"/></a><div class="image__source"><span class="image__source_text"><p><i>This image was generated by AI. It&#39;s still experimental, so it might not be a perfect match!</i></p></span></div></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;">The week, Europe codified digital sovereignty as procurement law the same week the Netherlands used its investment-screening authority to block a US company from buying the host of its national identity system. Two actively-exploited vulnerabilities (Drupal, Microsoft Defender) hit federal patch deadlines. A North Korean Lazarus subgroup went fully memory-resident, neutralizing most filesystem-based forensics in financial-sector intrusions. And Anthropic shipped a free in-IDE security review plugin for Claude Code that moves AppSec scrutiny inside the AI coding loop developers are already using.</p><p class="paragraph" style="text-align:left;">This week&#39;s conversation is with <b>Igor Andriushchenko</b>, CISO at <b>Lovable</b> (and 4x prior CISO across telco, AI, and medical-device companies), and <b>Jasper Mills</b>, co-founder and CEO of <b>ethira</b>, hosted by <b>Ashish Rajan</b>. The thread running through both the news and the episode: trust assumptions are breaking faster than the programs built to manage them. The vendor list is wrong because half the new vendors are five-person AI companies. The &quot;vendor&quot; category itself is wrong because every employee building with AI is functionally introducing third parties without procurement ever seeing them.<i>[</i><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/how-ai-agents-will-negotiate-your-vendor-contracts?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">⚡ TL;DR for Busy Readers</h2><div class="codeblock"><pre><code>- Netherlands blocks Kyndryl–Solvinity acquisition (DigiD host). EU Tech Sovereignty Package follows next day. CLOUD Act is now a procurement gate, not a legal-theory debate.

- Drupal CVE-2026-9082 actively exploited. CISA federal deadline today. PostgreSQL-only, CVSS 6.5 understates the operational risk.

- Microsoft pushed out-of-band patches for two Defender zero-days (RedSun, UnDefend) after six weeks of LPE exploitation. The EDR is the escalation path.

- Lazarus deployed memory-only RemotePE against financial and crypto firms. Filesystem-based EDR triage fails. Memory acquisition belongs in your IR runbook now.

- Igor + Jasper&#39;s frame: &quot;second-party risk&quot; — every employee vibe-coding an app with an MCP attached is a vendor your TPRM program does not know about.</code></pre></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="this-weeks-security-news">📰 <b>THIS WEEK&#39;S TOP SECURITY HEADLINES</b></h2><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-netherlands-blocks-kyndryl-solvin"><b> 1. </b><b>Netherlands Blocks Kyndryl–Solvinity Acquisition; EU Tech Sovereignty Package Lands the Next Day</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://digital-strategy.ec.europa.eu/en/policies/eu-tech-sovereignty?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">European Commission Digital Strategy</a> <br><b>Reporting:</b> <a class="link" href="https://techcrunch.com/2026/05/26/dutch-government-blocks-us-company-from-acquisition-citing-risk-to-public-interest/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">TechCrunch</a> · <a class="link" href="https://www.dutchnews.nl/2026/05/dutch-government-blocks-sale-of-digid-owner-to-us-tech-giant/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">DutchNews</a> <br><b>Analysis:</b> <a class="link" href="https://www.cnbc.com/2026/05/07/eu-commission-cloud-sensitive-data.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">CNBC</a> · <a class="link" href="https://thenextweb.com/news/the-netherlands-just-blocked-a-us-company-from-buying-the-cloud-provider-that-runs-dutch-digital-identity?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">TheNextWeb</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> On May 26, Dutch State Secretary for the Digital Economy Willemijn Aerdts issued a &quot;complete prohibition&quot; on Kyndryl&#39;s acquisition of Solvinity — the Dutch cloud provider that hosts DigiD, the national digital identity system used by millions of citizens to access tax, health, and government services. It is the first acquisition the Dutch Investment Screening Bureau (BTI) has ever fully blocked. The Dutch competition authority cleared the deal on antitrust grounds in February; the separate investment-screening review reached the opposite conclusion on public-interest grounds. The named concern was the US CLOUD Act.</p><p class="paragraph" style="text-align:left;">One day later, the European Commission unveiled its long-delayed Tech Sovereignty Package, which includes the Cloud and AI Development Act (CADA) and Chips Act 2.0. The package proposes to restrict EU member-state governments from using US-headquartered cloud platforms for sensitive public-sector data in healthcare, finance, and judicial systems. CLOUD Act is again the named cause. The package still requires all 27 member-state approvals.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> This is the first time the CLOUD Act has been codified as a procurement-disqualifying condition at EU scale rather than litigated through Schrems II–style data-protection rulings. The threat model is no longer hypothetical legal risk — it is a procurement gate. For US-headquartered enterprises with EU operations, the assumption that AWS, Azure, and GCP regions in Frankfurt, Dublin, or Paris are functionally interchangeable with sovereign-EU alternatives for sensitive public-sector contracts is now wrong. For European enterprises in regulated sectors, sovereignty review is moving from a contracts question to an architecture question. This connects to Jasper&#39;s point in this week&#39;s conversation: contractual accountability under DORA is the closest existing analogue, and the same mechanism — written guardrails that follow the data — is what regulators are now extending across the rest of EU procurement.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-drupal-cve-20269082-actively-expl"><b>2. </b><b>Drupal CVE-2026-9082 — Actively Exploited, CISA Federal Deadline Today</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://www.drupal.org/sa-core-2026-004?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Drupal advisory SA-CORE-2026-004</a> <br><b>Reporting:</b> <a class="link" href="https://thehackernews.com/2026/05/drupal-core-sql-injection-bug-actively.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a> · <a class="link" href="https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-drupal-vulnerability/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer</a> <br><b>Analysis:</b> <a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">CISA KEV Catalog</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> Drupal disclosed CVE-2026-9082 on May 19 — an unauthenticated SQL injection in Drupal Core&#39;s database abstraction API affecting PostgreSQL-backed deployments. Drupal rated it &quot;highly critical&quot; (23 of 25 on its internal severity scale). Discovered by Google/Mandiant researcher Michael Maturi. Within 48 hours of patch release, Drupal updated its advisory to confirm exploitation in the wild. CISA added the CVE to KEV on May 22 with a federal civilian remediation deadline of <b>May 27</b> under BOD 22-01. Imperva reported observing over 15,000 attack attempts against nearly 6,000 sites across 65 countries, with gaming and financial services sites comprising roughly half the attack traffic. MySQL, MariaDB, and SQLite-backed deployments are not affected.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> Drupal Core sits behind a long tail of government, education, research, and enterprise public-facing sites. The vulnerability is unauthenticated and the gap between disclosure and in-the-wild exploitation was under 48 hours. Programs that triage by CVSS alone will deprioritize this — the score is 6.5, lower than the operational risk. EPSS and KEV are the better signals. The PostgreSQL specificity is a natural triage gate, but only if asset inventory is current enough to answer &quot;which Drupal sites are on Postgres?&quot; without paging someone.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-microsoft-defender-zero-days-red-"><b>3. </b><b>Microsoft Defender Zero-Days RedSun and UnDefend — Out-of-Band Patches After Six Weeks of Exploitation</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://msrc.microsoft.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Microsoft Security Response Center</a> <br><b>Reporting:</b> <a class="link" href="https://www.bleepingcomputer.com/news/security/microsoft-warns-of-new-defender-zero-days-exploited-in-attacks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer</a> · <a class="link" href="https://www.securityweek.com/microsoft-patches-exploited-undefend-and-redsun-defender-zero-days/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek</a> <br><b>Analysis:</b> <a class="link" href="http://www.techtimes.com/articles/316957/20260521/microsoft-defender-zero-days-patched-redsun-undefend-exploits-already-used-live-intrusions.htm?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">TechTimes (Huntress confirmation)</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> On May 21, Microsoft pushed out-of-band patches for two Windows Defender zero-days — CVE-2026-41091 &quot;RedSun&quot; (CVSS 7.8) and CVE-2026-45498 &quot;UnDefend&quot; (CVSS 4.0) — after six weeks of confirmed in-the-wild exploitation. RedSun is a local privilege escalation in the Microsoft Malware Protection Engine ≤1.1.26030.3008 caused by improper link resolution before file access. A low-privileged user can manipulate a symbolic link or directory junction during a Defender scan to escalate to SYSTEM. UnDefend is a DoS flaw exploited by standard users to block Defender definition updates. Both were originally disclosed publicly without coordination by a researcher operating under the aliases &quot;Chaotic Eclipse&quot; / &quot;Nightmare Eclipse&quot; between April 3 and April 16. The first in the series (BlueHammer, CVE-2026-33825) was patched April 14. RedSun and UnDefend went unpatched for six weeks while Huntress confirmed exploitation in hands-on intrusions. The same engine update (Microsoft Defender Antimalware Platform 4.18.26040.7) also fixes CVE-2026-45584, a heap-based RCE (CVSS 8.1) not yet confirmed exploited. CISA added RedSun and UnDefend to KEV on May 20 with a federal deadline of June 3.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> The exploited flaws are in the endpoint agent itself. The defensive control becomes the privilege-escalation vector — compromised low-privilege accounts reach SYSTEM through the AV the SOC trusts. This inverts the trust direction of the control, which makes it the most consequential class of EDR/EPP bug. For Windows cloud workloads (VDI, RDS gateways, jump boxes, Citrix farms on Azure, AWS, or GCP), this is the lateral-movement layer. CVE-2026-45584 — RCE without user interaction — is the one to watch. Exploitation isn&#39;t confirmed yet, but the technical bar is the lowest in the bundle.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-microsoft-share-point-cve-2026456"><b>4. </b><b>Microsoft SharePoint CVE-2026-45659 — RCE with Only Site Member Permissions</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://msrc.microsoft.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Microsoft Security Response Center advisory</a> <br><b>Reporting:</b> <a class="link" href="https://thehackernews.com/2026/05/microsoft-patches-sharepoint-rce-flaw.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a> · <a class="link" href="https://www.helpnetsecurity.com/2026/05/26/sharepoint-vulnerability-cve-2026-45659/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Help Net Security</a> <br><b>Analysis:</b> <a class="link" href="https://www.darkreading.com/vulnerabilities-threats/microsoft-issues-sharepoint-patch?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Dark Reading</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> Microsoft released patches for CVE-2026-45659 (CVSS 8.8), a high-severity RCE in on-premises SharePoint disclosed as part of May 2026 Patch Tuesday (advisory published May 21, broader coverage May 26–27). The flaw is a deserialization-of-untrusted-data issue (CWE-502). An attacker with only Site Member permissions — no admin rights, no elevated privileges — can execute code remotely on a SharePoint Server instance. Network vector, low complexity, no user interaction. Affected: SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Microsoft assesses exploitation as &quot;less likely&quot; with no public PoC at disclosure, but the 2025–26 pattern for SharePoint deserialization bugs has consistently been reclassification upward within weeks once PoCs surface — CVE-2026-32201 followed that pattern and was added to CISA KEV in April.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> &quot;Authenticated but only Site Member&quot; is almost no bar at all. SharePoint Site Member permissions are routinely granted to contractors, vendors, business-line partners, and broad employee groups. Treat this as one credential-compromise hop from RCE. The conservative move is to patch on Microsoft&#39;s original cadence, not the assessed-likelihood cadence. SharePoint Online is patched centrally by Microsoft; the hybrid and on-prem footprint is where the residual risk concentrates.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-lazarus-group-deploys-remote-pe-f"><b>5. </b><b>Lazarus Group Deploys RemotePE — Fully Memory-Resident RAT Against Financial and Crypto Firms</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Fox-IT (NCC Group)</a> <br><b>Reporting:</b> <a class="link" href="https://www.scworld.com/brief/north-koreas-lazarus-group-uses-new-remotepe-malware-against-financial-targets?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">SC Media</a> · <a class="link" href="https://thehackernews.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a> <br><b>Analysis:</b> <a class="link" href="https://www.cryptopolitan.com/north-korea-lazarus-target-crypto-banks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Cryptopolitan</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> On May 22, NCC Group subsidiary Fox-IT published research on a new toolset deployed by a North Korea-linked Lazarus subgroup (overlapping with AppleJeus, Citrine Sleet, UNC4736, and Gleaming Pisces) in IR engagements against financial and crypto organizations. The toolset has three components forming a chain: DPAPILoader decrypts and loads RemotePELoader from disk using the Windows Data Protection API; RemotePELoader beacons to a C2 server and receives RemotePE, a RAT executed entirely in memory with no filesystem artifacts. The chain uses environmental keying via DPAPI (the second-stage loader can only be decrypted on the originally-infected host), Hell&#39;s Gate direct syscalls, and ETW patching. Initial access is via Telegram social engineering, with the actor impersonating trading-firm employees using cloned Calendly and Picktime scheduling pages. This toolset replaced the actor&#39;s previous ThemeForestRAT and PondRAT.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> Memory-only execution plus DPAPI environmental keying defeats most filesystem-based forensics. The standard EDR triage workflow — pull artifacts, find the dropped binary, hash and pivot — collapses. The DPAPI keying is the technically interesting part: even if defenders capture RemotePELoader, they cannot decrypt the next stage on a different machine. That is anti-collaboration design by construction. The targeting (trading firms, DeFi, banks with international operations) is the same population that runs the most sensitive cloud workloads. AWS, Azure, and GCP credentials, BI tool API keys, and trading-platform integrations are the actual prize.</p><hr class="content_break"><h4 class="heading" style="text-align:left;" id="6-iranian-apt-nimbus-manticore-ai-a"><b>6. Iranian APT Nimbus Manticore — AI-Assisted MiniFast Backdoor, AppDomain Hijacking, SEO Poisoning</b></h4><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Check Point Research</a> <br><b>Reporting:</b> <a class="link" href="https://thehackernews.com/2026/05/iranian-hackers-deploy-minifast-and.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a> · <a class="link" href="https://www.securityweek.com/iranian-apt-targets-aviation-software-companies-with-updated-tools/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek</a> <br><b>Analysis:</b> <a class="link" href="https://www.infosecurity-magazine.com/news/iranian-hackers-us-aviation/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Infosecurity Magazine</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> On May 22, Check Point Research published &quot;Fast and Furious — Nimbus Manticore Operations During the Iranian Conflict,&quot; documenting three waves of activity between February and April 2026 by the IRGC-affiliated threat actor Nimbus Manticore (also tracked as UNC1549, Screening Serpens). The campaigns coincide with Operation Epic Fury, the joint US–Israeli military operation that began February 28. Targets: aviation, software, defense, and telecommunications organizations across the US, Europe, Saudi Arabia, and Australia. Three tradecraft shifts: AppDomain hijacking replaces DLL sideloading (a trojanized XML .config file placed next to a legitimate .NET application loads an attacker-controlled DLL via the AppDomainManager class); a new backdoor named MiniFast replaces the older MiniJunk family, with hallmarks Check Point attributes to AI-assisted development; and SEO poisoning via a counterfeit Oracle SQL Developer download page. The March wave used a trojanized Zoom installer.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> AppDomain hijacking is well-known but underweighted relative to DLL sideloading in most hunt programs. The detection signal — an XML .config file appearing next to a legitimate .NET binary, named after the abused binary with a <code>.config</code> suffix — is concrete and hunt-friendly. AI-assisted malware development is no longer a forecast. Check Point&#39;s fingerprints (excessive error handling on trivial functions, verbose repetitive naming, debug-style status strings) are now indicators. State-actor capability ramp times are getting shorter. Aviation, defense, and software-supplier organizations in Australia and Saudi Arabia in scope is worth flagging for AU/NZ readers — Iranian APT activity is not historically the top concern for that region.</p><hr class="content_break"><h4 class="heading" style="text-align:left;" id="7-anthropic-ships-claude-code-secur"><b>7. Anthropic Ships Claude Code Security-Guidance Plugin and Self-Hosted Sandbox</b></h4><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://www.securityweek.com/anthropic-releases-new-claude-sandbox-security-guidance-plugin/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Anthropic announcement (via SecurityWeek)</a> <br><b>Reporting:</b> <a class="link" href="https://www.helpnetsecurity.com/2026/05/27/anthropic-claude-code-security-guidance-plugin/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Help Net Security</a> · <a class="link" href="https://cybersecuritynews.com/free-security-plugin-for-claude-code/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Cybersecurity News</a> <br><b>Analysis:</b> <a class="link" href="https://github.com/anthropics/claude-code-security-review?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Anthropic open-source reference (GitHub)</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> At the Code w/ Claude event in London the week of May 26, Anthropic announced two security-relevant features for Claude Code, its terminal-based AI coding agent. The security-guidance plugin (free, all plans, launched May 26) is a three-layer reviewer that runs inside the Claude Code session. Layer one is a deterministic regex pass with no model call — it catches around 25 dangerous patterns (eval, os.system, child_process.exec, pickle deserialization, dangerouslySetInnerHTML and similar) at zero usage cost. Layers two and three are deeper agentic reviews triggered on model turns and on commits, reading surrounding callers and sanitizers to minimize false positives. Anthropic&#39;s internal rollout reported a 30–40% reduction in security-related PR comments. Anthropic separately announced a public-beta self-hosted sandbox: Claude Managed Agents now run tool execution in customer-controlled environments (the customer&#39;s own infrastructure or a managed provider like Cloudflare, Daytona, Modal, or Vercel), while the orchestration loop stays on Anthropic infrastructure. Files, repositories, and runtime images stay inside the customer perimeter.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> AppSec embedded in the AI coding loop is the architectural shift the senior reader&#39;s developers are already living through. Free, zero-config security review at the point of code creation collapses the developer-friction tax that has been the longstanding gap in shift-left. The self-hosted sandbox addresses the most concrete enterprise objection to agentic AI coding — that agent-executed code, files, and secrets leave the corporate perimeter. Cloud security architects now have an architecture pattern to point to: agent reasoning external, execution internal. This connects directly to Igor&#39;s framing in this week&#39;s conversation. When employees build with AI agents and connect MCPs to internal data, the company is creating second-party risk on a continuous basis. Tooling that catches issues at the point of creation is the only realistic way to keep up.</p><hr class="content_break"><h4 class="heading" style="text-align:left;" id="8-akamai-to-acquire-layer-x-for-205">🤖 8. <b>Akamai to Acquire LayerX for $205M — Browser-Layer AI Usage Control Becomes a Platform Feature</b></h4><p class="paragraph" style="text-align:left;"><i>Announced May 14 — outside the strict 5-day window but included as the largest cybersecurity M&A of May 2026 and directly relevant to the AI-governance thread running through this week&#39;s news.</i></p><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://www.akamai.com/newsroom/press-release/akamai-technologies-announces-intent-to-acquire-layerx-advancing-its-workforce-security-strategy-with-ai-usage-control?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Akamai press release</a> <br><b>Reporting:</b> <a class="link" href="https://www.securityweek.com/akamai-to-acquire-ai-and-browser-security-firm-layerx-for-205-million/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek</a> · <a class="link" href="https://www.helpnetsecurity.com/2026/05/15/akamai-layerx-acquisition/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Help Net Security</a> <br><b>Analysis:</b> <a class="link" href="https://www.bankinfosecurity.com/akamai-to-buy-layerx-for-205m-to-expand-ai-browser-security-a-31695?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">BankInfoSecurity</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> Akamai announced a definitive agreement to acquire LayerX, a Tel Aviv–based browser-native security firm, for approximately $205 million in cash. LayerX provides AI usage control and secure-enterprise-browser (SEB) technology that runs on top of standard browsers (Chrome, Edge, Safari) rather than requiring users to switch to a proprietary browser. The platform covers shadow AI discovery, gen-AI data loss prevention, access controls for AI tools, and protection for agentic browsers (Atlas, Comet). The deal is expected to close in Q3 2026. This is Akamai&#39;s third Israel-based security acquisition after Guardicore (2021, ~$600M) and Noname Security (2024, ~$450M).</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> Browser-layer telemetry is becoming a category. The deal validates that &quot;AI usage control&quot; — which workforce uses which models with which data — is a platform requirement, not a standalone product. For cloud security architects, this signals a likely shift in vendor roadmaps: browser-based DLP, SaaS access governance, and AI-tool inventory will converge with ZTNA and CASB rather than sit alongside them. Expect Zscaler, Palo Alto, and Netskope to respond with comparable consolidation moves. The agentic-browser detail (Atlas, Comet) is the forward-looking part. If workforce starts using AI browsers that act on their behalf, the security control point has to live there — network-layer DLP cannot see what a browser-resident agent does inside a session.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="third-party-risk-in-the-ai-era-why-">Third-Party Risk in the AI Era - Why Your Vendor Inventory Is Already Wrong</h3><p class="paragraph" style="text-align:left;">The pre-AI state of third-party risk management was, in Igor&#39;s word, <i>&quot;abysmal.&quot;</i> A spreadsheet of 200-question vendor checklists, hours filled out by both sides, generating documentation nobody reads until an auditor asks for it. Both sides know it is a paper exercise. Both sides do it anyway.</p><p class="paragraph" style="text-align:left;">What Igor and Jasper lay out in this week&#39;s conversation is that the program was barely surviving the old model when AI broke three assumptions underneath it at once. The vendor list shrank from a handful of large suppliers to dozens of five-person AI companies whose risk profile a 200-question checklist cannot meaningfully assess. The &quot;vendor&quot; boundary itself stopped holding — when an employee builds an internal app with AI and wires an MCP server into Salesforce, no procurement event has occurred, but a third party has effectively been introduced inside the perimeter. And the pace at which both sides operate started moving toward agent speed. Pactum is already running agent-to-agent procurement negotiations. The same architecture applied to vendor questionnaires is technically obvious. The only thing holding it back is comfort.</p><p class="paragraph" style="text-align:left;">That is the framing for this week&#39;s conversation. Igor and Jasper are not predicting a distant future. They describe a transition already happening in pieces — and a series of practical decisions cloud security leaders need to make in the next 12–18 months about what to automate, where to keep humans in the loop, and how to inventory a class of &quot;vendors&quot; the existing TPRM program cannot see. <i>[</i><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/the-zero-day-clock-how-ai-shrank-exploit-times-from-months-to-hours?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow"><i>Listen to the full episode →</i></a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;"><b>Featured Experts This Week </b>🎤</h2><ul><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/igorandriushchenko/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Igor Andriushchenko</a></b> — Head of Information Security & CISO, Lovable</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/jaspermills/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Jasper Mills</a></b> — Co-founder & CEO, ethira </p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Third-Party Risk Management (TPRM):</b> Assessing, monitoring, and governing the security and compliance posture of external suppliers — historically driven by vendor questionnaires (SIG, CAIQ), SOC 2 reports, pen test attestations, and contractual clauses.</p></li><li><p class="paragraph" style="text-align:left;"><b>Second-Party Risk:</b> Igor&#39;s term for the risk introduced when internal employees or departments build their own applications with AI — functionally creating new &quot;vendors&quot; the procurement-driven TPRM program never sees.</p></li><li><p class="paragraph" style="text-align:left;"><b>MCP (Model Context Protocol):</b> A protocol that lets AI agents connect to external tools and data sources through standardized connectors. An MCP server bridges a language model to systems like Salesforce, Git, databases, or internal APIs. From a TPRM perspective, every MCP connection is a privileged integration point.</p></li><li><p class="paragraph" style="text-align:left;"><b>Shadow AI:</b> AI tools adopted by employees without security or procurement review. A common pattern: employees bypass enterprise restrictions on a sanctioned tool by creating a personal account and re-enabling the feature there.</p></li><li><p class="paragraph" style="text-align:left;"><b>DORA (Digital Operational Resilience Act):</b> EU financial-sector regulation that requires ongoing, contractual accountability for ICT third-party providers — including subcontractors, exit strategies, and continuous monitoring. The closest existing analogue for how regulators will likely govern AI agents.</p></li><li><p class="paragraph" style="text-align:left;"><b>Agent-to-Agent (A2A):</b> The emerging pattern where one organization&#39;s AI agent communicates directly with another organization&#39;s AI agent — for procurement negotiation, vendor onboarding, or security questionnaire exchange. Pactum is one of the early production examples.</p></li><li><p class="paragraph" style="text-align:left;"><b>CLOUD Act:</b> US law (2018) that lets American law enforcement compel US-headquartered cloud and technology providers to disclose customer data regardless of where the data is physically stored. The named concern behind both the Dutch Kyndryl–Solvinity block and the EU Tech Sovereignty Package this week.</p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <a class="link" href="https://links.cloudsecuritypodcast.tv/tamnoon-state-of-cloud-remediation-may2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow"><b>Tamnoon</b></a></p><p class="paragraph" style="text-align:center;">The Alert Crisis: 14M Cloud Threats Found… But Who&#39;s Fixing Them?</p><p class="paragraph" style="text-align:left;">Tamnoon&#39;s 2026 State of Cloud Remediation Report analyzed over 14 million CNAPP detections across hundreds of enterprise environments and 10 CNAPPs.</p><p class="paragraph" style="text-align:left;">With 53% of detections still open across cloud environments, critical alerts taking 150 days to close, and vulnerability management MTTR increasing by 22% since last year, it’s clear more work needs to be done.</p><p class="paragraph" style="text-align:left;">Read the 2026 State of Cloud Remediation Report for a full breakdown of what&#39;s improving, what&#39;s regressing, and the benchmarks your board will ask about next quarter.</p><p class="paragraph" style="text-align:center;"><a class="link" href="https://links.cloudsecuritypodcast.tv/tamnoon-state-of-cloud-remediation-may2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Want to know the one category that got slower this year? See the full report.</a></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><hr class="content_break"><h4 class="heading" style="text-align:left;" id="1-the-pre-ai-state-was-a-paper-exer"><b>1. The pre-AI state was a paper exercise. AI doesn&#39;t fix it — it raises the stakes.</b></h4><p class="paragraph" style="text-align:left;">The opening framing from Igor lands the first point hard:</p><p class="paragraph" style="text-align:left;"><i>&quot;If you take a security program, right? There is a whole bunch of security program dedicated, any security program dedicated to third-party risk management. You can fail a lot of audits on it. It requires a lot of documentation, a lot of rigor. And the more, the bigger company becomes, the more impossible it becomes to control your vendors the way you actually bring value. It becomes this kind of paper exercise where you do something for the sake of doing it.&quot;</i> — <b>Igor Andriushchenko</b></p><p class="paragraph" style="text-align:left;">Jasper&#39;s experience implementing DORA at her previous company hit the same wall from a different direction — DORA&#39;s accountability requirements collided with the AI-tooling wave at exactly the moment her organization was trying to onboard productivity tools at speed:</p><p class="paragraph" style="text-align:left;"><i>&quot;The process of, like, using the tools on the market felt like I&#39;d been catapulted to 1979. It was the worst experience of my professional career.&quot;</i> — <b>Jasper Mills</b></p><p class="paragraph" style="text-align:left;">The practical implication for senior cloud security leaders: the program does not need optimization. The cadence at which AI-driven vendors arrive, and the rate at which employees create new internal applications that behave like vendors, is fundamentally incompatible with a checklist-driven model. Optimization within the existing frame produces the same paper exercise faster.</p><h4 class="heading" style="text-align:left;" id="2-secondparty-risk-is-the-new-categ"><b>2. Second-party risk is the new category — and the existing program cannot see it</b></h4><p class="paragraph" style="text-align:left;">The most useful new vocabulary in the conversation is Igor&#39;s distinction between third-party and <i>second-party</i> risk:</p><p class="paragraph" style="text-align:left;"><i>&quot;Should we treat each of these people or their departments as mini vendors? Because essentially we need to apply to those, whatever they produce, some kind of rules, some kind of governance. And that governance is very similar in its nature to third party risk. You&#39;re, like, it&#39;s almost like it&#39;s a second party risk. It&#39;s your employees, it&#39;s your builders.&quot;</i> — <b>Igor Andriushchenko</b></p><p class="paragraph" style="text-align:left;">Jasper&#39;s working example crystallizes the operational problem:</p><p class="paragraph" style="text-align:left;"><i>&quot;Or maybe John built it themselves... and then he found an MCP that he has spun up and now it&#39;s going to Salesforce and, like, fetching whatever it wants.&quot;</i> — <b>Jasper Mills</b></p><p class="paragraph" style="text-align:left;">There is no procurement event for John. No SOC 2 review. No vendor questionnaire. There is an MCP server reaching into a CRM, configured by someone in a non-technical team, governed by nothing. From a TPRM program&#39;s perspective, John&#39;s app does not exist. From an actual risk perspective, it is one of the highest-velocity new sources of exposure in the organization.</p><p class="paragraph" style="text-align:left;"><b>The practitioner translation:</b> TPRM coverage has to extend to inventory the program does not currently own. Discovery of internal apps, MCP servers, and the data sources they touch needs to live alongside the vendor inventory — and the same risk-tiering language needs to apply to both.</p><h4 class="heading" style="text-align:left;" id="3-the-kindergarten-with-a-nuclear-b"><b>3. The &quot;kindergarten with a nuclear bomb&quot; problem</b></h4><p class="paragraph" style="text-align:left;">Jasper&#39;s most-quoted line in the episode comes from a customer conversation, and it captures why the AI-productivity push is currently outrunning the controls:</p><p class="paragraph" style="text-align:left;"><i>&quot;A CISO called me and he said, like, &#39;We have just given a kindergarten a nuclear bomb.&#39;&quot;</i> — <b>Jasper Mills</b> (recounting a customer conversation)</p><p class="paragraph" style="text-align:left;">The CISO had enabled AI tooling for sales and other non-technical teams. The technology worked. The productivity gains were real. Visibility into what those teams were doing with the tooling — where data was going, which integrations had been wired up — was effectively zero. The control plane lagged the adoption plane by months.</p><p class="paragraph" style="text-align:left;">Igor frames the dynamic from the other side — what&#39;s happening inside the user&#39;s head when they make the choice to bypass a sanctioned tool:</p><p class="paragraph" style="text-align:left;"><i>&quot;People just create a personal workspace, and they just enable that feature. Everything feels solvable, just, like, one toggle away.&quot;</i> — <b>Igor Andriushchenko</b></p><p class="paragraph" style="text-align:left;">When the friction between &quot;thing I want to do&quot; and &quot;thing I can do&quot; collapses, the security implication is no longer a calculation most users perform. The ergonomic gap between sanctioned and unsanctioned has to close, or the workforce will close it for the program.</p><h4 class="heading" style="text-align:left;" id="4-what-actually-gets-automated-and-"><b>4. What actually gets automated — and what stays human</b></h4><p class="paragraph" style="text-align:left;">Both speakers are practical about where the line sits today. Jasper described what ethira automates and what it explicitly does not:</p><p class="paragraph" style="text-align:left;"><i>&quot;We can do all of that autonomously. Where we actually pull the humans in is at the end. So we basically aggregate everything that we cannot get, or we&#39;ll give an analysis based on your risk tolerance — this is sort of what we would recommend, and these are the mitigating factors if you want to onboard or not.&quot;</i> — <b>Jasper Mills</b></p><p class="paragraph" style="text-align:left;">The automation absorbs data gathering, financial and news checks, GitHub-based open-source maintenance signal, pen test request workflows, and the back-and-forth that historically dominated TPRM analyst time. Human judgment stays at the point of risk acceptance, where it belongs.</p><p class="paragraph" style="text-align:left;">Igor reinforces the same pattern from the consumer side and recommends an underrated starting point that does not require new procurement:</p><p class="paragraph" style="text-align:left;"><i>&quot;I&#39;m very excited about AI doing inventory of everything that&#39;s going on in the company, &#39;cause we already have some solutions. They just look into telemetry from the device. Let&#39;s say they take CrowdStrike telemetry, they take any other agent kind of running on your computer telemetry, and then they analyze it, and it was like, &#39;Oh, I found these 75 vendors here.&#39;&quot;</i> — <b>Igor Andriushchenko</b></p><p class="paragraph" style="text-align:left;"><b>Practitioner takeaway:</b> AI-driven inventory is the highest-leverage place to start. Most enterprises already have the telemetry sitting in their EDR. What they don&#39;t have is a vendor list reconciled against it. Running AI over existing endpoint telemetry to produce a continuous vendor inventory closes a gap the spreadsheet has never been able to close.</p><h4 class="heading" style="text-align:left;" id="5-build-vs-buy-for-the-tprm-stack-b"><b>5. Build vs. buy for the TPRM stack — both speakers come down on &quot;buy&quot;</b></h4><p class="paragraph" style="text-align:left;">This is one of the rare sections where two AI-native operators arrive at the same conclusion from different angles. Igor&#39;s reasoning is operational, not philosophical:</p><p class="paragraph" style="text-align:left;"><i>&quot;Imagine you have to build your third party risk management from scratch... how many people are working on that really? Like, is there one engineer who&#39;s vibe coding it? Good. But then what happens next? It needs to be maintained. Somebody needs to take a look at logs, at alerts, at telemetry... and you end up with somebody whose full-time job is just maintaining that app.&quot;</i> — <b>Igor Andriushchenko</b></p><p class="paragraph" style="text-align:left;">He extends the point to audit posture: if it was your own fault, you decided to take that risk and build it yourself, then it could be a more serious issue.</p><p class="paragraph" style="text-align:left;">Jasper makes the same point from the vendor side — the unique data sources and hallucination-mitigation work that a serious TPRM product invests in are not realistic to replicate as a side project. For cloud security leaders evaluating whether to build internal TPRM tooling on top of foundation-model APIs, the maintenance tail and the audit-defensibility tail are typically larger than the build cost, and neither shows up in the initial estimate.</p><h4 class="heading" style="text-align:left;" id="6-where-this-ends-up-agenttoagent-p"><b>6. Where this ends up: agent-to-agent procurement, contractual accountability as guardrails</b></h4><p class="paragraph" style="text-align:left;">Both speakers point at the same destination. Igor names the year:</p><p class="paragraph" style="text-align:left;"><i>&quot;I&#39;ve heard it many times, 2027 is the year of agent to agent. We are looking at third party management agent, risk management agents talking to company agents, like vendor agents that are just there listening for anyone coming in, asking about pen test results or NDA or something like that... It may sound bad, but there is no place for humans in that loop.&quot;</i> — <b>Igor Andriushchenko</b></p><p class="paragraph" style="text-align:left;">Jasper draws the architectural line back to the regulatory anchor that the whole conversation circles:</p><p class="paragraph" style="text-align:left;"><i>&quot;DORA, one of the key sort of foundations is contractual accountability. And one of the things that we&#39;ve thought about is if you think about people, if you think about agents, if you think about vendors, historically what you&#39;ve been able to do, if you look at when something goes wrong, you go back to the contract, you call a person up. But actually what you&#39;re able to do with vendors, with third-party agents, even with first-party agents, you can then actually take the contract that you have and create guardrails.&quot;</i> — <b>Jasper Mills</b></p><p class="paragraph" style="text-align:left;">The contract becomes the guardrail. The guardrail becomes the policy the agent operates under. The audit trail becomes the proof that the policy was followed. That sequence — contract → guardrail → enforceable policy on agent behavior — is the most actionable architectural insight in the episode for senior cloud security leaders thinking about how their TPRM program survives 2027.</p><h4 class="heading" style="text-align:left;" id="7-the-it-becomes-hr-frame-managing-"><b>7. The &quot;IT becomes HR&quot; frame — managing agents like contracted workforce</b></h4><p class="paragraph" style="text-align:left;">Jasper&#39;s closing prediction is the one to sit with:</p><p class="paragraph" style="text-align:left;"><i>&quot;IT will end up being like HR, in the fact that it will be like your contracted workforce. So you&#39;ll have a lot of contracted agents, you&#39;ll have a life cycle, you&#39;ll have a cost within that. They have their own credentials. But I think you&#39;ll manage it very similarly to third party risk, and the vendors will eventually have their own agents that are working in your systems.&quot;</i> — <b>Jasper Mills</b></p><p class="paragraph" style="text-align:left;">Igor extends the metaphor into something more uncomfortable — and useful for designing controls:</p><p class="paragraph" style="text-align:left;"><i>&quot;What defines a person is the agency. We have free will. We decide what to do next. The agents have that too. Not to the same extent, of course. There is a program where there is intention we give them, but still, sometimes they do things we do not expect.&quot;</i> — <b>Igor Andriushchenko</b></p><p class="paragraph" style="text-align:left;"><i>&quot;The moment we start thinking, &#39;Hey, this thing will behave deterministically,&#39; we&#39;ve failed as security people.&quot;</i> — <b>Igor Andriushchenko</b></p><p class="paragraph" style="text-align:left;">The practical implication: the controls that work for non-deterministic actors (humans, contractors, agents) are different from the controls that work for deterministic systems. Audit logging at every action, source-and-destination metadata, scoped credentials, lifecycle management with onboarding and offboarding, and behavioral monitoring against a baseline — these are HR-adjacent controls. They are not the controls most TPRM programs are set up to run.</p><h4 class="heading" style="text-align:left;" id="practical-takeaways-for-cloud-secur"><b>Practical takeaways for cloud security leaders</b></h4><p class="paragraph" style="text-align:left;">A few things senior cloud security leaders can act on in the next 30–60 days:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Start inventory with the telemetry you already have.</b> Run AI over existing EDR telemetry to build a continuous vendor and application inventory before paying for a new tool. Most enterprises have the data — they just don&#39;t have the reconciled list.</p></li><li><p class="paragraph" style="text-align:left;"><b>Add a &quot;second-party&quot; track to TPRM.</b> Internal apps built with AI and connected to internal data sources (especially via MCP) need a risk-tiering process equivalent to the one used for external vendors. Procurement isn&#39;t going to catch these.</p></li><li><p class="paragraph" style="text-align:left;"><b>Treat MCP servers as privileged integrations.</b> Every MCP connection from an internal app to a SaaS data source (Salesforce, Git, internal APIs, CRM) is a privileged integration. Inventory, scope, and audit them with the same rigor applied to service accounts.</p></li><li><p class="paragraph" style="text-align:left;"><b>Pick the autonomy level deliberately.</b> Match the toggle to the risk class. Agent-to-vendor questionnaire negotiation is reversible and low-blast-radius; agent-driven risk acceptance is not.</p></li><li><p class="paragraph" style="text-align:left;"><b>Map contractual accountability to agent policy now.</b> Whether the organization is regulated under DORA or not, the contract → guardrail → policy sequence is the architectural pattern that survives the agent-to-agent transition. The teams that have written this out before 2027 will not have to retrofit it under regulatory pressure.</p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="mental-model-the-vendor-list-was-th">🧠<b> </b>Mental Model — The Vendor List Was the Inventory. The Inventory Is Now the Vendor List.</h2><p class="paragraph" style="text-align:left;">For 20 years, TPRM ran on a procurement-driven vendor list. Procurement onboarded a supplier, security reviewed it, the supplier went on the list, the list got audited. The list <i>was</i> the inventory.</p><p class="paragraph" style="text-align:left;">That sequence is now backwards. The inventory — what your EDR sees running, what your network sees connecting, what your developers have wired up — is the source of truth. The vendor list is a downstream projection of it, and an increasingly incomplete one. Procurement no longer sees a meaningful share of the third parties operating inside the perimeter, because employees are creating them with AI faster than procurement can intake them.</p><p class="paragraph" style="text-align:left;">The program that survives 2027 starts from inventory and projects out to a vendor list. Not the other way around.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>📚 RELATED RESOURCES 🎧</b></h2><ul><li><p class="paragraph" style="text-align:left;"><b>ethira</b> — Jasper&#39;s company; product focus on automated TPRM and agent governance</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://lovable.dev?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Lovable</a></b> — Igor&#39;s company; AI-native app builder</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">EU Digital Operational Resilience Act (DORA)</a></b> — Official text and guidance for financial-sector ICT third-party accountability</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://modelcontextprotocol.io/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow"><b>Anthropic Model Context Protocol (MCP)</b></a> — Protocol documentation and best-practice guidance for securing AI agent connectors</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">CISA Known Exploited Vulnerabilities (KEV) Catalog</a></b> — For Drupal, Microsoft Defender, and SharePoint vulnerability tracking referenced this week</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Fox-IT — RemotePE technical research</a></b> — Lazarus toolset analysis and detection guidance</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Check Point Research — Nimbus Manticore</a></b> — IRGC-affiliated APT activity, AppDomain hijacking, and AI-assisted malware fingerprints</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">OWASP Top 10 for Agentic Applications</a></b> — For organizations extending AppSec frameworks into AI-assisted development</p></li></ul><h3 class="heading" style="text-align:left;" id="podcast-episode"><b>Podcast Episode</b></h3><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/how-ai-agents-will-negotiate-your-vendor-contracts?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow"><b>Full Episode with Igor Andriushchenko and Jasper Mills</b></a> — Complete transcript and audio for this week&#39;s featured conversation</p></li></ul><hr class="content_break"><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔 Is your TPRM program seeing the apps your own employees built with AI this quarter or just the vendors procurement onboarded?<br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=every-employee-vibe-coding-an-app-is-now-a-vendor-igor-and-jasper-on-rebuilding-tprm-for-it" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=bf9f5da9-967d-45f3-8b8c-bc0f708b1d14&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🚨 GitHub Breach Caps TeamPCP&#39;s 5-Compromise Run - Sergej Epp on Why Defense Has No Verifiers</title>
  <description>GitHub confirmed 3,800 internal repos exfiltrated this week via a poisoned VS Code extension - TeamPCP&#39;s fifth 2026 supply chain compromise. Verizon&#39;s DBIR formalized what every operator already feels: vulnerability exploitation has overtaken credential theft as the #1 breach vector for the first time in 19 years. Sysdig CISO Sergej Epp explains his Cybersecurity Verification Law and why offence has a structural superpower that no amount of defensive AI investment alone can close.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/07447324-4553-41e9-a6e1-533056ff3b3d/Screenshot_2026-05-20_at_9.33.36_PM.png" length="1956419" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/github-3800-repos-breach-teampcp-verification-law</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/github-3800-repos-breach-teampcp-verification-law</guid>
  <pubDate>Wed, 20 May 2026 20:52:22 +0000</pubDate>
  <atom:published>2026-05-20T20:52:22Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">This week&#39;s Cloud Security Newsletter topic: <b>The Cybersecurity Verification Law — Why Offence Has a Superpower and What Defence Can Do About It</b><b> </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" rel="noopener noreferrer nofollow">(continue reading)</a> </p><hr class="content_break"><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://links.cloudsecuritypodcast.tv/see-how-ent-works?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers"><span class="button__text" style=""> This issue is sponsored by Ent Security </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/07447324-4553-41e9-a6e1-533056ff3b3d/Screenshot_2026-05-20_at_9.33.36_PM.png?t=1779309251"/></a><div class="image__source"><span class="image__source_text"><p><i>This image was generated by AI. It&#39;s still experimental, so it might not be a perfect match!</i></p></span></div></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;">This week&#39;s news has one through-line: trust is breaking down in the developer tooling layer. TeamPCP reached 3,800 GitHub internal repositories through a single poisoned VS Code extension on one employee&#39;s laptop. The Mini Shai-Hulud worm compromised TanStack&#39;s legitimate release pipeline and dragged OpenAI, Mistral, UiPath, and Guardrails AI into the blast radius. Grafana&#39;s GitHub token was lifted and its codebase extorted. Microsoft Exchange OWA has been under active exploitation for six days with no patch. And Verizon&#39;s 2026 DBIR confirmed it at industry scale: vulnerability exploitation has overtaken stolen credentials as the #1 initial access vector for the first time in 19 years.</p><p class="paragraph" style="text-align:left;">This week&#39;s conversation is with <b>Sergej Epp</b>, CISO at <b>Sysdig</b> and former CISO at Deutsche Bank and Palo Alto Networks, hosted by <b>Ashish Rajan</b>. Sergej&#39;s framing pulls the news together: offense has cheap binary verifiers — pop a shell, capture the flag, exfiltrate the secret. Defense doesn&#39;t. Until that gap closes, the speed asymmetry only widens.<i>[</i><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/the-zero-day-clock-how-ai-shrank-exploit-times-from-months-to-hours?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">⚡ TL;DR for Busy Readers</h2><div class="codeblock"><pre><code>- GitHub confirmed ~3,800 internal repos stolen via poisoned VS Code extension. TeamPCP&#39;s 5th 2026 supply chain hit. Audit dev extensions now.

- Exchange OWA zero-day (CVE-2026-42897) active 6+ days, no patch. EEMS mitigation doesn&#39;t cover IE-mode users. Run ExchangeHealthChecker.

- Verizon DBIR 2026: vuln exploitation overtakes credential theft for first time in 19 years. 22,000 confirmed breaches, 60% YoY rise in third-party involvement.

- Mini Shai-Hulud worm hit 170+ packages May 11 — caught two OpenAI 
  employee devices. First malicious npm package with valid SLSA provenance.

- Sergej Epp&#39;s argument: offense has cheap binary verifiers (shell popped or not), defense doesn&#39;t. The program that wins takes humans out of the response loop before attackers do.</code></pre></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="this-weeks-security-news">📰 <b>THIS WEEK&#39;S TOP SECURITY HEADLINES</b></h2><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-git-hub-confirms-3800-internal-re"><b> 1. </b><b>GitHub Confirms ~3,800 Internal Repositories Stolen via Poisoned VS Code Extension</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://twitter.com/github?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">GitHub statement on X (May 20)</a> <br><b>Reporting:</b> <a class="link" href="https://www.securityweek.com/github-confirms-hack-impacting-3800-internal-repositories/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek</a> · <a class="link" href="https://www.bleepingcomputer.com/news/security/github-confirms-breach-of-3-800-repos-via-malicious-vscode-extension/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer</a> <br><b>Analysis:</b> <a class="link" href="https://www.helpnetsecurity.com/2026/05/20/github-breached-teampcp/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">Help Net Security</a> · <a class="link" href="https://www.infosecurity-magazine.com/news/github-confirms-breach-vs-code/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">Infosecurity Magazine</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> GitHub confirmed on May 20 that approximately 3,800 internal repositories were exfiltrated after a single employee installed a malicious Visual Studio Code extension. &quot;Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker&#39;s current claims of ~3,800 repositories are directionally consistent with our investigation so far,&quot; GitHub stated. The TeamPCP group claimed responsibility on the Breached cybercrime forum, listing the data for $50,000 with a threat to leak it free if no buyer surfaces. GitHub has stated there is no evidence of customer repository impact, but the investigation is ongoing. This is TeamPCP&#39;s fifth major supply chain compromise of 2026. The group has previously compromised Aqua&#39;s Trivy security scanner, CheckMarx&#39;s KICS, the LiteLLM library, the Telnyx SDK, TanStack, MistralAI, and other packages that depended on those.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> A single VS Code extension on one employee&#39;s machine reached 3,800 internal GitHub repositories. &quot;<i>Developer workstations are the number one target in supply chain attacks right now, and this is exactly why</i>,&quot; Aikido Security&#39;s Mackenzie Jackson said. &quot;<i>Most security teams still have zero visibility into what extensions or packages are on their developers&#39; machines, or how recently they were published.</i>&quot; For cloud security architects, this collapses three trust boundaries at once: the IDE marketplace as a software distribution channel, the developer workstation as a privileged access endpoint, and the source-code repository as a sensitive data store. GitHub is the platform 90% of the Fortune 100 builds on; the breach hit its own internal code, meaning downstream organizations now face a 6–12 month window where attackers may probe leaked source for novel exploits.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders:</b> Build a real inventory of IDE extensions across your engineering org — VS Code, JetBrains, Cursor, Windsurf. Restrict installation to an allowlist of verified publishers. Treat developer workstations as Tier-0 assets with EDR coverage matching domain controllers. Move CI/CD authentication to short-lived OIDC tokens. Rotate any GitHub PATs, npm tokens, or cloud credentials a developer may have touched in the past 30 days.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-microsoft-exchange-owa-zero-day-c"><b>2. </b><b>Microsoft Exchange OWA Zero-Day (CVE-2026-42897) Under Active Exploitation - No Patch Six Days In</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://msrc.microsoft.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">Microsoft Security Response Center advisory</a> <br><b>Reporting:</b> <a class="link" href="https://www.securityweek.com/microsoft-warns-of-exchange-server-zero-day-exploited-in-the-wild/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek</a> · <a class="link" href="https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-exchange-zero-day-flaw-exploited-in-attacks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer</a> <br><b>Analysis:</b> <a class="link" href="https://www.darkreading.com/vulnerabilities-threats/microsoft-exchange-zero-day-no-patch?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">Dark Reading</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> Microsoft confirmed on May 14 that CVE-2026-42897 — a cross-site scripting flaw in the Outlook Web Access component of Exchange Server 2016, 2019, and Subscription Edition — is under active exploitation in the wild. An attacker needs only to send a crafted email; if the recipient opens it in OWA, arbitrary JavaScript executes inside their authenticated browser session, enabling session token theft, mailbox impersonation, and email rule manipulation without the attacker ever touching the server itself. No permanent patch exists.</p><p class="paragraph" style="text-align:left;">CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on May 15, giving Federal Civilian Executive Branch agencies until May 29 to apply mitigations. A May 18 update added that the mitigation does not protect users accessing OWA through Internet Explorer or Microsoft Edge in Internet Explorer compatibility mode. Exchange Online is not affected.</p><p class="paragraph" style="text-align:left;"><b>Why it matters: </b>Six days into active exploitation with no permanent patch, mitigations that disable features, and an explicit carveout for IE-compatibility-mode users. On-prem Exchange remains one of the most consistently exploited entry points to enterprise environments, and an XSS-class flaw in OWA can convert directly to session-token theft and mailbox impersonation — and from there, into lateral movement into cloud identity systems via Entra Connect.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders:</b> Verify EEMS is enabled and mitigation M2.1.x has been applied automatically. Run aka.ms/ExchangeHealthChecker. For air-gapped environments, manually apply EOMT. Identify any user populations still using IE or Edge IE-mode for OWA and force them off until a patch ships. Treat any anomalous mailbox rule creation in your OWA logs from May 14 onward as a high-priority IR signal.</p><hr class="content_break"><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><b>🛠 If you only do one thing this week:</b> Audit IDE extensions across your engineering org and rotate every GitHub PAT and cloud credential a developer has touched in the last 30 days. The same payload pattern that hit GitHub itself is the one that caught TanStack, Mistral, and two OpenAI employee devices nine days earlier.</p><figcaption class="blockquote__byline"></figcaption></blockquote></div><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-verizon-2026-dbir-vulnerability-e"><b>3. </b><b>Verizon 2026 DBIR: Vulnerability Exploitation Overtakes Credential Theft for the First Time in 19 Years</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://www.verizon.com/about/news/breach-industry-wide-dbir-finds?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">Verizon DBIR 2026 announcement</a> <br><b>Reporting:</b> <a class="link" href="https://www.securityweek.com/verizon-dbir-2026-vulnerability-exploitation-overtakes-credential-theft-as-top-breach-vector/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek</a> · <a class="link" href="https://www.darkreading.com/threat-intelligence/verizon-dbir-enterprises-vulnerability-glut?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">Dark Reading</a> <br><b>Analysis:</b> <a class="link" href="https://blog.qualys.com/vulnerabilities-threat-research/2026/05/19/inside-the-2026-verizon-dbir-what-one-billion-records-revealed-about-vulnerability-remediation?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">Qualys research partner breakdown</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> Verizon published its 19th annual Data Breach Investigations Report on May 19. More than 22,000 confirmed breaches, nearly double last year&#39;s 12,195. For the first time in DBIR history, software flaws (31%) surpassed stolen credentials as the leading initial access vector — and AI accelerating attacks from months to hours is the proximate cause.</p><p class="paragraph" style="text-align:left;">Other findings: ransomware in 48% of confirmed breaches (up from 44%); median ransom payment dropped below $140,000; only 31% of victims paid. Third-party-involved breaches up 60% YoY to 48% of total. On AI: 67% of users access AI services from corporate devices using non-corporate accounts; 45% of employees are now regular AI users, up from 15% last year.</p><p class="paragraph" style="text-align:left;">The patching crisis is the report&#39;s structural finding: only 26% of critical KEV vulnerabilities were fully remediated in 2025, down from 38% the previous year. Median resolution time increased by two weeks (43 days, up from 32), and organizations had 50% more critical bugs to patch than last year.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> This is the year&#39;s anchoring industry baseline. Qualys, a DBIR research partner, frames it directly: this dataset may be an initial measurement of a &quot;speed of light&quot; for vulnerability remediation processes — a theoretical limit on what any model bound by human triage, change-windows, and approval gates can deliver. Sergej Epp&#39;s Zero Day Clock data lines up: in 2020 the disclosure-to-exploitation window was over 18 months; today it sits between 8 hours and 3 days.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders:</b> Re-anchor your vulnerability program on exposure window, not patch SLA. Pull your KEV remediation curve for the last 12 months and compare against the DBIR survival analysis. Prioritize by active exploitation, not CVSS. Treat shadow AI (67% bypassing corporate accounts) as a DLP problem today, not a future one.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-mini-shai-hulud-supply-chain-worm"><b>4. </b><b>Mini Shai-Hulud Supply Chain Worm Catches OpenAI, Mistral, UiPath, Guardrails — TeamPCP&#39;s Fourth Wave</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://openai.com/index/our-response-to-the-tanstack-npm-supply-chain-attack/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">OpenAI disclosure</a> · <a class="link" href="https://tanstack.com/blog/npm-supply-chain-compromise-postmortem?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">TanStack postmortem</a> <br><b>Reporting:</b> <a class="link" href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">Wiz analysis</a> · <a class="link" href="https://snyk.io/blog/tanstack-npm-packages-compromised/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">Snyk</a> <br><b>Analysis:</b> <a class="link" href="https://thehackernews.com/2026/05/tanstack-supply-chain-attack-hits-two.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> On May 11, TeamPCP executed the fourth wave of the Shai-Hulud npm worm. The attacker published 84 malicious versions across 42 @tanstack/* packages between 19:20 and 19:26 UTC, chaining the pull_request_target &quot;Pwn Request&quot; pattern, GitHub Actions cache poisoning, and runtime extraction of an OpenID Connect (OIDC) token from runner process memory. The coordinated attack compromised over 170 npm packages and 2 PyPI packages, totaling 404 malicious versions — including Mistral AI&#39;s SDK suite, UiPath&#39;s automation tooling, OpenSearch, and Guardrails AI.</p><p class="paragraph" style="text-align:left;">On May 15, OpenAI disclosed it had been caught: &quot;Two employee devices in our corporate environment were impacted by this attack ... unauthorized access and credential-focused exfiltration activity, in a limited subset of internal source code repositories to which the two impacted employees had access.&quot;</p><p class="paragraph" style="text-align:left;">The payload is built for cloud CI/CD. It steals GitHub tokens, npm tokens, AWS credentials (via IMDSv2), GCP and Azure credentials, Kubernetes service account tokens, HashiCorp Vault tokens, and environment variables — then identifies packages the victim has publish access to and propagates. It is also the first documented case of a malicious npm package carrying valid SLSA provenance.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> SLSA provenance was a control model many cloud security programs were planning to lean on. TeamPCP just broke it. And as story #1 makes clear, this campaign was a dry run — the same playbook produced the GitHub internal repo breach nine days later.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders:</b> Treat any developer machine or CI runner that installed an affected package version on May 11 as compromised. Rotate every credential reachable from that host. Search for the gh-token-monitor daemon at <code>~/Library/LaunchAgents/com.user.gh-token-monitor.plist</code> (macOS) or <code>~/.config/systemd/user/gh-token-monitor.service</code> (Linux) and remove <i>before</i> revoking tokens, to avoid the wiper. Pin all GitHub Actions to full commit SHAs. Block git-tanstack[.]com and *.getsession.org at egress.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-grafana-confirms-git-hub-codebase"><b>5. </b><b>Grafana Confirms GitHub Codebase Theft After Coinbase Cartel Extortion Attempt</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://grafana.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">Grafana Labs statement</a> <br><b>Reporting:</b> <a class="link" href="https://www.cybersecuritydive.com/news/grafana-labs-says-hacker-gained-access-to-codebase-through-leaked-token/820485/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">Cybersecurity Dive</a> · <a class="link" href="https://therecord.media/grafana-refuses-to-pay-ransom-codebase-theft?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">The Record</a> <br><b>Analysis:</b> <a class="link" href="https://thehackernews.com/2026/05/grafana-github-token-breach-led-to.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a> · <a class="link" href="https://www.securityweek.com/grafana-confirms-breach-after-hackers-claim-they-stole-data/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> On May 17, Grafana Labs publicly confirmed an unauthorized party used a compromised token to access its GitHub environment and download the company&#39;s codebase. The Coinbase Cartel extortion group listed Grafana on its leak site on May 15. Grafana refused to pay.</p><p class="paragraph" style="text-align:left;">Grafana operates an open-source observability platform with more than 25 million users and 7,000 customers globally — including Nvidia, Microsoft, and Anthropic. No customer data or personal information was accessed during the attack. </p><p class="paragraph" style="text-align:left;">CoinbaseCartel emerged in September 2025, assessed to be an offshoot of the ShinyHunters, Scattered Spider, and LAPSUS$ ecosystems. The group focuses purely on data theft and extortion, and has amassed 170 victims across healthcare, technology, transportation, manufacturing, and business services.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> Three days before GitHub itself was breached through a different vector, Grafana lost its codebase through a stolen GitHub token. The trust model around source-code repositories is breaking down on multiple axes at once. Stolen source code remains risky because private repositories may contain internal logic, secrets, build processes, or unreleased features attackers can analyze for novel exploits.</p><p class="paragraph" style="text-align:left;"><b>Action for defenders:</b> Inventory every PAT, app installation token, and OAuth grant against your GitHub org. Set token TTLs as low as your CI/CD architecture tolerates. Apply phishing-resistant MFA across all maintainer accounts.</p><hr class="content_break"><h4 class="heading" style="text-align:left;" id="6-git-hub-action-tag-hijack-actions"><b>6. GitHub Action Tag Hijack: actions-cool/issues-helper Compromised via Imposter Commits</b></h4><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://www.stepsecurity.io/blog/actions-cool-issues-helper-github-action-compromised-all-tags-point-to-imposter-commit-that-exfiltrates-ci-cd-credentials?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">StepSecurity disclosure</a> <br><b>Reporting:</b> <a class="link" href="https://thehackernews.com/2026/05/github-actions-supply-chain-attack.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a> · <a class="link" href="https://www.scworld.com/brief/github-actions-workflow-compromised-to-steal-ci-cd-credentials?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">SC Media</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> On May 18, StepSecurity disclosed that the widely used GitHub Action <code>actions-cool/issues-helper</code> had been compromised through a tag-redirection attack. &quot;Every existing tag in the repository has been moved to point to an imposter commit that does not appear in the action&#39;s normal commit history,&quot; StepSecurity researcher Varun Sharma said. &quot;That commit contains malicious code that exfiltrates credentials from CI/CD pipelines that run the action.&quot; A second action, <code>actions-cool/maintain-one-comment</code>, was hit the same way. The exfiltration domain has previously been observed in the Mini Shai-Hulud campaign, suggesting a potential link between the two activities. </p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> The tag-redirection technique exploits the fact that most workflows pin to floating version tags (<code>@v3</code>) rather than full commit SHAs. Any workflow that references the action by version pulls the malicious code on its next run. Only workflows pinned to a known-good full commit SHA are unaffected. </p><p class="paragraph" style="text-align:left;"><b>Action for defenders:</b> Audit every workflow for references to the compromised actions. Treat any CI run executing either as a credential exposure event. Implement an org-wide policy requiring SHA pinning for third-party GitHub Actions.</p><hr class="content_break"><h4 class="heading" style="text-align:left;" id="7-nyc-health-hospitals-18-million-p"><b>7. NYC Health + Hospitals: 1.8 Million Patients, Including Fingerprints and Palm Prints, Stolen via Third-Party Vendor</b></h4><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://www.nychealthandhospitals.org/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">NYC Health + Hospitals breach notice</a> <br><b>Reporting:</b> <a class="link" href="https://techcrunch.com/2026/05/18/nyc-health-and-hospitals-says-hackers-stole-medical-data-and-fingerprints-during-breach-affecting-at-least-1-8-million-people/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">TechCrunch</a> · <a class="link" href="https://www.techradar.com/pro/security/nyc-health-hospitals-says-mega-data-breach-allowed-hackers-to-steal-personal-data-medical-records-and-fingerprints-scans-of-around-1-8-million-people?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">TechRadar</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> On May 18, NYC Health + Hospitals disclosed a months-long breach exposing data on at least 1.8 million people. NYCHHC detected the attack on February 2 and secured its network; the hackers had been inside since approximately November 25, 2025 — more than two months of access before detection. </p><p class="paragraph" style="text-align:left;">The breach is particularly sensitive because hackers stole biometric information, including fingerprints and palm prints, which affected individuals have for life and cannot replace. NYCHHC tied the intrusion to an unnamed third-party vendor. </p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> Another data point in the DBIR&#39;s 60% YoY rise in third-party breach involvement — but with biometric data, where the consequences are permanent. A stolen Social Security number can be replaced. A compromised password can be changed. A fingerprint cannot. </p><p class="paragraph" style="text-align:left;"><b>Action for defenders:</b> Audit which third-party vendors store biometric data on your behalf and what the recovery path looks like when one is breached. Force a real conversation with any vendor whose contract permits indefinite biometric retention.</p><hr class="content_break"><h4 class="heading" style="text-align:left;" id="8-anthropic-to-brief-financial-stab">🤖 8. Anthropic to Brief Financial Stability Board on Mythos Vulnerabilities — Bank of England Asked</h4><p class="paragraph" style="text-align:left;"><b>Primary source:</b> Financial Times reporting (May 18) <br><b>Reporting:</b> <a class="link" href="https://www.pymnts.com/cybersecurity/2026/anthropic-will-update-regulators-mythos-cyber-vulnerability-findings/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">PYMNTS</a> · <a class="link" href="https://www.techradar.com/pro/security/anthropic-to-present-exposed-mythos-flaws-to-global-watchdog-claims-critical-vulnerabilities-found-in-every-major-operating-system-and-web-browser?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">TechRadar</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> Anthropic agreed to meet with members of the Financial Stability Board (FSB) to discuss its Mythos model. The meeting was requested by Bank of England Governor Andrew Bailey, who is also an FSB member. Many FSB members have grown concerned that Mythos and AI models from other US tech companies could expose weaknesses in banks&#39; cyber defenses. Anthropic said last month that Mythos had &quot;found thousands of high-severity vulnerabilities, including some in every major operating system and web browser,&quot; with potential fallout for &quot;economies, public safety and national security.&quot; </p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> First time a sovereign-level financial stability regulator has formally engaged with an AI lab on the systemic risk of AI-assisted vulnerability discovery. For CISOs at financial institutions across the FSB&#39;s footprint, expect questions in your next exam about exposure window measurement and how your program scales if AI-discovered vulnerabilities arrive at 2–5× current volume in 2026–27.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="the-cybersecurity-verification-law-"><b>The Cybersecurity Verification Law — Why Offense Has a Superpower and What Defense Can Do About It</b></h3><p class="paragraph" style="text-align:left;">If you read this week&#39;s news brief and felt the underlying mechanic was familiar, Sergej Epp has a name for it: the Cybersecurity Verification Law. The argument goes like this. In every domain where AI has surged — chess, Sudoku, mathematics, benchmark coding — what made the surge possible was cheap verification. You can tell instantly whether the move worked, whether the proof is valid, whether the test passed. AI compounds capability fastest where the feedback loop is binary and cheap.</p><p class="paragraph" style="text-align:left;">Map that principle onto cybersecurity and the picture is uncomfortable. Offense has cheap binary verifiers everywhere: you pop a shell or you don&#39;t, you capture the flag or you don&#39;t, you exfiltrate the secret or you don&#39;t. Defense has almost none. &quot;Is this binary 56% malicious?&quot; is not a verifier. &quot;How confident is the SIEM alert?&quot; is not a verifier. That asymmetry is structural — and it explains why offensive AI capability is sprinting ahead of defensive AI capability even when both sides have access to the same models.</p><p class="paragraph" style="text-align:left;">That&#39;s the framing thread for this week&#39;s conversation with Sergej, who&#39;s spent 15 years inside cyber defense at Deutsche Bank, Palo Alto Networks, and now as CISO at Sysdig. <i>[</i><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/the-zero-day-clock-how-ai-shrank-exploit-times-from-months-to-hours?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow"><i>Listen to the full episode →</i></a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;"><b>Featured Experts This Week </b>🎤</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/sergejepp/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow"><b>Sergej Epp</b></a> — CISO, Sysdig | Former CISO Deutsche Bank, Palo Alto Networks</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Cybersecurity Verification Law:</b> Sergej&#39;s framing for why offensive AI is outpacing defensive AI. Wherever a domain has cheap binary verifiers (exploit worked / it didn&#39;t), AI compounds capability fast. Offense has these natively; defense doesn&#39;t.</p></li><li><p class="paragraph" style="text-align:left;"><b>Zero Day Clock:</b> Sysdig&#39;s running measurement of the time between a CVE being disclosed and being exploited in the wild. In 2020 the window was over 18 months. As of this year it&#39;s between 8 hours and 3 days, depending on the cohort.</p></li><li><p class="paragraph" style="text-align:left;"><b>YOLO mode (Claude Code):</b> Auto-approve mode in which the agent runs end-to-end without per-action confirmation. Sergej uses this as the offensive analogue for what defense now needs to build — autonomous response loops where the human is not in the per-event approval path.</p></li><li><p class="paragraph" style="text-align:left;"><b>Objective verifiers vs. environmental verifiers:</b> Sergej&#39;s distinction. Offense owns objective verifiers (did the exploit fire?). Defense owns environmental verifiers (does this action match how my environment actually works — naming conventions, identity patterns, expected network flows?).</p></li><li><p class="paragraph" style="text-align:left;"><b>Honey tokens:</b> One of the few cleanly binary signals on the defense side — a decoy credential or object that, when touched, conclusively indicates malicious activity.</p></li><li><p class="paragraph" style="text-align:left;"><b>Runtime security:</b> Real-time detection and response inside production workloads, as opposed to point-in-time posture management or scanning. Sergej argues runtime telemetry is the ground truth that makes AI-driven defensive action reliable rather than hallucinated.</p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <a class="link" href="https://links.cloudsecuritypodcast.tv/see-how-ent-works?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow"><b>Ent Security</b></a></p><p class="paragraph" style="text-align:center;"><span style="background-color:rgb(255, 255, 255);">Most security tools are built to detect. They watch, log, and alert after the fact, when the damage is already done. Threats now move faster than humans can respond. Security has to move closer to where work actually happens.</span></p><p class="paragraph" style="text-align:left;"><span style="background-color:rgb(255, 255, 255);">Ent is an AI-native endpoint security platform built around one idea: understanding intent. Ent runs at the edge, sees what users see and do, and intervenes before damage is done. Adaptive by design, it continuously learns what normal looks like for every person and workflow in your organization, without data leaving your environment. Ent brings prevention at the speed of work.</span></p><p class="paragraph" style="text-align:center;">See how it works: <span style="background-color:rgb(255, 255, 255);"><a class="link" href="https://links.cloudsecuritypodcast.tv/see-how-ent-works?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(17, 85, 204)">schedule a 1:1 conversation</a></span><span style="background-color:rgb(255, 255, 255);"><span style="color:rgb(34, 34, 34);font-family:Arial, Helvetica, sans-serif;font-size:small;"><a class="link" href="https://links.cloudsecuritypodcast.tv/see-how-ent-works?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">.</a></span></span></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-the-cybersecurity-verification-la">1. The Cybersecurity Verification Law — Where Offense Got Its Superpower</h3><p class="paragraph" style="text-align:left;">Sergej&#39;s opening move in the conversation reframes the AI security debate. The interesting question isn&#39;t who has the better model. It&#39;s where each side gets a clean signal that the model worked. <i>&quot;In every domain where you can measure something and verification is easy... AI is becoming very good. So all the benchmarks we&#39;ve created so far across all the domains, AI was able just to reach 90, 95% of successes.&quot;</i> — Sergej Epp</p><p class="paragraph" style="text-align:left;">Apply that principle to security and the picture inverts. <i>&quot;It turns out offense is dominating. If you pop a shell, if you exploit, you get a very easy binary feedback. You get this feedback loop during the training, but also during the inference when AI agents are working — that yes, this happened really, now you&#39;ve got this. Capture the flag, you&#39;ve got this token, you&#39;ve got the flag, the exploit worked. And so offense has this very cheap verifiers.&quot;</i> — Sergej Epp</p><p class="paragraph" style="text-align:left;">Defense doesn&#39;t have that. The signals are probabilistic, the alerts are noisy, the confidence scores are themselves model outputs. Sergej&#39;s blunt summary:<i>&quot;In defense, we don&#39;t really have this deterministic, binary verifiers. And therefore that explains a lot we&#39;re seeing right now — that offense is pretty much getting the superpower and accelerating much more compared to defense.&quot;</i> — Sergej Epp</p><p class="paragraph" style="text-align:left;"><b>What to do with this:</b> This is the lens that makes the rest of the conversation coherent. If your defensive program is being asked to &quot;use AI&quot; without first asking where your verifiers are, the AI investment compounds into the same noise floor you already had — just faster. The architectural work is making defense more like chess: identifying the places where you can produce binary signal, and building scaffolding everywhere you can&#39;t.</p><h4 class="heading" style="text-align:left;" id="2-the-zero-day-clock-from-18-months">2. The Zero Day Clock — From 18 Months to 8 Hours</h4><p class="paragraph" style="text-align:left;">The Verification Law sounds abstract until Sergej puts a number on it. Sysdig publishes a running measurement called the Zero Day Clock that tracks the time from CVE disclosure to active exploitation. <i>&quot;It was more than one and a half years... And now we are like under a day. Under, under 24 hours. I think it&#39;s just varying between eight hours and one to three days... You can expect this is going to drop to minutes or hours.&quot;</i> — Sergej Epp</p><p class="paragraph" style="text-align:left;">The mechanism is mundane and powerful at the same time. <i>&quot;Effectively when a vendor ships a patch, it ships the blueprint of the vulnerability. And the AI is really good right now in reconstructing this blueprint and building the exploit out of this blueprint. So right now, as a bad nation state, you can just deploy a lab and then collect all these different patches and instantly create exploits.&quot;</i> — Sergej Epp</p><p class="paragraph" style="text-align:left;">The patch <i>is</i> the disclosure. The diff is the spec. AI-assisted analysis turns N-day vulnerabilities into working exploits inside the time most enterprises take to schedule a change advisory board meeting. That maps directly onto Verizon&#39;s DBIR finding this week: only 26% of critical vulnerabilities were fully remediated by organizations in 2025, compared to 38% the previous year. The defenders aren&#39;t getting worse. The window is. </p><p class="paragraph" style="text-align:left;"><b>Cloud security takeaway:</b> If your patch SLA is 30/60/90 and your change-management window is two weeks, you&#39;re now permanently out of band with the threat.</p><h4 class="heading" style="text-align:left;" id="3-the-8-minute-aws-compromise-why-s">3. The 8-Minute AWS Compromise — Why Speed of Attack Forces Speed of Defense</h4><p class="paragraph" style="text-align:left;">The Verification Law explains the trajectory. Sergej then drops the operational example that grounds it. <i>&quot;We just saw recently — we detected one AWS environment being compromised. The attacker moved from zero — he just got some stolen credentials — to full admin in eight minutes.&quot;</i> — Sergej Epp</p><p class="paragraph" style="text-align:left;">The attacker was using AI, and Sergej&#39;s team could tell because of the artifacts the AI left behind: <i>&quot;He was assuming roles which were called &#39;Claude&#39;. Whenever the AI was stuck — for instance trying to spin up some GPU to mine cryptocurrency — when it was stuck, it was just trying to call an Anthropic GitHub repo which didn&#39;t exist.&quot;</i> — Sergej Epp</p><p class="paragraph" style="text-align:left;">Eight minutes from stolen credential to full admin. Sergej&#39;s framing of what this requires: <i>&quot;How is a SOC analyst supposed to cope with an attack which is taking under 10 minutes? We have to take the human out of the loop.&quot;</i> — Sergej Epp</p><p class="paragraph" style="text-align:left;">The link back to story #3 in the news brief: the DBIR doesn&#39;t just say patching is slow. It says the speed-of-defense ceiling is hitting a wall that human triage and approval cycles can&#39;t break through.</p><h4 class="heading" style="text-align:left;" id="4-what-defenders-actually-have-hone">4. What Defenders Actually Have — Honey Tokens and the First-Principle Advantage</h4><p class="paragraph" style="text-align:left;">If the Verification Law makes defense sound hopeless, Sergej&#39;s deeper point is that it isn&#39;t — defense just has different verifiers than offense, and most programs aren&#39;t using them.</p><p class="paragraph" style="text-align:left;">The cleanest binary signal on the defense side: <i>&quot;Honey tokens. If you look at any EDR, XDR solution — all of them are throwing around honey tokens to detect ransomware. Because it&#39;s the only unique binary signal that something is happening. Somebody&#39;s eliminating these honey tokens. Same in the cloud.&quot;</i> — Sergej Epp</p><p class="paragraph" style="text-align:left;">The first-principle advantage: <i>&quot;The attackers do not understand the environment. So every time they&#39;re just going to go in and reach the objective... they&#39;re going to start to perform steps from scratch based on the training data. So they will try to assume certain roles with certain usernames, based on trying to hallucinate down something. And that&#39;s going to create a lot of noise. You can hear this noise — you can start build your detection around that.&quot;</i> — Sergej Epp</p><p class="paragraph" style="text-align:left;">The 8-minute AWS incident is the proof point. The attacker&#39;s AI hallucinated <code>Claude</code>-named roles and reached for a non-existent Anthropic GitHub repo because it had no idea what the actual environment looked like. That noise is detectable — but only if the defender has done the work of mapping their environment first. <i>&quot;If you can explain how your environment is looking like — for instance, what kind of naming conventions you&#39;re using for your clusters, what kind of naming conventions you&#39;re using for your identities — starting to understand that, equipping your team with this understanding, building detection rules on top of that, is quite powerful. And that&#39;s by the way, something also vendors will not be able to help with. Because that&#39;s your unique experience, insights you have as a company.&quot;</i> — Sergej Epp</p><p class="paragraph" style="text-align:left;"><b>Cloud security takeaway:</b> Build the environment graph and the naming-convention catalog as a first-class artifact, not an afterthought. The detection signal that catches a TeamPCP-style intrusion is unlikely to be a CVE signature — it&#39;s a service account assuming a role with a name that doesn&#39;t exist in your taxonomy.</p><h4 class="heading" style="text-align:left;" id="5-runtime-security-as-the-ground-tr">5. Runtime Security as the Ground Truth</h4><p class="paragraph" style="text-align:left;">If detection has to happen inside the attack window, the data layer that supports it has to be real-time and high-fidelity. <i>&quot;If a hack is happening within eight minutes, your inventory posture management is not going to help. Whatever&#39;s just misconfigured, you&#39;ll not be able to go back, send this, open up a ticket in Jira and have the engineer just work on that.&quot;</i> — Sergej Epp</p><p class="paragraph" style="text-align:left;">Why runtime, not posture: <i>&quot;To have this ground truth — what&#39;s going on. Because if you just have parts of it — five or six events suggesting, oh, something happened in this Kubernetes container — but I don&#39;t really know what processes were running, I don&#39;t really know if container escapes were performed. If I don&#39;t have a lot of this telemetry, I&#39;m not going to be confident to say &#39;I&#39;m going to kill this container.&#39;&quot;</i> — Sergej Epp</p><p class="paragraph" style="text-align:left;">The architectural prescription: runtime telemetry produces ground truth, deterministic rules produce binary signal, and only then does AI come in to reason across the noise. This inverts how most &quot;AI for SOC&quot; pitches are structured — and it lines up with where the news brief landed: Mini Shai-Hulud, the actions-cool tag hijack, and the GitHub VS Code extension breach all depended on activity inside developer or CI/CD workloads that posture scanning can&#39;t see in real time.</p><h4 class="heading" style="text-align:left;" id="6-ai-agent-risk-simon-willisons-thr">6. AI Agent Risk — Simon Willison&#39;s Three Categories</h4><p class="paragraph" style="text-align:left;">When the conversation pivots to securing AI agents inside the enterprise, Sergej grounds it in a mental model from security researcher Simon Willison. Agents do three things; the safe configuration takes at least one off the table. <i>&quot;What kind of access to data is the AI agent having? Can the AI agent execute commands? Does the AI agent have access to the internet? Simon Willison posted about this recently — you have to take at least one of these out. Otherwise it&#39;s going to be a huge blast radius and could lead to a nightmare scenario.&quot;</i> — Sergej Epp</p><p class="paragraph" style="text-align:left;">Sergej is realistic about how hard this is in cloud: <i>&quot;Even if you take one of those aspects out, you can&#39;t really take out the network capability in the cloud. Let&#39;s say you&#39;re going to say it cannot run commands — I&#39;m even not sure that&#39;s possible, because even if you analyze a PDF or whatever, the AI is going to write a script and then the script is going to do something.&quot;</i> — Sergej Epp</p><p class="paragraph" style="text-align:left;">His operational fallback is the same as for any other privileged workload: runtime visibility into every LLM and coding agent in production.</p><p class="paragraph" style="text-align:left;"><b>Cloud security takeaway:</b> Apply Willison&#39;s three-category test to every AI agent deployment before production. If your coding agent has data access, execution rights, and network egress, document why and what control compensates.</p><h4 class="heading" style="text-align:left;" id="7-two-team-archetypes-architects-of">7. Two Team Archetypes — Architects of Security and Validators of Security</h4><p class="paragraph" style="text-align:left;">The conversation moves to organizational design. Sergej&#39;s argument is that the discipline-based team structure (cloud security, AppSec, IR, etc.) doesn&#39;t survive AI-speed operations. What replaces it is a two-archetype split. <i>&quot;We&#39;re going to see two types of roles going forward. The ones where you have all the security engineering, forensics coming together — the architects of security. And the validators of security: people who are building a validation architecture. Trying to understand: now I&#39;ve got these controls — what kind of ground rules, what kind of data are those controls collecting? Is this EDR really in the position to explain this type of attack and reconstruct it back? Are these rules really validated?&quot;</i> — Sergej Epp</p><p class="paragraph" style="text-align:left;">The third leg is the operating assumption: <i>&quot;You have simply to assume breach. That&#39;s the reality we are living in. And based on that, you build up your runtime, real-time controls — where you take the human out of the loop.&quot;</i> — Sergej Epp</p><p class="paragraph" style="text-align:left;"><b>Cloud security takeaway:</b> If your current org chart has a discipline-based shape (one team per technology), start thinking about how to overlay an architect/validator split on top of it. The validator role specifically — the team whose job is to continuously verify that your detections and controls actually fire on the attacks you claim they cover — is the one most programs don&#39;t have today.</p><h4 class="heading" style="text-align:left;" id="8-the-sysdig-hackathon-why-culture-">8. The Sysdig Hackathon — Why Culture Beats Mandate for AI Adoption</h4><p class="paragraph" style="text-align:left;">The most practical part of the conversation is also the most underrated. Sergej described running an internal hackathon to let his security team build with AI rather than mandating tool adoption from the top. <i>&quot;A lot of companies are trying to mandate from the top — you have to use AI, this is the tool you have to use. I think the first thing AI is going to disrupt is the entire management layer. Because the experts understand the pain points, they understand the problem. So let them try out how the AI is working, let them try to fix these problems.&quot;</i> — Sergej Epp</p><p class="paragraph" style="text-align:left;">The output surprised him: <i>&quot;I had a lot of IT people who didn&#39;t have an understanding of security, and a threat researcher who never wrote a line of code. And she was able then to come up with a framework to check if any APIs of Azure had drift, and how to adopt automatically the rules on top of that.&quot;</i> — Sergej Epp</p><p class="paragraph" style="text-align:left;"><b>Cloud security takeaway:</b> A half-day cross-functional hackathon — explicitly framed as exploration, not delivery — surfaces use cases your org chart doesn&#39;t predict.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="mental-model-offense-owns-objective">🧠<b> </b>Mental Model — Offense Owns Objective Verifiers. Defense Owns Environmental Verifiers.</h2><p class="paragraph" style="text-align:left;">Offense knows when the exploit worked. Defense doesn&#39;t natively know when the detection was right.</p><p class="paragraph" style="text-align:left;">The program that wins in 2026 is the one that asks, for every control in its stack, &quot;what&#39;s the binary signal that this fired correctly?&quot; — and replaces the controls where the answer is &quot;we don&#39;t really know.&quot;</p><p class="paragraph" style="text-align:left;">Honey tokens give you that signal. Environment graphs give you that signal. Naming-convention catalogs give you that signal. CSPM dashboards mostly don&#39;t.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>📚 RELATED RESOURCES 🎧</b></h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://zerodayclock.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow"><b>Zero Day Clock</b></a><a class="link" href="https://zerodayclock.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow"> </a>— Sergej&#39;s running dashboard tracking the gap between CVE disclosure and active exploitation</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.sysdig.com/blog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow"><b>Sysdig Strategic Research</b></a><a class="link" href="https://www.sysdig.com/blog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow"> </a>— Cloud threats and runtime security publications</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.verizon.com/business/resources/reports/dbir/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow"><b>Verizon 2026 DBIR</b></a> — Full report and industry-specific breakdowns</p></li><li><p class="paragraph" style="text-align:left;"><b>CISA Known Exploited Vulnerabilities Catalog</b> — Authoritative list of what&#39;s being exploited</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow"><b>Simon Willison&#39;s writing on AI agent risk</b></a> — The three-category mental model Sergej references</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow"><b>OWASP LLM Top 10</b></a><a class="link" href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow"> </a>— For teams building the AI agent governance layer</p></li></ul><h3 class="heading" style="text-align:left;" id="podcast-episode"><b>Podcast Episode</b></h3><ul><li><p class="paragraph" style="text-align:left;"><b>[</b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/the-zero-day-clock-how-ai-shrank-exploit-times-from-months-to-hours?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow"><b>Full Episode with Sergej Epp (Sysdig)</b></a><b>]</b> — Complete transcript and audio for this week&#39;s featured conversation</p></li></ul><hr class="content_break"><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔 If you mapped your defensive controls against Sergej&#39;s Verification Law tomorrow, which ones produce binary signal — and which are just probabilistic noise dressed up as detection?<br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=github-breach-caps-teampcp-s-5-compromise-run-sergej-epp-on-why-defense-has-no-verifiers" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=07330c1d-2e54-4571-8ea9-cfebd0a0ef45&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🚨 Google Stops the First AI-Generated Zero-Day - Why &quot;Guardrails Are Dead&quot;</title>
  <description>Google Threat Intelligence disrupted the first documented AI-generated zero-day this week, Microsoft published research turning Semantic Kernel prompt injection into host-level RCE, and a 172-package npm/PyPI worm tore through TanStack, Mistral AI, and UiPath in under six minutes. Against that backdrop, Check Point&#39;s David Haber (former Lakera CEO) and Paul Barbosa argue the layered-guardrail model security teams have built over the last two years is structurally finished, and explain what replaces it.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b5e6de56-18b3-4133-bb30-7daa924c94ff/Screenshot_2026-05-13_at_3.30.52_PM.png" length="2645841" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/google-stops-first-ai-zero-day-guardrails-dead</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/google-stops-first-ai-zero-day-guardrails-dead</guid>
  <pubDate>Wed, 13 May 2026 22:39:48 +0000</pubDate>
  <atom:published>2026-05-13T22:39:48Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">This week’s Cloud Security Newsletter topic<b>: </b><b>Guardrails Are Dead — What Replaces Them in the Agentic Era </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" rel="noopener noreferrer nofollow">(continue reading)</a> </p><hr class="content_break"><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://ceros.beyondidentity.ai/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead"><span class="button__text" style=""> This issue is sponsored by Beyond Identity </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b5e6de56-18b3-4133-bb30-7daa924c94ff/Screenshot_2026-05-13_at_3.30.52_PM.png?t=1778711491"/></a><div class="image__source"><span class="image__source_text"><p><i>This image was generated by AI. It&#39;s still experimental, so it might not be a perfect match!</i></p></span></div></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;">The week of May 8–13 produced two stories that sit at exactly the same intersection: AI is now both the attacker&#39;s tool and the attack surface. Google Threat Intelligence Group disrupted the first documented case of a criminal actor using an AI-generated zero-day exploit. Microsoft published research showing how prompt injection in its own Semantic Kernel framework escalates to host-level remote code execution in two separate code paths. And TeamPCP&#39;s Mini Shai-Hulud worm, which the same Google report attributed to UNC6780, compromised 172 packages across 403 versions, including the first malicious npm package ever to carry valid SLSA provenance.</p><p class="paragraph" style="text-align:left;">This week&#39;s conversation is with <b>David Haber</b>, VP AI Security at Check Point and founder of Lakera (the team behind Gandalf, the AI red-team game that has logged over 100 million human-AI interactions), and <b>Paul Barbosa</b>, VP of Cloud and SASE at Check Point, hosted by <b>Ashish Rajan</b>. The framing is sharp: David&#39;s position, <i>&quot;I believe guardrails are dead,&quot;</i> is the editorial spine of this week&#39;s news as much as it is of the episode. <i>[</i><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/how-claude-mythos-changes-vulnerability-management-from-cvss-to-exploitability?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">⚡ TL;DR for Busy Readers</h2><div class="codeblock"><pre><code>- Mini Shai-Hulud (CVE-2026-45321) compromised 172 npm/PyPI packages including TanStack, Mistral AI, UiPath, and OpenSearch. First malicious npm package with valid SLSA provenance. Rotate every secret that touched affected pipelines May 10–12.

- Google disrupted the first AI-generated zero-day: a Python 2FA bypass authored by an LLM and identified before mass exploitation. Assume exploit dev is now faster than your patch cycle.

- Microsoft Semantic Kernel CVEs (CVE-2026-26030, CVE-2026-25592) turn prompt injection into host RCE. If your agent calls tools, prompt injection is now a code-execution problem with blast radius equal to the agent&#39;s IAM.

- PAN-OS CVE-2026-0300 (CVSS 9.3) actively exploited by a likely state-sponsored cluster. Restrict Captive Portal to internal zones now; patches start May 13.

- David Haber&#39;s central argument: Stop layering perimeter guardrails. Move to contextual intelligence: evaluating agent intent, system instructions, and behavioral traces against what the agent is currently doing.</code></pre></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="this-weeks-security-news">📰 <b>THIS WEEK&#39;S TOP SECURITY HEADLINES</b></h2><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-google-disrupts-the-first-documen"><b> 1. Google Disrupts the First Documented AI-Generated Zero-Day</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">Google Cloud Threat Intelligence</a> <br><b>Reporting:</b> <a class="link" href="https://www.bloomberg.com/news/articles/2026-05-11/hackers-used-ai-to-build-zero-day-attack-google-researchers-say?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow"> Bloomberg</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> On May 11, Google Threat Intelligence Group disclosed the first known case of a criminal threat actor using an AI-generated zero-day exploit: a Python script that bypassed two-factor authentication on a popular open-source, web-based system administration tool. GTIG identified the exploit before mass exploitation and attributes AI authorship with high confidence based on hallucinated CVSS scores, abundant educational docstrings, and textbook Pythonic formatting. Gemini was not the LLM used. The same report documents North Korea-linked APT45 running thousands of recursive prompts to validate PoC exploits at scale, China-linked UNC2814 using persona jailbreaks (&quot;act as a senior security auditor&quot;) to research TP-Link firmware flaws, and a Chinese actor deploying agentic offensive tools Strix and Hexstrike against East Asian targets.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> This is the operational confirmation defenders have been forecasting for two years. AI-assisted vulnerability discovery has moved from theory to a working capability in the wild. For cloud security teams, the implication is concrete: if a single LLM-augmented researcher can produce weaponizable exploits faster than your patch cycle can absorb them, patch SLAs alone are no longer a viable program. Weight has to shift toward compensating controls: behavioral detection, least-privilege scoping for service accounts and non-human identities, and rapid containment playbooks that work without a patch in hand. The 72-minute breakout-time benchmark Unit 42 cited earlier this year now looks like the floor, not the ceiling.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-mini-shai-hulud-worm-172-packages"><b>2. Mini Shai-Hulud Worm: 172 Packages Compromised, Including the First Malicious Package with Valid SLSA Provenance </b>🚨</h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow"> Wiz</a> ·<a class="link" href="https://snyk.io/blog/tanstack-npm-packages-compromised/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow"> Snyk</a> <br><b>Advisory:</b> <a class="link" href="https://digital.nhs.uk/cyber-alerts/2026/cc-4781?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">NHS England Cyber Alert</a> <br><b>Analysis:</b> <a class="link" href="https://thehackernews.com/2026/05/mini-shai-hulud-worm-compromises.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> Between 19:20 and 19:26 UTC on May 11, TeamPCP (tracked as UNC6780 in Google&#39;s report this week) published 84 malicious versions across 42 @tanstack/* npm packages in under six minutes, then propagated to Mistral AI, UiPath, OpenSearch, Guardrails AI, and PyPI within hours. By May 12 the campaign had hit 172 unique packages across 403 malicious versions with cumulative downloads exceeding 518 million. TanStack&#39;s compromise was assigned CVE-2026-45321 (CVSS 9.6). The attack chain hijacked GitHub Actions via a pull_request_target trigger, used cache poisoning, and extracted OIDC tokens from /proc memory on the runner. npm tokens were never stolen; the publish pipeline itself was compromised. Payloads exfiltrate AWS IAM keys, GitHub PATs, HashiCorp Vault tokens, Kubernetes secrets, and 1Password/Bitwarden vaults, and inject persistence hooks into Claude Code (.claude/settings.json) and VS Code (tasks.json with runOn: folderOpen).</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> This is the most consequential supply chain attack of 2026 to date, and it breaks an assumption cloud security programs were starting to rely on: SLSA provenance attestation no longer guarantees a package wasn&#39;t tampered with. Any CI/CD environment that mints OIDC tokens (i.e., most modern GitHub Actions pipelines) is in scope. The persistence vector into AI coding agents is novel and underappreciated: a single <span style="color:rgb(24, 128, 56);">.claude/settings.json</span> injection turns a developer&#39;s daily AI assistant into a sustained execution channel. This is also the precise scenario David Haber describes in this week&#39;s episode: agents with tool access, untrusted inputs, and the autonomy to act.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-microsoft-research-semantic-kerne"><b>3. Microsoft Research: Semantic Kernel Prompt Injection Becomes Host-Level RCE</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> Microsoft Security Blog — Semantic Kernel research disclosure <b>Advisory:</b> CVE-2026-26030 (Python semantic-kernel &lt; 1.39.4) · CVE-2026-25592 (.NET SessionsPythonPlugin) <b>Analysis:</b> Vibe Graveyard · Windows Forum</p><p class="paragraph" style="text-align:left;"><b>What happened:</b> On May 7, Microsoft disclosed and patched two CVEs in its Semantic Kernel AI agent framework. CVE-2026-26030 (critical, Python semantic-kernel &lt; 1.39.4) is in the In-Memory Vector Store / Search Plugin path: a single crafted prompt launches calc.exe on the agent&#39;s host machine when the agent uses the default filter functionality. CVE-2026-25592 is in the .NET SDK&#39;s SessionsPythonPlugin, which is meant to isolate Python execution inside Azure Container Apps dynamic sessions but exposed a sandbox-to-host file-transfer helper as a kernel function. Once the LLM could invoke it as a tool, the local file path became attacker-controlled, enabling arbitrary host file writes from inside what was supposed to be an isolated sandbox. Microsoft framed the research as a class problem, not a one-off.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> This is the cleanest existing demonstration that AI agent security cannot be reduced to prompt safety. When an agent can call functions, query stores, run scripts, or touch cloud APIs, prompt injection is an application-security and identity problem with blast radius proportional to the agent&#39;s privileges. The story lands the same week David Haber argues, for unrelated reasons, that guardrail-style perimeter defenses are no longer sufficient against exactly this class of attack. The Microsoft research is the proof.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-panos-captive-portal-zero-day-act"><b>4. PAN-OS Captive Portal Zero-Day Actively Exploited — Likely State-Sponsored </b>🚨</h3><p class="paragraph" style="text-align:left;"><b>Advisory:</b> <a class="link" href="https://security.paloaltonetworks.com/CVE-2026-0300?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">Palo Alto Networks Advisory</a><br><b>Analysis:</b> <a class="link" href="https://unit42.paloaltonetworks.com/captive-portal-zero-day/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">Unit 42 Threat Brief</a>  · <a class="link" href="https://www.wiz.io/blog/critical-vulnerability-in-pan-os-exploited-in-the-wild-cve-2026-0300?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">Wiz</a> <br><b>Reporting:</b> <a class="link" href="https://thehackernews.com/2026/05/palo-alto-pan-os-flaw-under-active.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a></p><p class="paragraph" style="text-align:left;"><b>What happened:</b> Palo Alto Networks disclosed CVE-2026-0300 (CVSS 9.3) on May 6, with patches starting May 13. The flaw is an unauthenticated buffer overflow in the PAN-OS User-ID Authentication Portal (Captive Portal) on PA-Series and VM-Series firewalls, enabling RCE with root privileges via crafted packets. Prisma Access, Cloud NGFW, and Panorama are unaffected. CISA added it to KEV on May 6 with a May 9 federal patching deadline. Unit 42 attributes limited observed exploitation to CL-STA-1132, a likely state-sponsored cluster that achieved RCE on April 16 after a week of unsuccessful attempts beginning April 9, injected shellcode into an nginx worker, deployed EarthWorm and ReverseSocks5 tunneling tools, and conducted Active Directory enumeration using the firewall&#39;s service account credentials.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> A second story this week reinforcing the same theme as #1 and #2: internet-exposed security infrastructure is a primary target, not a hardened boundary. The post-exploitation pattern (pivot from the firewall&#39;s service account into AD enumeration) is textbook state-sponsored playbook and reinforces why firewall service accounts deserve tier-zero-equivalent treatment in your identity model. Approximately 225,000 internet-facing PAN-OS instances exist globally per Shodan, though only a subset run Captive Portal on ports 6081/6082.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-instructure-pays-ransom-to-shiny-"><b>5. Instructure Pays Ransom to ShinyHunters After Double Canvas Breach Hits 275M Users</b></h3><p class="paragraph" style="text-align:left;"><b>Primary source:</b> <a class="link" href="https://www.insidehighered.com/news/tech-innovation/administrative-tech/2026/05/11/instructure-pays-ransom-canvas-hackers?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">Inside Higher Ed</a> · <a class="link" href="https://www.theregister.com/security/2026/05/12/double-canvas-intrusion-confirmed-as-shinyhunters-resets-leak-deadline/5238361?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">The Register</a><br><b>Reporting:</b> <a class="link" href="https://thehackernews.com/2026/05/instructure-reaches-ransom-agreement.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow"> The Hacker News</a> </p><p class="paragraph" style="text-align:left;"><b>What happened:</b> Instructure, parent of the Canvas LMS used by ~41% of North American higher-ed institutions, confirmed on May 11 it reached an agreement with ShinyHunters after a two-stage breach. The initial intrusion on April 29 (disclosed May 1) exploited a flaw in the Canvas Free-for-Teacher account program to exfiltrate 3.65 TB of data: ~275 million records across 8,809 institutions including Harvard, Princeton, Columbia, Stanford, Penn, and Georgetown. After Instructure declined to negotiate and attempted to patch, ShinyHunters returned on May 7, defaced ~330 Canvas login portals worldwide, and took the platform offline during US finals week. Instructure subsequently stated it received &quot;digital confirmation of data destruction (shred logs),&quot; a strong implication of a ransom payment the company has not explicitly confirmed. The Free-for-Teacher program has been permanently shut down.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> This is the largest education-sector breach on record and a textbook SaaS concentration-risk case. A single under-governed product feature gave the adversary a path into the production multitenant Canvas environment. ShinyHunters&#39; 2026 playbook (third-party integrator compromise to reach downstream customers at scale) builds on its 2024 Snowflake-customer campaign and 2025 Salesforce campaign. The broader question for enterprise CISOs: many organizations now depend on a small number of critical SaaS platforms but lack mature playbooks for tenant compromise, platform-wide outage, or third-party-driven data exposure. The gaps this incident exposes for ed-tech are equally true for HR, CRM, identity, and collaboration SaaS.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="guardrails-are-dead-what-replaces-t"><b>Guardrails Are Dead - What Replaces Them in the Agentic Era</b></h3><p class="paragraph" style="text-align:left;">The thread running through every story above is the same: attackers no longer need to break the perimeter when they can manipulate the systems that operate inside it. The Google-disrupted AI zero-day worked because LLMs collapse the cost of producing weaponizable exploits. The Mini Shai-Hulud worm worked because trusted CI/CD primitives (OIDC tokens, SLSA attestations, GitHub Actions triggers) could be weaponized inside a pipeline that defenders had explicitly designed as trusted. The Semantic Kernel CVEs work because an agent&#39;s tool-calling layer is, by design, a privileged execution channel that text from anywhere can reach.</p><p class="paragraph" style="text-align:left;">David Haber and Paul Barbosa&#39;s argument is that the security industry&#39;s response to this class of problem, layering more guardrails, more perimeter checks, more &quot;don&#39;t do that&quot; rules at the prompt level, is structurally finished. What replaces it is something Haber calls contextual intelligence: evaluating intent, system instructions, behavioral traces, and tool calls in real time against what the agent is actually supposed to be doing. It is a harder problem and a different operating model.</p><hr class="content_break"><h2 class="heading" style="text-align:left;"><b>Featured Experts This Week </b>🎤</h2><ul><li><p class="paragraph" style="text-align:left;"><b>David Haber</b> — VP AI Security, Check Point | Founder & former CEO, Lakera (creators of Gandalf)</p></li><li><p class="paragraph" style="text-align:left;"><b>Paul Barbosa</b> — VP, Cloud and SASE, Check Point</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Direct prompt injection:</b> User input crafted to override an LLM&#39;s system instructions. The original form (&quot;ignore your previous instructions and do as I say&quot;) exploits the fact that LLMs do not architecturally distinguish between system instructions, retrieved data, and user input. It is all text and tokens.</p></li><li><p class="paragraph" style="text-align:left;"><b>Indirect prompt injection:</b> Malicious instructions delivered to an agent via the data and tools it consumes: a shared document, an email, an MCP-connected drive, an output from another agent. The victim does not interact with the malicious content; the agent does. As David Haber puts it, indirect prompt injections are often invisible, both hard to spot in real time and undetectable after the fact.</p></li><li><p class="paragraph" style="text-align:left;"><b>Gandalf:</b> Lakera&#39;s open-source AI red-teaming game launched ~2.5 years ago. Has reached tens of millions of people and logged over 100 million human-AI interactions, one of the largest datasets of how people actually try to exploit LLMs.</p></li><li><p class="paragraph" style="text-align:left;"><b>Contextual intelligence (as a defense pattern):</b> The replacement Haber proposes for perimeter guardrails. Evaluates the agent&#39;s design, system instructions, behavioral traces, and current actions in real time to reason about whether the agent is being manipulated. Requires substantially more telemetry than guardrail-based defenses.</p></li><li><p class="paragraph" style="text-align:left;"><b>Non-human identity (NHI):</b> Service accounts, API keys, OAuth tokens, and AI-agent identities. The credentials that AI agents and automation use to act inside cloud and SaaS environments.</p></li><li><p class="paragraph" style="text-align:left;"><b>Language as the new executable:</b> Paul Barbosa&#39;s framing that the domain of exploitation has shifted from code (requiring CS expertise and tool fluency) to natural language (bounded only by human creativity).</p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <a class="link" href="https://ceros.beyondidentity.ai/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow"><b>Beyond Identity</b></a></p><p class="paragraph" style="text-align:center;">AI Agents Are Running With Keys Your Security Stack Can&#39;t See</p><p class="paragraph" style="text-align:center;">The pressure to ship AI agents is real: do more with less, automate everything, yesterday. But every agent you deploy carries API keys, accesses sensitive systems, and executes actions your security tools were never designed to see. Legacy architectures leave you choosing between AI velocity and actual governance. Ceros eliminates that tradeoff. It controls the agent launch point with hardware-bound identity and continuous authorization, giving you full visibility into every tool call, MCP connection, and data flow.</p><p class="paragraph" style="text-align:center;"><a class="link" href="https://ceros.beyondidentity.ai/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">Try Ceros for Free</a></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-the-threat-model-shift-language-i"><b>1. The Threat Model Shift: Language Is the New Executable</b></h3><p class="paragraph" style="text-align:left;">The opening frame of the conversation is one cloud security leaders should sit with. Paul Barbosa describes the moment he understood why prompt injection is qualitatively different from prior classes of vulnerability:</p><p class="paragraph" style="text-align:left;"><i>&quot;The domain of exploit was very code driven. You had to know what you were doing. But with prompt injection, it&#39;s language. And we&#39;re only bound by like the limits of human creativity, which we know is boundless.&quot;</i> — Paul Barbosa</p><p class="paragraph" style="text-align:left;">The implication is that the population of people who can produce a working exploit has expanded by orders of magnitude. Haber confirms this empirically from Gandalf&#39;s 100M+ interaction dataset:</p><p class="paragraph" style="text-align:left;"><i>&quot;The most beautiful example we see — 12-year-old kids that are very successful playing the game. And we see some of the most advanced hackers that are also very successful at playing the game.&quot;</i> — David Haber</p><p class="paragraph" style="text-align:left;">That observation is the editorial bridge to this week&#39;s Google Threat Intelligence report. AI-assisted vulnerability research is not theoretical for state actors. APT45&#39;s recursive PoC validation runs and the criminal actor who produced the disrupted 2FA bypass are both empirical confirmations of what Haber has been seeing from the offensive side for two years.</p><p class="paragraph" style="text-align:left;"><b>What to do with this:</b> Audit which assumptions in your threat model still depend on &quot;attacker scarcity,&quot; the idea that sophisticated attacks require sophisticated attackers. The assumption no longer holds. Programs that rely on it (vulnerability triage that deprioritizes anything not on KEV, MFA selection that treats SMS as adequate, AppSec coverage that assumes attackers won&#39;t fuzz a particular surface) need an explicit refresh.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-indirect-prompt-injection-is-the-"><b>2. Indirect Prompt Injection Is the Attack That Matters</b></h3><p class="paragraph" style="text-align:left;">Haber draws a sharp distinction between direct and indirect prompt injection that maps directly onto how security teams should weight their concern:</p><p class="paragraph" style="text-align:left;"><i>&quot;I can exfiltrate your entire corporate inbox in about three seconds while you are on vacation, sipping a mojito. You will not even notice that I did that through an indirect prompt injection. You will have no idea. The indirect ones are often invisible. They&#39;re not only hard to spot — but also after the fact, you wouldn&#39;t even know.&quot;</i> — David Haber</p><p class="paragraph" style="text-align:left;">The Check Point team demonstrated this with a now-canonical example: a Google Doc containing a malicious prompt, shared with a user who never opens it. The user&#39;s AI agent, connected to their Drive, reads the document, follows the injected instructions, and exfiltrates data. The victim is not in the interaction loop at any point.</p><p class="paragraph" style="text-align:left;">This is the exact attack class Microsoft&#39;s Semantic Kernel research validates this week. The agent has tools. The tools have privileges. Any text the agent processes (including text it was asked to summarize, retrieve, or analyze) can become an instruction. The blast radius is determined entirely by what the agent is permitted to do.</p><p class="paragraph" style="text-align:left;"><b>What to do with this:</b> Inventory every AI agent in your environment by what data it reads and what tools it can call. Any agent that ingests untrusted content (email, shared documents, web pages, MCP-connected drives, tickets) and also has write or execute privileges is a candidate for indirect prompt injection. Reduce one side of the equation or the other; most agents are over-permissioned on tools relative to what they actually need.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-guardrails-are-dead-and-why-that-"><b>3. Guardrails Are Dead, and Why That Matters Now</b></h3><p class="paragraph" style="text-align:left;">This is the central thesis of the conversation, and Haber is unambiguous:</p><p class="paragraph" style="text-align:left;"><i>&quot;Last year, the hot talk in town was guardrails. I believe guardrails are dead. With the autonomy and the complexity that agentic AI brings, we need to go away from what are essentially perimeter checks. Putting one guardrail after another — &#39;don&#39;t talk about weapons, no hate speech, don&#39;t bash the competitor, prompt injection defense&#39; — we&#39;ve been layering on these guardrails on top of AI. That&#39;s over. It doesn&#39;t scale. What we need to do now is we need to move from perimeter checks to contextual intelligence.&quot;</i> — David Haber</p><p class="paragraph" style="text-align:left;">Contextual intelligence, in Haber&#39;s framing, evaluates the agent&#39;s design intent, system instructions, traces from past behavior, and user analytics in real time against the action the agent is currently taking. It is reasoning about whether the agent is being manipulated, not a static rule about what it can and cannot say.</p><p class="paragraph" style="text-align:left;">The structural critique applies just as cleanly to traditional cloud security tooling. Barbosa surfaces the WAF analogue:</p><p class="paragraph" style="text-align:left;"><i>&quot;How do you detect the prompt injection through a WAF? It&#39;s impossible. So if that&#39;s the access modality — that&#39;s one of the first places that we chose to make the integration with Lakera and the runtime security — to augment the WAF. Otherwise it&#39;s a request and there&#39;s no existing method to try to detect it.&quot;</i> — Paul Barbosa</p><p class="paragraph" style="text-align:left;">The point is not that WAFs are obsolete. It is that the layer in your stack designed to inspect text-shaped requests has no native concept of &quot;is this text trying to manipulate a downstream model?&quot; Adding that capability is an architectural change, not a rule update.</p><p class="paragraph" style="text-align:left;"><b>What to do with this:</b> If your current AI security strategy is a list of prompt filters or content guardrails bolted to model APIs, treat that as a starting baseline and not the end state. The investments that actually scale are agent-level behavioral instrumentation, tool-call auditing, and runtime evaluation of agent actions against declared intent. These are heavier engineering lifts than guardrails, and they need to start now.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-identity-for-agents-is-not-a-solv"><b>4. Identity for Agents Is Not a Solved Problem</b></h3><p class="paragraph" style="text-align:left;">When asked whether non-human identity controls can carry the weight that guardrails no longer can, Haber&#39;s answer is direct. His position, paraphrased from the transcript (where one word appears garbled and is preserved as such below):</p><p class="paragraph" style="text-align:left;"><i>&quot;I don&#39;t think the identity prompt [transcript reads &quot;prompt&quot;; almost certainly &quot;problem&quot;] for agents has been solved. At all... There are certain important questions around how we want to treat agents... One of the big areas people are looking into is self-replicating agents. So you&#39;ve got teams that are replicating themselves to maybe do other tasks. How do identities evolve with that? I don&#39;t think that&#39;s clear at all. Many claim they&#39;ve solved it. I&#39;ve not seen anything that convinces me that we have a good handle on that.&quot;</i> — David Haber [VERIFY exact word — possible transcription error]</p><p class="paragraph" style="text-align:left;">Barbosa reinforces the point. Least privilege for NHIs is necessary but not sufficient, because the space is moving too fast for any static control to be a stopping point:</p><p class="paragraph" style="text-align:left;"><i>&quot;It&#39;s never gonna be enough. The space is evolving too fast for any static control to say, okay, I understand I have non-human identity and I&#39;m gonna apply least privilege. That&#39;s just table stakes.&quot;</i> — Paul Barbosa</p><p class="paragraph" style="text-align:left;">This connects directly to the Mini Shai-Hulud worm and the Semantic Kernel CVEs. The worm exfiltrates exactly the credentials agents and automation use (AWS IAM keys, GitHub PATs, Vault tokens) and uses them to expand. The Semantic Kernel research shows that the agent&#39;s own service identity is the blast radius. Least privilege bounds the damage; it does not prevent the path.</p><p class="paragraph" style="text-align:left;"><b>What to do with this:</b> Treat NHI governance as a year-long program, not a project. The minimum tactical baseline: every AI agent in production has its own service identity (not a shared one), the identity is scoped to the specific tools and data the agent needs, and there is logging that tells you when the identity is used outside its expected pattern. Beyond that, plan for the harder problems Haber names: identity for self-replicating agents, identity that travels across environments, distinguishing &quot;Ashish acting via an agent&quot; from &quot;an agent acting on Ashish&#39;s behalf.&quot;</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-the-same-action-catastrophic-by-c"><b>5. The Same Action, Catastrophic by Context</b></h3><p class="paragraph" style="text-align:left;">Barbosa&#39;s framing of why context-aware defense matters is the cleanest articulation of the agentic security problem:</p><p class="paragraph" style="text-align:left;"><i>&quot;The same action that an agent could take could be okay — or it could be catastrophic, just depending on the conditions. The constraint on AI is never gonna be security, unfortunately. The constraint is gonna be productivity — and productivity by its very nature is always to be more helpful, is gonna ask for more and more access, more and more authorization. And I think as humans we&#39;re gonna gladly grant that. That same action taken by an attacker could be catastrophic.&quot;</i> — Paul Barbosa</p><p class="paragraph" style="text-align:left;">This is the exact dynamic in the Semantic Kernel SessionsPython case: a file-transfer helper is benign in the workflow it was written for, and an arbitrary host write primitive in the hands of an injected prompt. The function did not change. The context did.</p><p class="paragraph" style="text-align:left;"><b>What to do with this:</b> When evaluating agent deployments, the question is not &quot;does this tool seem dangerous?&quot; but &quot;what is the worst action this tool enables if the agent is being manipulated by content it just ingested?&quot; Most production agents have not been audited against that question. Start with the agents that touch customer data or cloud control planes.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="6-app-sec-network-data-its-all-one-"><b>6. AppSec, Network, Data — It&#39;s All One Problem Now</b></h3><p class="paragraph" style="text-align:left;">The conversation closes on an organizational point that maps directly onto how this week&#39;s news has to be triaged. Ashish presses on whether AI security is an AppSec problem or a data security problem. Haber&#39;s answer:</p><p class="paragraph" style="text-align:left;"><i>&quot;Now it&#39;s everything.&quot;</i> — David Haber</p><p class="paragraph" style="text-align:left;">Barbosa expands on what that means operationally:</p><p class="paragraph" style="text-align:left;"><i>&quot;It used to be like they own the tool — they&#39;re the network security team, they got the firewall, we&#39;ll get a ServiceNow ticket, it&#39;ll go to them. Now I think everyone more than ever, it&#39;s everyone&#39;s problem. If I&#39;m a CISO, I&#39;m going to every domain that I have a tool set and saying — how are you solving for this? Because it can render itself through your control, your tool set, or the applications that you&#39;re protecting.&quot;</i> — Paul Barbosa</p><p class="paragraph" style="text-align:left;">The Mini Shai-Hulud worm illustrates the point. The story is simultaneously a CI/CD problem (poisoned GitHub Actions), an identity problem (OIDC token theft), a secrets problem (Vault and IAM exfiltration), an endpoint problem (persistence into Claude Code and VS Code config), and a SaaS problem (npm and PyPI as the distribution channel). No single domain owner can fully respond to it.</p><p class="paragraph" style="text-align:left;"><b>What to do with this:</b> This week is a forcing function to ask, across every security domain in your organization, the same question Barbosa describes: &quot;how are you solving for this?&quot; If the answer is &quot;we&#39;re not, that&#39;s another team,&quot; find the gap and own it.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="7-the-defense-window-is-open-but-it"><b>7. The Defense Window Is Open, But It Is Closing</b></h3><p class="paragraph" style="text-align:left;">Haber&#39;s closing observation is the one worth carrying into next week&#39;s planning:</p><p class="paragraph" style="text-align:left;"><i>&quot;We are actually at a very unique time, I believe right now, where we still have a chance for defense to catch up. I see both offensive security and defense on an exponential curve. But I think the question is — what&#39;s the exponent? How fast are we actually moving?&quot;</i> — David Haber</p><p class="paragraph" style="text-align:left;">The Google-disrupted exploit was caught because GTIG was looking; the next one may not be. Mini Shai-Hulud broke an attestation primitive (SLSA) that defenders were starting to trust. Microsoft framed the Semantic Kernel research as a class problem, not a one-off.</p><p class="paragraph" style="text-align:left;"><b>What to do with this:</b> Pick one of the harder problems — agent behavioral monitoring, NHI lifecycle management, CI/CD supply chain attestation that survives runner compromise — and make actual progress on it this quarter.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="mental-model-language-is-the-new-ex">🧠<b> Mental Model — Language Is the New Executable</b></h2><p class="paragraph" style="text-align:left;">If language is executable, then every place an agent reads untrusted data is a place an attacker can run code.</p><p class="paragraph" style="text-align:left;">Guardrails were the AV scanner of the LLM era: pattern-matching on a target that mutates faster than the patterns. The successor is not a better filter. It is runtime context — what was this agent told to do, what is it doing now, and does the second match the first?</p><p class="paragraph" style="text-align:left;">Cloud security teams that build that telemetry layer in 2026 will be the ones positioned to defend in 2027. Teams that keep adding guardrails will be running an antivirus strategy against an autonomous adversary.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>📚 RELATED RESOURCES 🎧</b></h2><ul><li><p class="paragraph" style="text-align:left;">Check Point AI Security research — AI security threat research and Lakera-related publications</p></li><li><p class="paragraph" style="text-align:left;">Gandalf by Lakera — <a class="link" href="https://gandalf.lakera.ai?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">gandalf.lakera.ai</a> — AI red-team game, educational tool for prompt injection patterns</p></li><li><p class="paragraph" style="text-align:left;">CISA Known Exploited Vulnerabilities Catalog</p></li><li><p class="paragraph" style="text-align:left;">Google Cloud Threat Intelligence — AI Threat Tracker (May 2026)</p></li><li><p class="paragraph" style="text-align:left;">Microsoft Security Blog — Semantic Kernel research disclosure</p></li><li><p class="paragraph" style="text-align:left;">Unit 42 — PAN-OS CVE-2026-0300 Threat Brief</p></li><li><p class="paragraph" style="text-align:left;">Wiz / Snyk — Mini Shai-Hulud analyses</p></li></ul><h3 class="heading" style="text-align:left;" id="podcast-episode"><b>Podcast Episode</b></h3><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-guardrails-are-dead-the-threat-of-indirect-prompt-injection?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">Full Episode with David Haber and Paul Barbosa (Check Point) </a>— Complete transcript and audio for this week&#39;s featured conversation</p></li></ul><hr class="content_break"><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔 If guardrails are dead, what is the first thing you take out of your AI security stack — and what do you put in its place?<br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-stops-the-first-ai-generated-zero-day-why-guardrails-are-dead" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=d84a33f6-8ca0-4377-9fcf-c5e989343e51&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Claude Mythos broke vulnerability management in 72 hours</title>
  <description>Heartbleed was a storm. Mythos is climate change. That&#39;s how Brad Hibbert (COO, Brinqa) framed this week&#39;s shift on the podcast and the news cycle proved him right within 72 hours.Active PAN-OS zero-day. 35,000 M365 users phished past MFA. 300,000 Ollama servers leaking API keys. Cisco dropping $400M on non-human identity.Every story this week hits the same nerve: the gap between vulnerability disclosed and vulnerability weaponized is no longer measured in months. The 30/60/90-day patch SLA your program runs on? It&#39;s already obsolete.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3203c2d5-b2a6-4b89-8917-126c6c6e2ece/Screenshot_2026-05-07_at_2.29.18_PM.png" length="4051108" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/claude-mythos-broke-vulnerability-management-in-72-hours</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/claude-mythos-broke-vulnerability-management-in-72-hours</guid>
  <pubDate>Thu, 07 May 2026 21:21:00 +0000</pubDate>
  <atom:published>2026-05-07T21:21:00Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><h2 class="heading" style="text-align:left;" id="hello-from-the-cloudverse"><span style="background-color:#28EEDA;"><b>Hello from the Cloud-verse!</b></span></h2><p class="paragraph" style="text-align:left;">This week’s Cloud Security Newsletter topic<b>: </b><b>Why CVSS Alone Won&#39;t Survive the AI Era </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" rel="noopener noreferrer nofollow">(continue reading)</a> </p><hr class="content_break"><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://links.cloudsecuritypodcast.tv/orca-cloud-security-live-2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours"><span class="button__text" style=""> This issue is sponsored by Orca Security </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3203c2d5-b2a6-4b89-8917-126c6c6e2ece/Screenshot_2026-05-07_at_2.29.18_PM.png?t=1778157012"/></a><div class="image__source"><span class="image__source_text"><p><i>This image was generated by AI. It&#39;s still experimental, so it might not be a perfect match!</i></p></span></div></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;">If the past week had a thesis, it&#39;s this: the gap between <i>vulnerability disclosed</i> and <i>vulnerability weaponized</i> is no longer measured in months. It&#39;s measured in days, sometimes hours, and the underlying cause isn&#39;t a single tool or actor — it&#39;s the AI-assisted offensive workflow that&#39;s now table stakes for advanced adversaries.</p><p class="paragraph" style="text-align:left;">The news brief reflects it everywhere. Palo Alto Networks disclosed CVE-2026-0300 with state-sponsored exploitation already underway. Microsoft documented a three-day AiTM campaign that quietly stole post-MFA tokens from 13,000 organizations. Cyera&#39;s Bleeding Llama disclosure showed how default-permissive AI infrastructure is leaking the most sensitive secrets in the building. And Cisco put $400 million on the table to lock down non-human identities — the credential layer AI agents now use to act inside enterprises.</p><p class="paragraph" style="text-align:left;">Against that backdrop, this week&#39;s conversation is with <b>Brad Hibbert</b>, COO and Chief Strategy Officer at <b>Brinqa</b>, hosted by <b>Ashish Rajan</b> of <i>Cloud Security Podcast</i>. The discussion is about Claude Mythos — Anthropic&#39;s frontier model now being tested in private programs against vulnerability discovery — and what it means for every existing vulnerability management program. Brad&#39;s framing is sharp: <i>&quot;Heartbleed was a storm. Mythos is climate change.&quot; </i><i>[</i><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/how-claude-mythos-changes-vulnerability-management-from-cvss-to-exploitability?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">⚡ TL;DR for Busy Readers</h2><div class="codeblock"><pre><code>This week’s attacks didn’t break systems — they used them


🔥 PAN-OS CVE-2026-0300 is being actively exploited by a likely state-sponsored cluster — restrict Captive Portal to internal IPs now; patches start May 13.

🪪 Microsoft AiTM campaign stole post-MFA tokens from 35K users — non-phishing-resistant MFA is over; move M365 admins to FIDO2/passkeys this quarter.

🦙 Bleeding Llama (CVE-2026-7482) leaks heap memory from 300K Ollama servers, including API keys and prompts — inventory, upgrade to 0.17.1, rotate exposed secrets.

🤖 Cisco&#39;s $400M Astrix acquisition validates non-human identity as a top-tier security category — start your NHI inventory this month.

⏱️ Brad Hibbert&#39;s core argument: Stop measuring patch SLAs. Start measuring the exposure window — how long a vulnerability was actually exploitable in your environment..</code></pre></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="this-weeks-security-news">📰 <b>THIS WEEK&#39;S TOP SECURITY HEADLINES</b></h2><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-panos-zeroday-state-actors-are-al"><b> 1. </b><b>PAN-OS zero-day: state actors are already inside</b></h3><p class="paragraph" style="text-align:left;">Palo Alto Networks disclosed CVE-2026-0300 on May 6 — unauthenticated RCE on PA-Series and VM-Series firewalls. Unit 42 is tracking active exploitation by CL-STA-1132, a likely state-sponsored cluster. The pattern: RCE → log destruction → AD enumeration via firewall service account credentials.</p><p class="paragraph" style="text-align:left;">CISA added it to KEV on May 6. Patches roll out May 13. Until then: restrict the User-ID Authentication Portal to internal IPs only.</p><p class="paragraph" style="text-align:left;">The attackers had RCE for <i>days</i> before disclosure. Any defender measuring success by patch SLA had a green dashboard while their AD was being mapped, a textbook example of why &quot;exposure window&quot; matters more than &quot;patch window.&quot;</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://unit42.paloaltonetworks.com/captive-portal-zero-day/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">→ Read the Unit 42 brief</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-35000-users-mfa-didnt-help"><b>2. </b><b>35,000 users. MFA didn&#39;t help.</b></h3><p class="paragraph" style="text-align:left;">Microsoft Defender Research disclosed a 3-day adversary-in-the-middle campaign (April 14-16) that hit 35,000+ users across 13,000 organizations. Healthcare and finance led the target list. The attackers proxied the legitimate Microsoft login flow in real time, capturing post-authentication session tokens — sidestepping passwords <i>and</i> SMS/app-based MFA entirely.</p><p class="paragraph" style="text-align:left;">If you&#39;re still on non-phishing-resistant MFA for M365 admins, this is your wake-up call. FIDO2 or passkeys this quarter, not next.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">→ Read Microsoft&#39;s analysis</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-your-ai-inference-servers-are-lea"><b>3. </b><b>Your AI inference servers are leaking secrets</b></h3><p class="paragraph" style="text-align:left;">Cyera&#39;s &quot;Bleeding Llama&quot; disclosure (CVE-2026-7482, CVSS 9.1) is the AI infrastructure story most cloud teams aren&#39;t tracking. Three unauthenticated API calls leak the entire Ollama process memory — including the API keys, database creds, and cloud secrets sitting in environment variables on your inference hosts.</p><p class="paragraph" style="text-align:left;">300,000 servers exposed. Patched silently in 0.17.1, but the patch notes never flagged it as a security update — so most operators never upgraded.</p><p class="paragraph" style="text-align:left;">The pattern: AI infrastructure deployed with <a class="link" href="https://localhost?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">localhost</a>-tool defaults running as production servers, with the most sensitive credentials in the building sitting in <code>0.0.0.0</code>-bound process memory.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cyera.com/research/bleeding-llama-critical-unauthenticated-memory-leak-in-ollama?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">→ Read Cyera&#39;s writeup</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-cisco-bets-400-m-that-nonhuman-id"><b>4. </b>Cisco bets $400M that non-human identity is the new perimeter</h3><p class="paragraph" style="text-align:left;">Cisco announced its intent to acquire Israeli identity-security startup <b>Astrix Security</b> for ~$400M on May 4. Astrix discovers and governs non-human identities (NHIs) — API keys, service accounts, OAuth tokens, machine credentials — across their lifecycle. Cisco will fold it into Identity Intelligence, Duo, Secure Access, and Splunk.</p><p class="paragraph" style="text-align:left;">This is the first nine-figure security M&A explicitly framed around securing AI agents at the credential layer. Machine identities outnumber humans 10-to-1 in most enterprises, and they&#39;re the path of least resistance for AI-agent compromise and supply chain attacks.</p><p class="paragraph" style="text-align:left;">Expect rapid consolidation across Okta, CyberArk, SailPoint, Wiz, and Palo Alto. Inventory NHIs now if you haven&#39;t.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.securityweek.com/cisco-moves-to-acquire-astrix-security-to-tackle-non-human-identity-risks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">→ Read SecurityWeek&#39;s coverage</a></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="from-patch-windows-to-exposure-wind"><b>From Patch Windows to Exposure Windows — Why CVSS Alone Won&#39;t Survive the AI Era</b></h3><p class="paragraph" style="text-align:left;">The shift Brad Hibbert describes is structural, not tactical. For two decades, vulnerability management has run on a clear contract: a vendor publishes a CVSS score, your scanner picks it up, you classify by severity, and you remediate within an SLA — typically 30/60/90 days driven by PCI or another compliance regime. Patch SLA performance became the metric that boards and auditors rallied around.</p><p class="paragraph" style="text-align:left;">That contract assumed two things that no longer hold: (1) attackers needed time and skill to weaponize disclosed vulnerabilities, and (2) the volume of meaningful CVEs would scale linearly. AI-assisted vulnerability discovery breaks both assumptions simultaneously. Brad describes the Mythos shift bluntly: <i>&quot;It&#39;s a persistent elevation of capability that the threat actors have, which is that they can discover vulnerabilities at machine speeds now.&quot;</i></p><p class="paragraph" style="text-align:left;">The implication for cloud security leaders is that the <i>yardstick itself</i> has to change. The new metric is the exposure window how long a given vulnerability was actually exploitable inside your environment, taking into account business context, mitigating controls, network reachability, identity blast radius, and attack-chain composition. Patching faster doesn&#39;t get you there; some of the most consequential issues this week (PAN-OS, Bleeding Llama) were exploitable for weeks before patches existed.</p><p class="paragraph" style="text-align:left;">That reframing forces a series of architectural and operating-model changes and it&#39;s the central thread running through this week&#39;s news as well as the conversation below.</p><hr class="content_break"><h2 class="heading" style="text-align:left;"><b>Featured Experts This Week </b>🎤</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/bradhibbert/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow"><b>Brad Hibbert</b></a> — COO & Chief Strategy Officer, Brinqa</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Claude Mythos:</b> Anthropic&#39;s frontier model currently in private testing for security and intelligence applications, including AI-assisted vulnerability discovery at scale. Brad describes it as a <i>&quot;climate change&quot;</i> shift versus prior temporal events like Heartbleed and Log4Shell.</p></li><li><p class="paragraph" style="text-align:left;"><b>Exposure Window:</b> The duration a vulnerability is actually exploitable in your environment — distinct from the patch window. Driven by reachability, mitigating controls, and identity blast radius, not just CVSS severity.</p></li><li><p class="paragraph" style="text-align:left;"><b>CTEM (Continuous Threat Exposure Management):</b> Gartner-defined program model that emphasizes continuous discovery, validation, prioritization, and mobilization. Brad argues the Mythos compression effectively forces every program toward CTEM-style operations on a compressed timeline.</p></li><li><p class="paragraph" style="text-align:left;"><b>EPSS (Exploit Prediction Scoring System):</b> Probability score for whether a CVE will be exploited in the wild within 30 days. Useful as a complement to CVSS, but Brad&#39;s caveat lands: <i>&quot;if everything is exploited and everything&#39;s kind of ranked the same, how do you provide better guidance to your team?&quot;</i></p></li><li><p class="paragraph" style="text-align:left;"><b>Attack Chain Analysis:</b> The practice of evaluating multiple low/medium-severity findings together as a path-to-impact, rather than node-by-node. Mythos demonstrated chained privilege escalation across three medium CVEs to achieve root.</p></li><li><p class="paragraph" style="text-align:left;"><b>Non-Human Identity (NHI):</b> Service accounts, API keys, OAuth tokens, machine credentials, and AI-agent identities — typically outnumbering human identities 10-to-1 in modern enterprises.</p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <b><a class="link" href="https://links.cloudsecuritypodcast.tv/orca-cloud-security-live-2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">Orca Security</a></b></p><p class="paragraph" style="text-align:center;">Orca Security is hosting Cloud Security LIVE, a half-day virtual summit on Tuesday, May 12th. Join CISOs, security co-founders, and practitioners for unfiltered insight real stories and strategies from people securing the world&#39;s most complex cloud environments. </p><p class="paragraph" style="text-align:left;">Sessions include:</p><ul><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);font-family:Arial, Helvetica, sans-serif;font-size:small;"><b>The new standard for resilience: zero-breach to zero-impact</b></span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);font-family:Arial, Helvetica, sans-serif;font-size:small;"><b>AI on both sides: securing models and APIs while using AI to defend your cloud</b></span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);font-family:Arial, Helvetica, sans-serif;font-size:small;"><b>Mastering 3rd-party and supply chain risk</b></span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);font-family:Arial, Helvetica, sans-serif;font-size:small;"><b>Security leadership panel on AI, risk, and driving change</b></span></p><p class="paragraph" style="text-align:left;"><br><span style="color:rgb(34, 34, 34);font-family:Arial, Helvetica, sans-serif;font-size:small;"><i>Join for a chance to win* a 64GB Beelink AI PC. *US-based attendees only.</i></span></p></li></ul><p class="paragraph" style="text-align:center;"><a class="link" href="https://links.cloudsecuritypodcast.tv/orca-cloud-security-live-2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">Register Today</a></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-heartbleed-was-a-storm-mythos-is-"><b>1. Heartbleed was a storm. Mythos is climate change.</b></h3><p class="paragraph" style="text-align:left;">Brad opens the conversation with a frame that&#39;s worth sitting with. Past high-profile vulnerabilities Heartbleed, Log4Shell were <i>temporal</i>. They caused intense activity, then closed out. The exploit cycle had a beginning, a middle, and an end.</p><p class="paragraph" style="text-align:left;"><i>&quot;It&#39;s not just a temporal thing — it&#39;s a persistent elevation of capability that the threat actors have... your months went down to weeks, and in some cases down to seconds before these things can be exploited.&quot;</i> — Brad Hibbert</p><p class="paragraph" style="text-align:left;">What this changes for cloud security leaders is the <b>planning horizon</b> of the program itself. A program designed to handle 12 Heartbleed-class events per year fails when the underlying capability shift is permanent. The PAN-OS exploitation pattern this week successful RCE within a week of first attempts, log destruction inside the same operation is the <i>normal</i> tempo now, not the anomaly.</p><p class="paragraph" style="text-align:left;"><b>What to do with this:</b> Audit your program&#39;s design assumptions. If your SLAs, change-control windows, and remediation handoff cadence were built when &quot;manual vulnerability research at machine scale&quot; was a contradiction in terms, those assumptions need an explicit refresh. Brad&#39;s framing for the board: <i>&quot;It&#39;s not about closing off your criticals in 30 days to meet PCI compliance. It&#39;s about how exploitable, what&#39;s that exposure window, and how am I showing that go down?&quot;</i></p><h3 class="heading" style="text-align:left;" id="2-the-threat-model-isnt-dead-but-th"><b>2. The threat model isn&#39;t dead — but the assumptions inside it are</b></h3><p class="paragraph" style="text-align:left;">When Ashish asks whether existing threat models are still valid, Brad&#39;s answer is nuanced: the structure holds, but the embedded assumptions don&#39;t.</p><p class="paragraph" style="text-align:left;"><i>&quot;The assumptions that sophisticated attacks required sophisticated attackers has kind of gone away.&quot;</i> — Brad Hibbert</p><p class="paragraph" style="text-align:left;">Three specific assumptions Brad calls out:</p><ol start="1"><li><p class="paragraph" style="text-align:left;"><b>Attacker scarcity.</b> The cost of mounting a sophisticated attack has collapsed. The Mexican government breach earlier this year — where a single actor used Claude to steal 150GB across nine agencies validated this empirically.</p></li><li><p class="paragraph" style="text-align:left;"><b>Time between discovery and remediation.</b> PCI&#39;s 30-day window for criticals is an artifact of an era when 30 days was a reasonable gap before exploitation. It isn&#39;t anymore.</p></li><li><p class="paragraph" style="text-align:left;"><b>CVSS as primary prioritization.</b> Brad&#39;s point: when 40,000 highs become 80,000 highs and EPSS marks most of them as likely-exploited, prioritization based on severity scores degenerates into noise.</p></li></ol><p class="paragraph" style="text-align:left;"><b>Practitioner translation:</b> Run a tabletop exercise this quarter where the trigger is <i>&quot;a new CVE-2026-0300-class vulnerability is disclosed at 9am with public PoC by noon, mass exploitation by midnight.&quot;</i> Where does your program fail? That&#39;s your investment list.</p><h3 class="heading" style="text-align:left;" id="3-the-new-yardstick-is-exploitabili"><b>3. The new yardstick is exploitability and the exposure window</b></h3><p class="paragraph" style="text-align:left;">This is the core argument of the conversation, and the through-line back to the news.</p><p class="paragraph" style="text-align:left;"><i>&quot;The biggest thing today is the biggest short-term thing that CISOs need to do is they need to focus on exploitability and explainability... what we&#39;ve been talking about with a lot of companies right now is you have to get down to exploitability.&quot;</i> — Brad Hibbert</p><p class="paragraph" style="text-align:left;">Exploitability, in Brad&#39;s framing, isn&#39;t just &quot;is there a public PoC?&quot; It&#39;s the intersection of the vulnerability with <i>your</i> environment: reachability, mitigating controls (EDR, segmentation, identity guardrails), business context, and the existence of attack paths that chain it with other findings.</p><p class="paragraph" style="text-align:left;">The exposure window is the operational consequence: how long was the vulnerability <i>actually</i> exploitable in your environment, end-to-end, until you reduced or eliminated that exploitability — whether by patching, segmenting, killing reachability, or applying a compensating control. Brad&#39;s distinction is critical: <b>you don&#39;t always need to patch to close the exposure window.</b> You need to make the path inactive.</p><p class="paragraph" style="text-align:left;">That distinction maps directly to several stories this week. Bleeding Llama: the patch existed but wasn&#39;t flagged as security; the <i>real</i> fix for most enterprises was putting an auth proxy in front and binding Ollama to <a class="link" href="https://localhost?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">localhost</a>. PAN-OS: patches don&#39;t ship until May 13 but restricting User-ID portal access to internal IPs collapses the exposure window today.</p><h3 class="heading" style="text-align:left;" id="4-stop-ignoring-the-lows-start-mapp"><b>4. Stop ignoring the lows. Start mapping attack chains.</b></h3><p class="paragraph" style="text-align:left;">One of the sharpest moments in the conversation comes when Ashish acknowledges what most security teams have been quietly doing for years:</p><p class="paragraph" style="text-align:left;"><i>&quot;90% of the time, a lot of the lows were just simply ignored because like, &#39;Hey, it&#39;s a low.&#39; I don&#39;t know how many organizations have done this ever.&quot;</i> — Ashish Rajan</p><p class="paragraph" style="text-align:left;">Brad&#39;s response confirms the gap:</p><p class="paragraph" style="text-align:left;"><i>&quot;Three medium vulnerabilities, leveraging privilege escalation, could give them root access to a machine versus one standalone critical CVE... you&#39;ve got to back up and take a look at it not from a node lens, but from a network path lens and attack chain lens.&quot;</i> — Brad Hibbert</p><p class="paragraph" style="text-align:left;">This is what AI-assisted attackers do natively. Mythos demonstrated the ability to chain three medium CVEs into a privilege escalation that would not have triggered any individual high/critical SLA. Defenders running CVSS-only prioritization will keep missing these because the analytical lens is wrong; they&#39;re evaluating findings node-by-node when the attacker is reasoning over graphs.</p><p class="paragraph" style="text-align:left;"><b>Practical implication:</b> This is one of the strongest arguments for the kind of unified exposure data plane Brad describes. You cannot compose attack chains across silos. If your CSPM, EDR, vulnerability scanner, and identity tools all run independent AI-driven prioritization, you get <i>siloed AI decisions</i> which are structurally weaker than what an integrated attacker is doing.</p><h3 class="heading" style="text-align:left;" id="5-remediation-has-been-the-foreverp"><b>5. Remediation has been the forever-problem because the </b><i><b>objective</b></i><b> was misaligned</b></h3><p class="paragraph" style="text-align:left;">Ashish&#39;s question &quot;why have we never solved remediation?&quot; opens the most operationally useful section of the conversation. Brad&#39;s answer is that the security and remediation teams have been measured on different things:</p><p class="paragraph" style="text-align:left;"><i>&quot;If you have two teams that are measured differently — one team&#39;s measured on how quickly they can identify and prioritize, the other team&#39;s measured on how quick a patch gets released — they&#39;re two different measurements. If you focus on the same outcome as a shared objective, which is to reduce the exploitability window, out of that will follow a bunch of other decisions.&quot;</i> — Brad Hibbert</p><p class="paragraph" style="text-align:left;">This is the kind of strategic-architectural insight senior cloud security leaders can act on without buying anything new. The fix is the operating model, not tooling: rewrite the shared OKR for security + cloud ops + dev so both sides are measured on <b>reduction of exposure window</b> rather than time-to-patch and time-to-detect respectively.</p><p class="paragraph" style="text-align:left;">Brad also flags the friction layer that bottoms most programs out — the manual handoff:</p><p class="paragraph" style="text-align:left;"><i>&quot;They wanna know why is A ahead of B? Why is B ahead of C? When you pass that information, if you have a shared objective and a shared understanding for how the security team is prioritizing, and an agreed upon approach... you have less of this &#39;let me export that to Excel, let me compare that to my scanner.&#39;&quot;</i> — Brad Hibbert</p><p class="paragraph" style="text-align:left;">Building shared explainability as to why a finding was prioritized, in language remediation teams trust  is the trust-building work that lets you eventually automate decisions. Without it, every prioritization becomes a negotiation.</p><h3 class="heading" style="text-align:left;" id="6-trust-is-a-muscle-automate-increm"><b>6. Trust is a muscle. Automate incrementally, but start.</b></h3><p class="paragraph" style="text-align:left;">When Ashish presses on whether AI-suggested remediation can be trusted enough to automate, Brad&#39;s answer is staged but firm:</p><p class="paragraph" style="text-align:left;"><i>&quot;You can automate things that are simple, that have very minimal impact, that are reversible. That&#39;s great. But if it&#39;s not reversible and can have an impact, then you start to get a little queasy in your stomach... they have to build up trust as they start to automate these processes through reasoning and through AI. They will start taking that 5% that they automate today, the 6%, the 10%, the 20%.&quot;</i> — Brad Hibbert</p><p class="paragraph" style="text-align:left;">The pattern he describes is small, reversible, low-blast-radius first, building toward more consequential decisions with explainability and audit trails throughout — matches what mature platform-engineering teams already do for production change management. The application of the same pattern to security remediation is the bridge that&#39;s been missing.</p><p class="paragraph" style="text-align:left;"><b>Cloud-security takeaway:</b> Pick one cloud-native control where automation is reversible (e.g., revoking an over-privileged IAM role, blocking egress from a workload, rotating a service-account secret) and instrument it end-to-end with audit logging and rollback. That&#39;s your wedge for trust-building. Once the muscle exists, extending to less reversible actions becomes a policy conversation, not a technical one.</p><h3 class="heading" style="text-align:left;" id="7-dont-boil-the-ocean-pick-one-high"><b>7. Don&#39;t boil the ocean pick one high-stakes asset and prove the model</b></h3><p class="paragraph" style="text-align:left;">When asked about quick wins, Brad is pragmatic:</p><p class="paragraph" style="text-align:left;"><i>&quot;If you&#39;re gonna build on the top of the pyramid, don&#39;t try to do everything across the whole asset stack. Focus on a high-profile application that could have significant impact to the business, and maybe focus on your external attack surface first. Pick your poison... work the kinks out, work on that shared responsibility, kind of what the shared measurements are gonna be. Show the model working and then expand from there.&quot;</i> — Brad Hibbert</p><p class="paragraph" style="text-align:left;">This is the most actionable 30-60 day playbook from the conversation:</p><ol start="1"><li><p class="paragraph" style="text-align:left;">Pick one high-business-impact application or one critical external attack surface segment.</p></li><li><p class="paragraph" style="text-align:left;">Define a shared exposure-window OKR across security and the relevant remediation team.</p></li><li><p class="paragraph" style="text-align:left;">Instrument the full lifecycle — discovery, enrichment, exploitability assessment, prescriptive remediation guidance, two-way ticketing integration, post-remediation verification.</p></li><li><p class="paragraph" style="text-align:left;">Measure exposure-window reduction, not patch volume.</p></li><li><p class="paragraph" style="text-align:left;">Use the working model as the proof case to expand scope.</p></li></ol><h3 class="heading" style="text-align:left;" id="8-the-convergence-problem-siloed-ai"><b>8. The convergence problem: siloed AI is going to fail</b></h3><p class="paragraph" style="text-align:left;">Brad&#39;s closing observation is one cloud security leaders should plan for now:</p><p class="paragraph" style="text-align:left;"><i>&quot;I think a lot of security vendors are gonna say, &#39;We have the solution, it&#39;s AI.&#39; But then what you&#39;re gonna do is you have these siloed security products making siloed AI decisions. What organizations need is to bring all this information into a global exposure repository so they can understand everything from a global perspective.&quot;</i> — Brad Hibbert</p><p class="paragraph" style="text-align:left;">The Cisco/Astrix deal in this week&#39;s news is, in part, a bet on this convergence pulling NHI, identity intelligence, secure access, and SIEM (via Splunk) into a single context-aware control plane. Expect more consolidation along the same line over the next 18 months. For practitioners building their own roadmap, the design principle is to invest in data integration and unified context before adding more siloed AI features.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>📚 RELATED RESOURCES 🎧</b></h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.brinqa.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">Brinqa — Resources on Mythos and Exposure Management</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">CISA Known Exploited Vulnerabilities Catalog</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cisa.gov/topics/industrial-control-systems/ci-fortify?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">CISA CI Fortify Initiative</a> — guidance for critical infrastructure operators on isolation and recovery</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://unit42.paloaltonetworks.com/captive-portal-zero-day/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">Unit 42 PAN-OS Threat Brief (CVE-2026-0300)</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">Microsoft Security Blog — AiTM Code-of-Conduct Campaign Analysis</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cyera.com/research/bleeding-llama-critical-unauthenticated-memory-leak-in-ollama?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">Cyera Research — Bleeding Llama Disclosure</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.gartner.com/en/cybersecurity/topics/exposure-management?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">Gartner CTEM Framework Overview</a> — for teams building toward continuous threat exposure management</p></li></ul><h3 class="heading" style="text-align:left;" id="podcast-episode"><b>Podcast Episode</b></h3><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/how-claude-mythos-changes-vulnerability-management-from-cvss-to-exploitability?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow"><b>Cloud Security Podcast -Full Episode with Brad Hibbert</b></a>- Complete transcript and audio for this week&#39;s featured conversation</p></li></ul><hr class="content_break"><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔<b> </b> If you measured your program on <i>exposure window reduction</i> instead of patch SLA next quarter, which OKR breaks first — and what does that tell you?<br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=claude-mythos-broke-vulnerability-management-in-72-hours" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=6d78eac2-6bc4-4eb1-a5e0-960264aab3ce&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>An AI gateway exploited in 36 hours</title>
  <description>This week&#39;s Cloud Security Newsletter unpacks the AI gateway exploitation pattern (CVE-2026-42208) that turned LiteLLM into a cloud-account-class risk, Wiz&#39;s GitHub disclosure (CVE-2026-3854), and Google Cloud Next &#39;26&#39;s agentic defense pivot, alongside Shawn Hays of Varonis on the eight pillars of an enterprise AI security program, why visibility and AISPM alone leave the biggest gaps, and how to apply zero trust across agents, prompts, identities, and the cloud architects sitting behind the data. Topics: AI security program, AISPM, agentic AI, agent identity, AI bill of materials, third-party AI risk, copilot governance, multi-AI enterprise, zero trust for agents</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/64bd6df4-8933-4f4c-ae99-f52da5d01f5c/Screenshot_2026-04-29_at_6.19.45_PM.png" length="2104039" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/ai-security-program-gaps-litellm-github-rce</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/ai-security-program-gaps-litellm-github-rce</guid>
  <pubDate>Wed, 29 Apr 2026 21:00:00 +0000</pubDate>
  <atom:published>2026-04-29T21:00:00Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><h2 class="heading" style="text-align:left;" id="hello-from-the-cloudverse"><span style="background-color:#28EEDA;"><b>Hello from the Cloud-verse!</b></span></h2><p class="paragraph" style="text-align:left;">This week’s Cloud Security Newsletter topic<b>: </b><b>What&#39;s Missing From Most AI Security Programs</b><b> </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" rel="noopener noreferrer nofollow">(continue reading)</a> </p><hr class="content_break"><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://links.cloudsecuritypodcast.tv/orca-cloud-security-live-2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours"><span class="button__text" style=""> This issue is sponsored by Orca Security </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/64bd6df4-8933-4f4c-ae99-f52da5d01f5c/Screenshot_2026-04-29_at_6.19.45_PM.png?t=1777483225"/></a><div class="image__source"><span class="image__source_text"><p><i>This image was generated by AI. It&#39;s still experimental, so it might not be a perfect match!</i></p></span></div></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;">Two stories defined this week, and both expose the same gap. On the AI side, the LiteLLM SQL injection (CVE-2026-42208) was exploited in the wild within 36 hours of disclosure, the AI gateway turned out to be a credential vault holding OpenAI, Anthropic, and AWS Bedrock keys in a single PostgreSQL row. On the platform side, Wiz disclosed a GitHub RCE (CVE-2026-3854) reachable via a single git push, with cross-tenant blast radius on shared storage. Different bug classes, same underlying signal: the security perimeter for cloud workloads has moved up the stack into AI gateways, agent identities, and the platforms between developers and production, and most enterprise AI security programs were scoped before any of this was on the map.</p><p class="paragraph" style="text-align:left;">To unpack the gap and what to do about it, we sat down with <b>Shawn Hays</b>, Product Marketing Manager for Microsoft Applications and AI Security Solutions at <b>Varonis</b>. Shawn spent six years configuring CMMC environments for defense industrial base customers, three years inside Microsoft on the Purview/Defender/Sentinel go-to-market, and is now driving Varonis&#39;s AI security platform, Atlas. His central argument, that we&#39;ve entered a &quot;multi-AI era&quot; analogous to the multi-cloud explosion of fifteen years ago, and that the market has over-pivoted on AISPM while leaving guardrails, pen-testing, and runtime enforcement underbuilt, is the lens this newsletter uses to read the news. <i>[</i><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/aispm-isnt-enough-how-to-apply-zero-trust-to-ai-agents?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">⚡ TL;DR for Busy Readers</h2><div class="codeblock"><pre><code>This week’s attacks didn’t break systems — they used them


🔑 AI gateways are Tier-0 secrets stores. LiteLLM&#39;s litellm_credentials table holds enterprise cloud provider keys, treat every AI proxy as you would your IAM root, and rotate now if you ran a vulnerable build.  

🧬 &quot;Agent identity&quot; just became a procurement category. Google Cloud Next &#39;26 introduced Agent Identity, Agent Gateway, and Model Armor primitives, IAM roadmaps without scoped non-human identity will fall behind in 2026.  

🏗️ AISPM alone is not an AI security program. Shawn Hays argues the market has over-pivoted on posture and visibility while leaving guardrails, pen-testing, and runtime monitoring underbuilt, close the gap before regulators do.  

🔗 Vendor-environment access is the breach pattern of the quarter. Anthropic Mythos, Citizens/Frost, and the Anthropic contractor incident all share the same root cause, third-party identity hygiene that doesn&#39;t match the sensitivity of what those vendors can reach. 

🛠️ Edge persistence outlasts patching. FIRESTARTER on Cisco firewalls and the April 24 KEV additions (SimpleHelp, Samsung MagicINFO, D-Link) prove that &quot;we patched, so we&#39;re clean&quot; is no longer a defensible posture for hybrid cloud environments.</code></pre></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="this-weeks-security-news">📰 <b>THIS WEEK&#39;S TOP SECURITY HEADLINES</b></h2><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-lite-llm-sql-injection-cve-202642"><b> 1. LiteLLM SQL Injection (CVE-2026-42208) Exploited Within 36 Hours: AI Gateway Becomes Cloud-Account-Class Risk</b></h3><p class="paragraph" style="text-align:left;"><b>What Happened.</b> A pre-authentication SQL injection in BerriAI&#39;s LiteLLM (CVSS 9.3) was indexed in the GitHub Advisory Database on April 24 and saw its first observed exploitation attempt on April 26 at 16:17 UTC, roughly 36 hours later. The flaw concatenates the Authorization Bearer value into a query without parameterization, letting unauthenticated attackers run arbitrary SQL against the PostgreSQL backend. Sysdig observed targeted UNION-based payloads from German-hosted IPs (AS200373) hitting precisely the three highest-value tables: <span style="color:rgb(24, 128, 56);">LiteLLM_VerificationToken</span> (virtual API keys + master key), <span style="color:rgb(24, 128, 56);">litellm_credentials</span> (stored OpenAI/Anthropic/Bedrock provider credentials), and <span style="color:rgb(24, 128, 56);">litellm_config</span> (environment variables). Affected versions: 1.81.16 through 1.83.6. Fixed in 1.83.7-stable.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters.</b> LiteLLM has 45,000+ GitHub stars and is widely deployed as the AI gateway in front of multi-provider LLM architectures. A single <span style="color:rgb(24, 128, 56);">litellm_credentials</span> row can hold an OpenAI org key with five-figure monthly spend, an Anthropic console key with workspace admin rights, and an AWS Bedrock IAM credential, meaning the blast radius is closer to a cloud account compromise than a typical web SQLi. Three takeaways: (1) inventory every AI gateway, proxy, and middleware tier and treat them as Tier-0 secrets stores, not developer convenience tooling; (2) any internet-facing LiteLLM instance running a vulnerable version during the exposure window should be assumed compromised; rotate every key and audit upstream provider billing; (3) the operator-grade exploitation (Prisma schema awareness, schema-aware column-count enumeration) means GHSA-only critical advisories now warrant KEV-level urgency.</p><p class="paragraph" style="text-align:left;">🔎 <b>Sources:</b><a class="link" href="https://www.sysdig.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow"> Sysdig analysis</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-git-hub-rce-via-single-git-push-c"><b>2. GitHub RCE via Single Git Push (CVE-2026-3854): Wiz Discloses Cross-Tenant Risk</b></h3><p class="paragraph" style="text-align:left;"><b>What Happened.</b> On April 28, GitHub and Wiz coordinated disclosure on CVE-2026-3854, a CVSS 8.7 command injection in GitHub&#39;s internal git push pipeline. By chaining three injections through unsanitized push option values, an authenticated user with push access could override the rails environment, redirect the custom hooks directory, and trigger path traversal via <span style="color:rgb(24, 128, 56);">repo_pre_receive_hooks</span> to execute arbitrary commands as the git user (with cross-tenant blast radius on shared storage). <a class="link" href="https://GitHub.com?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">GitHub.com</a> was patched within two hours of Wiz&#39;s report; per CISO Alexis Wales, ~88% of GHES instances were vulnerable at disclosure. The bug was discovered using AI-assisted reverse engineering (IDA MCP).</p><p class="paragraph" style="text-align:left;"><b>Why It Matters.</b> Two threads to track. Operationally, any GitHub Enterprise Server instance must be on 3.19.3 or later. Wiz called the exploit &quot;remarkably easy.&quot; Architecturally, the lesson is that when multiple services in different languages pass data through a shared internal protocol, the assumptions each service makes about that data become a critical attack surface. It&#39;s the same pattern that has haunted ingress-nginx and other shared-data systems. This is also the third notable GitHub incident in a single week (alongside the merge queue regression of April 22–23 and an April 27 search outage), which is putting platform-dependency assumptions under stress for compliance teams.</p><p class="paragraph" style="text-align:left;">🔎 <b>Sources:</b><a class="link" href="https://www.wiz.io/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow"> Wiz Research</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-google-cloud-next-26-wiz-integrat"><b>3. Google Cloud Next &#39;26: Wiz Integration Goes Deep, Agentic Defense Lands</b></h3><p class="paragraph" style="text-align:left;"><b>What Happened.</b> Google Cloud Next &#39;26 ran April 22 in Las Vegas with a security agenda that, post-Wiz acquisition, finally looked unified. Headline announcements: three new Google Security Operations agents (Threat Hunting, Detection Engineering, Third-Party Context); Wiz Defend detections natively forwarded to Google SecOps and Mandiant Threat Defense; expanded Wiz coverage to Databricks, AWS AgentCore, Azure Copilot Studio, Salesforce Agentforce, Cloudflare AI Security for Apps, and Vercel; agent-governance primitives (Agent Identity, Agent Gateway, Model Armor integration); reCAPTCHA reborn as Google Cloud Fraud Defense; and KMS Quantum Safe Key Imports in preview. Google&#39;s M-Trends 2026 data claims initial-access-to-handoff time has collapsed from 8 hours three years ago to 22 seconds today.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters.</b> Two structural takeaways. First, &quot;agent identity&quot; has moved from concept to procurement category: Agent Identity, Agent Gateway, and Model Armor sketch the primitives every enterprise will need as autonomous agents proliferate inside production. Second, the Wiz/Google SecOps integration is meaningful but more incremental than secondary coverage suggests. Google&#39;s own language is careful (&quot;updated how we integrate&quot;) rather than fully native. Custom parsing, normalization, and SOAR content sitting between Wiz and Chronicle UDM today is not automatically obsolete. CISOs should ask vendors specifically what changes versus what&#39;s marketing gloss. Third, the SCC Standard tier now bundles posture, compliance, and vulnerability management; worth a hard look for teams paying separately today.</p><p class="paragraph" style="text-align:left;">🔎 <b>Sources:</b><a class="link" href="https://cloud.google.com/blog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow"> Google Cloud Blog</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-service-now-closes-775-b-armis-ac"><b>4. ServiceNow Closes $7.75B Armis Acquisition, Reshaping Asset-Centric Security</b></h3><p class="paragraph" style="text-align:left;"><b>What Happened.</b> ServiceNow completed its all-cash $7.75 billion acquisition of cyber exposure management vendor Armis on April 20, six months ahead of the originally guided H2 2026 close. Together with the pending Veza identity acquisition, ServiceNow says the combination will more than triple its addressable market for security and risk solutions, embedding real-time asset discovery across IT, OT, IoT, medical devices, &quot;physical AI,&quot; and cloud directly into the ServiceNow platform.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters.</b> This is a structural bet that the next decade of enterprise security runs through asset-and-identity context, not more detection. For cloud security leaders: (1) ITSM-native CMDBs are about to absorb cyber asset intelligence, which will pressure standalone CAASM tooling and reshape how exposures get prioritized; (2) the OT/IoT/medical visibility coming with Armis pulls non-IT assets into the same pane of glass as cloud workloads (meaningful for healthcare, manufacturing, and CNI buyers running hybrid estates); (3) for CISOs running ServiceNow as the system of record, the integration roadmap is now the ceiling on how fast you can collapse asset, vulnerability, and exposure tools. Plan for a 12–18 month integration window before depth catches up to the marketing.</p><p class="paragraph" style="text-align:left;">🔎 <b>Sources:</b><a class="link" href="https://newsroom.servicenow.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow"> ServiceNow Newsroom</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-anthropic-investigates-unauthoriz"><b>5. Anthropic Investigates Unauthorized Access to &quot;Mythos&quot; Cyber Model via Vendor Environment</b></h3><p class="paragraph" style="text-align:left;"><b>What Happened.</b> Bloomberg reported on April 21 that a small Discord group of AI enthusiasts gained unauthorized access to Anthropic&#39;s Claude Mythos Preview, the vulnerability-discovery model restricted to Project Glasswing partners (Apple, Microsoft, Cisco, Amazon, Mozilla, several major banks, and reportedly the NSA). The group leveraged credentials from a third-party Anthropic contractor and guessed the model&#39;s endpoint URL based on naming-convention knowledge, gaining access on April 7, the same day Glasswing was publicly announced. Anthropic confirmed the investigation and characterized the access as scoped to a third-party vendor environment.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters.</b> Strip away the AI framing and this is a textbook contractor-credential-meets-predictable-naming-convention failure. Lessons: (1) third-party vendor environments holding access to your most sensitive systems need the same identity rigor as your own production: scoped credentials, short-lived tokens, no shared environments; (2) predictable naming conventions for staging, preview, and unreleased resources are an under-appreciated reconnaissance surface; (3) controlled-distribution governance for dual-use AI capability will keep failing in similar ways unless the access control layer matches the model&#39;s sensitivity. With OpenAI&#39;s GPT-5.4-Cyber and Google&#39;s Big Sleep operating in similar territory, expect more of these incidents, and expect frontier-AI access controls to become a board-level question for any organization participating in these partner programs.</p><p class="paragraph" style="text-align:left;">🔎 <b>Sources:</b><a class="link" href="https://techcrunch.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow"> TechCrunch</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="6-cisa-ncsc-firestarter-implant-sur"><b>6. CISA & NCSC: FIRESTARTER Implant Survives Patches on Cisco Firewalls</b></h3><p class="paragraph" style="text-align:left;"><b>What Happened.</b> On April 23, CISA and the UK NCSC published a joint malware analysis report on FIRESTARTER, a custom Linux ELF backdoor found on a U.S. federal civilian agency&#39;s Cisco Firepower device running ASA software. Tracked to UAT-4356 (the same cluster behind ArcaneDoor), the implant was deployed in September 2025 via CVE-2025-20333 and CVE-2025-20362, and crucially persisted through the patches the agency later applied. CISA updated Emergency Directive 25-03 the same day, requiring federal agencies to collect device core dumps. Cisco recommends full reimaging; only a hard power cycle clears the persistence mechanism.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters.</b> &quot;We patched, so we&#39;re clean&quot; no longer holds for any organization that ran an internet-exposed ASA between September 2025 and patching. FIRESTARTER hooks into LINA, modifies the boot file, and re-launches itself on signal. For hybrid cloud architects specifically, these devices typically terminate site-to-site VPNs into AWS/Azure/GCP and house the credentials, certificates, and routing trust that connect on-prem to cloud workloads. A compromised firewall is also a compromised cloud egress path. Concrete actions: (1) treat any device exposed during the September 2025 window as compromised regardless of patch state; (2) plan reimaging, not patching, and rotate every credential, certificate, and key that touched the box, including cloud-side IAM roles or service account credentials accessible from those tunnels.</p><p class="paragraph" style="text-align:left;">🔎 <b>Sources:</b><a class="link" href="https://www.cisa.gov/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow"> CISA AR26-113A</a></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="whats-missing-from-most-ai-security"><b>What&#39;s Missing From Most AI Security Programs</b></h3><p class="paragraph" style="text-align:left;">The dominant question Shawn Hays hears at RSA from CISOs is some version of <i>&quot;I bought one AI security tool, why doesn&#39;t it cover my whole estate?&quot;</i> His answer is uncomfortable: most enterprises are already in the <b>multi-AI era</b>, and most AI security purchases were made for a single-vendor world that no longer exists. Copilot was the beta. Then Copilot Studio agents. Then Atlassian shipped Jira agents. Then Salesforce Agentforce. Then a business unit picked Bedrock for a specific use case, another picked Foundry for another, and somewhere a developer wired in an MCP server pointing at a Hugging Face model. Now the AISPM tool that scopes only to Microsoft prompts and responses sees a fraction of the surface.</p><p class="paragraph" style="text-align:left;">Shawn frames this as a direct parallel to the multi-cloud transition fifteen years ago: every booth at RSA 2010 was selling multi-cloud security because organizations had lifted-and-shifted to &quot;this place and that place and that place&quot; without knowing how to protect it. We are now living the same pattern with AI, and the program design that worked for a single-stack AI strategy is not going to carry forward. But the bigger gap, in Shawn&#39;s view, is not breadth. It&#39;s <b>depth</b>. Most programs have visibility and posture management, and almost nothing else. The rest of this newsletter walks through the eight pillars he uses to frame an enterprise-grade AI security program, and why <b>AISPM and visibility alone are the wrong place to stop</b>.</p><hr class="content_break"><h2 class="heading" style="text-align:left;"><b>Featured Experts This Week </b>🎤</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/shawn-rosco-hays/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow"><b>Shawn Hays</b></a> ex-Product Marketing Manager for Microsoft Applications & AI Security Solutions at <b>Varonis</b>.</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><b>AISPM (AI Security Posture Management).</b> Continuous discovery, posture assessment, and risk prioritization across AI components such as models, agents, MCP servers, code repos, and datasets. Analogous to CSPM but for AI estates.</p></li><li><p class="paragraph" style="text-align:left;"><b>DSPM (Data Security Posture Management).</b> Continuous discovery and risk assessment of sensitive data across cloud and SaaS, including who has access and how it&#39;s classified.</p></li><li><p class="paragraph" style="text-align:left;"><b>ITDR (Identity Threat Detection and Response).</b> Behavioral monitoring of identities (both human and non-human) for compromise indicators like privilege escalation, anomalous logins, and lateral movement.</p></li><li><p class="paragraph" style="text-align:left;"><b>CIEM (Cloud Infrastructure Entitlement Management).</b> Visibility and right-sizing of permissions for identities accessing cloud resources.</p></li><li><p class="paragraph" style="text-align:left;"><b>AI Bill of Materials (AI BoM).</b> A manifest of components inside an AI system (models, datasets, MCP servers, prompts, tools, dependencies). Analogous to SBOM for software supply chain.</p></li><li><p class="paragraph" style="text-align:left;"><b>MCP (Model Context Protocol).</b> The emerging standard for how agents call external tools and data sources. An MCP server exposes capabilities (e.g., &quot;read this database,&quot; &quot;call this API&quot;) that an agent can invoke at runtime.</p></li><li><p class="paragraph" style="text-align:left;"><b>RAG AI (Retrieval-Augmented Generation).</b> AI systems like Copilot that ground responses in data the prompting user already has access to, via token-exchange checks at query time. Permissions are inherited from the user.</p></li><li><p class="paragraph" style="text-align:left;"><b>Guardrails.</b> Runtime controls that block an agent from taking specific actions or producing specific outputs. Input guardrails (e.g., &quot;reject prompt-injection attempts&quot;), output guardrails (e.g., &quot;never emit PHI&quot;).</p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <b><a class="link" href="https://links.cloudsecuritypodcast.tv/orca-cloud-security-live-2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">Orca Security</a></b></p><p class="paragraph" style="text-align:center;">Orca Security is hosting Cloud Security LIVE, a half-day virtual summit on Tuesday, May 12th. Join CISOs, security co-founders, and practitioners for unfiltered insight real stories and strategies from people securing the world&#39;s most complex cloud environments. </p><p class="paragraph" style="text-align:left;">Sessions include:</p><ul><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);font-family:Arial, Helvetica, sans-serif;font-size:small;"><b>The new standard for resilience: zero-breach to zero-impact</b></span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);font-family:Arial, Helvetica, sans-serif;font-size:small;"><b>AI on both sides: securing models and APIs while using AI to defend your cloud</b></span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);font-family:Arial, Helvetica, sans-serif;font-size:small;"><b>Mastering 3rd-party and supply chain risk</b></span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);font-family:Arial, Helvetica, sans-serif;font-size:small;"><b>Security leadership panel on AI, risk, and driving change</b></span></p><p class="paragraph" style="text-align:left;"><br><span style="color:rgb(34, 34, 34);font-family:Arial, Helvetica, sans-serif;font-size:small;"><i>Join for a chance to win* a 64GB Beelink AI PC. *US-based attendees only.</i></span></p></li></ul><p class="paragraph" style="text-align:center;"><a class="link" href="https://links.cloudsecuritypodcast.tv/orca-cloud-security-live-2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">Register Today</a></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-the-multi-ai-era-why-it-changes-p"><b>1. The &quot;Multi-AI Era&quot;: Why It Changes Program Design</b></h3><p class="paragraph" style="text-align:left;">Shawn opens with a frame that anyone who lived through 2010-era multi-cloud chaos will recognize immediately:</p><p class="paragraph" style="text-align:left;"><i>&quot;I think we are now entering this multi-AI era where no longer is an organization, an enterprise, sophisticated organization, just using copilot. They&#39;re using all these different pieces.&quot; </i><b>Shawn Hays, Varonis</b></p><p class="paragraph" style="text-align:left;">The implication for security architecture is direct. A program that scopes only to Microsoft Copilot&#39;s prompts and responses will not see Jira agents, Agentforce, Bedrock pro-code agents, or MCP servers pulling in third-party models. Shawn describes a recurring conversation with enterprises who bought a single-vendor AI security tool early, and then discovered, as they matured, that &quot;the entirety of the AI that they have, or maybe the AI they&#39;re going to have&quot; exceeds what one tool can cover. This is the AISPM equivalent of early CSPM tools that only saw AWS: useful, but incomplete the moment a second cloud showed up.</p><p class="paragraph" style="text-align:left;"><b>What to do about it.</b> When evaluating an AI security platform, Shawn&#39;s recommended buyer&#39;s question is: <i>&quot;Can it protect all the AI I&#39;ve built today, all the AI I plan to build tomorrow, and all the AI I don&#39;t even know about?&quot;</i> If the answer scopes to a single hyperscaler or a single AI vendor, the tool is solving a 2024 problem.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-the-eight-pillars-aispm-is-necess"><b>2. The Eight Pillars: AISPM Is Necessary, Not Sufficient</b></h3><p class="paragraph" style="text-align:left;">Shawn argues the market has <b>over-pivoted on AISPM and visibility</b>. It&#39;s the same pattern Varonis saw in DSPM five years ago, where customers bought posture tools and then realized they had no enforcement layer. The full program he describes covers eight areas; the pillars he emphasizes most:</p><ol start="1"><li><p class="paragraph" style="text-align:left;"><b>Inventory and observability</b> across every layer of the AI stack, models, MCP servers, agents, services, code repos, even Jupyter Notebooks (where he&#39;s seen developers stash secrets for convenience). Continuous, not point-in-time.</p></li><li><p class="paragraph" style="text-align:left;"><b>AISPM</b>, misconfigurations, vulnerabilities, posture drift across that inventory.</p></li><li><p class="paragraph" style="text-align:left;"><b>AI Bill of Materials</b> for both internal-built systems and third-party AI services. If a model has a CVE in NIST&#39;s NVD, you need to know it&#39;s in your stack, and you need to know it&#39;s in Grammarly&#39;s stack too.</p></li><li><p class="paragraph" style="text-align:left;"><b>Pen-testing of agents</b> before they go live. As Shawn puts it, you &quot;need to put it through the ringer… both from a jailbreaking, poisoning [perspective] but also very run-of-the-mill interactions to see how it&#39;s gonna behave.&quot;</p></li><li><p class="paragraph" style="text-align:left;"><b>Runtime guardrails</b> that block specific behaviors, input guardrails for prompt injection, output guardrails for sensitive-data emission.</p></li><li><p class="paragraph" style="text-align:left;"><b>Compliance monitoring</b> mapped to frameworks like NIST AI RMF that re-evaluate as the agent changes.</p></li><li><p class="paragraph" style="text-align:left;"><b>Third-party AI risk management</b> including AI BoM ingestion from vendors.</p></li><li><p class="paragraph" style="text-align:left;"><b>Continuous monitoring</b> across the full lifecycle, not just deployment.</p></li></ol><p class="paragraph" style="text-align:left;">The strategic insight underneath this list:</p><p class="paragraph" style="text-align:left;"><i>&quot;They have great visibility, they have inventory, they know every piece of their AI system, but they really have no way of preventing that agent or AI system from going off the rails.&quot; - </i><b>Shawn Hays, Varonis</b></p><p class="paragraph" style="text-align:left;">This is the most actionable critique in the conversation. Many enterprises in 2026 will pass an internal audit of their AI security program, they have the dashboards, they have the inventory, they have CVE alerting on models, and still have nothing in front of an agent that would stop it from doing something stupid in production. The pen-testing-and-guardrails layer is where most programs are thinnest.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-identity-is-woven-through-everyth"><b>3. Identity Is Woven Through Everything: Why Native Tools Won&#39;t Carry You</b></h3><p class="paragraph" style="text-align:left;">Shawn is precise about how identity sprawls across an agentic estate:</p><p class="paragraph" style="text-align:left;"><i>&quot;You&#39;ve got identities for the folks that can access data in the cloud store… you have the identity of the agent, you have identity of the builders, like the people making these agents… if they&#39;re using some sort of Bitbucket, GitHub, you have identities for those that can have access to the code repos. It&#39;s like there&#39;s an identity layer woven throughout.&quot; - </i><b>Shawn Hays, Varonis</b></p><p class="paragraph" style="text-align:left;">Each of those identity surfaces needs ITDR coverage. Not just the cloud architect (with normal CIEM/ITDR for elevated privileges and lateral movement), but the <b>agent identity itself</b>, alerting on agents that suddenly gain entitlements, access resources they typically don&#39;t, or &quot;feverishly&quot; light up after a period of dormancy.</p><p class="paragraph" style="text-align:left;">Ashish pushes on the obvious counter, <i>&quot;I have an E5 license, the native services cover this, right?&quot;</i>, and Shawn&#39;s response is the most quotable piece of practical guidance in the episode:</p><p class="paragraph" style="text-align:left;"><i>&quot;Native tools are really good about solving some of the native challenges. But then once you start broadening the scope and the aperture, that&#39;s when it gets a little tough.&quot; - </i><b>Shawn Hays, Varonis</b></p><p class="paragraph" style="text-align:left;">The example he uses is HIPAA. Microsoft Purview will do an excellent job preventing PHI exfiltration via labeled data and DLP policies, <i>inside the Microsoft tenant</i>. The moment an AWS Bedrock agent calls an EHR system through an MCP server, that protection envelope ends, but the regulator&#39;s expectation does not. For CISOs in regulated industries, this is the architectural argument for a cross-stack AI security platform regardless of how aligned your primary cloud is.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-the-connector-ecosystem-is-quiet-"><b>4. The Connector Ecosystem Is Quiet Third-Party Risk</b></h3><p class="paragraph" style="text-align:left;">The connector ecosystem is the part of the AI security problem most enterprises haven&#39;t budgeted for. Shawn&#39;s example: turning on the Salesforce connector in Microsoft 365 Copilot doesn&#39;t require deploying a &quot;highly configured, sophisticated pro-code AI solution.&quot; It&#39;s a checkbox. But the moment that connector is on, Copilot is grounded in Salesforce data via the same can-access model, and any data permission misconfiguration in Salesforce now flows into Copilot output.</p><p class="paragraph" style="text-align:left;">This is why <b>DSPM and AI security are intertwined</b>, not adjacent. RAG AI inherits user permissions; if those permissions are over-permissive, the AI is over-permissive. Shawn&#39;s guidance for Copilot governance specifically (and it transfers to any RAG-based AI tool in your estate):</p><ol start="1"><li><p class="paragraph" style="text-align:left;">Understand what data Copilot can access.</p></li><li><p class="paragraph" style="text-align:left;">Test whether existing classification and labeling actually works.</p></li><li><p class="paragraph" style="text-align:left;">Define how <i>new</i> data will be classified and labeled going forward.</p></li><li><p class="paragraph" style="text-align:left;">Apply zero trust at runtime: monitor how Copilot interacts with data even after permissions are right-sized.</p></li></ol><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-zero-trust-applied-to-the-whole-c"><b>5. Zero Trust Applied to the Whole Chain, Not Just the User</b></h3><p class="paragraph" style="text-align:left;">The strongest architectural insight in the conversation is Shawn&#39;s reframing of zero trust as <i>applied to every actor in an agentic transaction simultaneously</i>:</p><p class="paragraph" style="text-align:left;"><i>&quot;I need to not trust that agent. I need to even not trust the user prompting… I need to also not trust the cloud architect that&#39;s over that maybe data SQL database that&#39;s sitting in Azure. I wanna apply zero trust to that entire chain, and the reason being [is] data.&quot; - </i><b>Shawn Hays, Varonis</b></p><p class="paragraph" style="text-align:left;">In a healthcare patient-facing agent example, this means: don&#39;t trust the prompt (it might contain a jailbreak embedded inside legitimately-ingested PHI), don&#39;t trust the agent&#39;s downstream actions (it might write PHI to the wrong table), don&#39;t trust the Azure architect&#39;s identity (it might be compromised), and don&#39;t trust the cloud configuration (misconfig could leak data via SQL). Each link is a separate enforcement point with separate controls.</p><p class="paragraph" style="text-align:left;">This is also the lens that makes this week&#39;s news cohere. The Anthropic Mythos incident violated trust at the contractor link. FIRESTARTER violated trust at the network appliance link. LiteLLM violated trust at the AI gateway link. None of these were AI-specific in the bug-class sense. They were identity-and-access failures dressed up in different costumes.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="the-ron-burgundy-analogy-why-data-a"><b>The &quot;Ron Burgundy&quot; Analogy: Why Data and Identity Will Outlast Every AI Architecture</b></h3><p class="paragraph" style="text-align:left;">When Ashish asks what controls will stand the test of time as 2027 and 2028 AI architectures arrive, Shawn lands on an analogy worth keeping:</p><p class="paragraph" style="text-align:left;"><i>&quot;At least the AI we have now, and maybe for the next five years… AI is Ron Burgundy. It&#39;s only gonna read what&#39;s on the teleprompter. So if we&#39;re looking at identity solutions and data security… it&#39;s like, how are we gonna make sure that the right data shows up on the teleprompter?&quot; - </i><b>Shawn Hays, Varonis</b></p><p class="paragraph" style="text-align:left;">The point is durable: whatever the next-generation agent architecture looks like, it will still be reading from a context window, and that context window is still being populated by data systems and identity decisions that you control. <b>Right-size data access, instrument identity at every layer, and apply zero trust to the chain.</b> Do that, and you&#39;ll be in a defensible position regardless of what AI architecture wins next.</p><h3 class="heading" style="text-align:left;" id="ashishs-frame-the-horse-has-left-th"><b>Ashish&#39;s Frame: The Horse Has Left the Barn</b></h3><p class="paragraph" style="text-align:left;">Ashish makes the operational counterpoint that should sit with every CISO reading this:</p><p class="paragraph" style="text-align:left;"><i>&quot;With AI, that horse has left the barn.&quot; - </i><b>Ashish Rajan, Cloud Security Podcast</b></p><p class="paragraph" style="text-align:left;">Data classification programs that &quot;never had the rubber hit the road&quot; (Ashish&#39;s words from his own CISO experience) are no longer a deferrable problem. The assumption that confidential data stays inside organizational boundaries is broken the moment an agent reaches into Salesforce, Jira, or a third-party MCP server. The teams that get ahead in 2026 are the ones treating data classification, identity hygiene, and access right-sizing as the AI security work, because, per Shawn&#39;s argument, that <i>is</i> the AI security work for the dominant RAG-based AI patterns.</p><h3 class="heading" style="text-align:left;" id="practical-application-a-3060-minute"><b>Practical Application: A 30–60 Minute Action List</b></h3><p class="paragraph" style="text-align:left;">Drawing from Shawn&#39;s eight pillars and this week&#39;s news, the immediate work for cloud security teams:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Inventory every AI gateway, proxy, and middleware in your estate</b> (LiteLLM, Portkey, custom OpenAI proxies, etc.) and treat their secrets stores as Tier-0. If you ran a vulnerable LiteLLM build, rotate now.</p></li><li><p class="paragraph" style="text-align:left;"><b>Map your full multi-AI footprint</b> (Copilot, Copilot Studio, Foundry, Bedrock, Agentforce, Jira agents, custom agents, MCP servers, and any third-party SaaS using AI as a feature). Score each for AI BoM availability.</p></li><li><p class="paragraph" style="text-align:left;"><b>Apply ITDR to non-human identities</b> (agents and service principals), not just to humans. Anomalous agent behavior should page the SOC the same way anomalous human behavior does.</p></li><li><p class="paragraph" style="text-align:left;"><b>Audit your connector ecosystem.</b> Every cross-product connector (Copilot ↔ Salesforce, etc.) inherits permissions. Run a DSPM/AISPM pass on the data side of each connector.</p></li><li><p class="paragraph" style="text-align:left;"><b>Add pen-testing and guardrails to your agent SDLC.</b> If your AI program documentation only describes posture and inventory, it&#39;s incomplete.</p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>📚 RELATED RESOURCES 🎧</b></h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.varonis.com/products/atlas?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">Varonis Atlas overview</a>: Varonis&#39;s AI security platform</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.varonis.com/blog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">Varonis blog: Applying Zero Trust to MCP Servers</a>: Shawn&#39;s recent write-up referenced in the conversation</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.sysdig.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">Sysdig: CVE-2026-42208 LiteLLM Analysis</a>: exploitation timeline and detection guidance</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.wiz.io/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">Wiz Research: GitHub CVE-2026-3854</a>: full technical disclosure</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cisa.gov/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">CISA Emergency Directive 25-03 (FIRESTARTER)</a>: federal guidance applicable to all enterprises running ASA/FTD</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.nist.gov/itl/ai-risk-management-framework?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">NIST AI Risk Management Framework (AI RMF)</a>: compliance reference for AI security programs</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://learn.microsoft.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">Microsoft Purview + Copilot governance documentation</a>: native controls baseline for the Microsoft stack</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloud.google.com/blog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">Google Cloud Next &#39;26 security keynote recap</a>: Agent Identity, Agent Gateway, Model Armor announcements</p></li></ul><h3 class="heading" style="text-align:left;" id="podcast-episode"><b>Podcast Episode</b></h3><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/aispm-isnt-enough-how-to-apply-zero-trust-to-ai-agents?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast -Full Episode </a><b>with Shawn Hays</b>- Complete transcript and audio for this week&#39;s featured conversation</p></li></ul><hr class="content_break"><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔<b> </b>If you had to pick one (AISPM, runtime guardrails, or AI-aware ITDR), which is the biggest gap in your program right now?<br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=an-ai-gateway-exploited-in-36-hours" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=625d8342-7c4d-423f-85f2-5940a3807506&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🚨 Vercel OAuth Attack | How AI Is Breaking Cloud Security (What CISOs Must Do Now)</title>
  <description>The Vercel OAuth supply chain breach shows how a single AI tool with over-permissioned access can cascade into enterprise-wide credential exposure. Elad Koren from Palo Alto Networks’ Cortex Cloud team joins Cloud Security Podcast to explain why the CNAPP of 2026 must be agentic-first and why organizations have less than 25 minutes to respond before an active threat exfiltrates data.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f58afa8e-b3c8-4000-aaf8-0b416bdcfaaf/Screenshot_2026-04-22_at_11.36.55_PM.png" length="1654656" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/vercel-oauth-attack-ai-breaking-cloud-security</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/vercel-oauth-attack-ai-breaking-cloud-security</guid>
  <pubDate>Wed, 22 Apr 2026 22:38:26 +0000</pubDate>
  <atom:published>2026-04-22T22:38:26Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><h2 class="heading" style="text-align:left;" id="hello-from-the-cloudverse"><span style="background-color:#28EEDA;"><b>Hello from the Cloud-verse!</b></span></h2><p class="paragraph" style="text-align:left;">This week’s Cloud Security Newsletter topic<b>: </b><b>Agentic Cloud Security: Why the CNAPP Must Evolve Before Your Adversaries Do</b><b> </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" rel="noopener noreferrer nofollow">(continue reading)</a> </p><hr class="content_break"><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://links.cloudsecuritypodcast.tv/orca-cloud-security-live-2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now"><span class="button__text" style=""> This issue is sponsored by Orca Security </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f58afa8e-b3c8-4000-aaf8-0b416bdcfaaf/Screenshot_2026-04-22_at_11.36.55_PM.png?t=1776897468"/></a><div class="image__source"><span class="image__source_text"><p><i>This image was generated by AI. It&#39;s still experimental, so it might not be a perfect match!</i></p></span></div></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;">This week’s uncomfortable truth:</p><p class="paragraph" style="text-align:left;">Attackers are no longer breaking into your systems.<br>They are operating inside them using your tools, your APIs, and your trust relationships.</p><ul><li><p class="paragraph" style="text-align:left;">APT41 is stealing IAM credentials using cloud metadata APIs</p></li><li><p class="paragraph" style="text-align:left;">Vercel was breached without a vulnerability - just OAuth trust abuse</p></li><li><p class="paragraph" style="text-align:left;">Microsoft Teams is being used to impersonate IT helpdesks</p></li><li><p class="paragraph" style="text-align:left;">Cisco ISE can now be taken over with read-only credentials</p></li></ul><p class="paragraph" style="text-align:left;">And according to Palo Alto Networks Research: It’s taking <b>~25 minutes from breach to data exfiltration</b>. <i>[</i><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/the-rise-of-agentic-cloud-security-code-to-cloud-shrinks-to-3-days?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">⚡ TL;DR for Busy Readers</h2><div class="codeblock"><pre><code>This week’s attacks didn’t break systems — they used them


🔴 APT41 cloud credential theft: 
Winnti backdoor harvesting AWS/Azure/GCP tokens via SMTP (zero detections). Block outbound SMTP from non-mail workloads NOW  

🔑 SaaS tokens = your weakest link: 
Vercel breached via over-permissioned OAuth — API keys, GitHub &amp; NPM tokens exposed. Audit third-party OAuth access TODAY  

⚠️ Identity isn’t safe: 
Cisco ISE CVSS 9.9 flaws exploitable with read-only credentials. Patch manually — Cisco can’t do this for you  

📦 Third Party Breach risk is live ( 1yr later): 
A 2025 Salesforce compromise is still exposing new victims — including 13.5M user records and SSNs — nearly a year later.  

🤖 CNAPP model is breaking: 
25-minute breach-to-exfiltration window confirmed — human-speed response is no longer viable   </code></pre></div><hr class="content_break"><h2 class="heading" style="text-align:left;" id="this-weeks-security-news">📰 <b>THIS WEEK&#39;S TOP SECURITY HEADLINES</b></h2><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-microsoft-teams-used-for-helpdesk"><b> </b>🚨<b> 1. </b>Microsoft Teams Used for Helpdesk Impersonation Attacks</h3><h3 class="heading" style="text-align:left;" id="whats-happening">What’s happening</h3><p class="paragraph" style="text-align:left;">Microsoft has documented a nine-stage attack chain where Attackers are spinning up fake Microsoft tenants and impersonating internal IT via Teams → convincing employees to start remote sessions → then moving laterally and exfiltrating data.</p><h3 class="heading" style="text-align:left;" id="why-this-matters">Why this matters</h3><p class="paragraph" style="text-align:left;">No malware. No exploit.<br>Just <b>trusted tools used against you</b>.</p><p class="paragraph" style="text-align:left;">Your EDR sees normal activity.<br>Your users see “IT support”.</p><p class="paragraph" style="text-align:left;">This is a living-off-the-land attack that requires no malware, no CVEs, and no phishing emails. It exploits the trust users have placed in a familiar collaboration platform. Because the attacker operates from a Microsoft-issued tenant using Microsoft-sanctioned tools, most endpoint detection stacks will see Zoom-like remote access activity with no signal that anything is wrong. The cross-tenant access feature is enabled by default in most Microsoft 365 deployments and has almost certainly never been reviewed in your environment.</p><h3 class="heading" style="text-align:left;" id="what-to-do">👉 What to do</h3><p class="paragraph" style="text-align:left;">▶     <span style="color:rgb(26, 82, 118);"><b>Audit Teams external access policy immediately.  </b></span>Most organizations have never restricted cross-tenant chat. Limit it to approved domains, or disable it if not operationally required.</p><p class="paragraph" style="text-align:left;">▶     <span style="color:rgb(26, 82, 118);"><b>Establish out-of-band helpdesk verification.  </b></span>Create a verbal authentication phrase that all IT staff use before initiating remote sessions. Include this in your security awareness training.</p><p class="paragraph" style="text-align:left;">▶     <span style="color:rgb(26, 82, 118);"><b>Hunt for Rclone in your environment.  </b></span>Rclone has no legitimate enterprise use in most organizations. Its presence on an endpoint is an incident indicator.</p><p class="paragraph" style="text-align:left;">▶     <span style="color:rgb(26, 82, 118);"><b>Create a detection rule for Quick Assist sessions from external tenants.  </b></span>This pattern is unusual enough that a well-scoped rule should have near-zero false positives.</p><p class="paragraph" style="text-align:left;"><b>Sources</b>: <a class="link" href="https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"> </a><span style="color:rgb(174, 182, 191);"> </span><a class="link" href="https://www.bleepingcomputer.com/news/security/microsoft-teams-increasingly-abused-in-helpdesk-impersonation-attacks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"> BleepingComputer</a><span style="color:rgb(174, 182, 191);">  | </span><a class="link" href="https://www.csoonline.com/article/4160858/attackers-abuse-microsoft-teams-to-impersonate-the-it-helpdesk-in-a-new-enterprise-intrusion-playbook.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"> CSO Online</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-salesforce-breach-surfaces-downst">🚨<b> 2.  </b>Salesforce Breach Surfaces Downstream: McGraw-Hill 13.5M, OneDigital 28K SSNs</h3><p class="paragraph" style="text-align:left;"><b>What happened:</b></p><p class="paragraph" style="text-align:left;">A 2025 Salesforce compromise is still exposing new victims — including 13.5M user records and SSNs — nearly a year later. <i>OneDigital</i> confirmed approximately 28,414 individuals had names and SSNs exposed. <i>McGraw-Hill</i> disclosed that ShinyHunters stole and publicly leaked 13.5 million user accounts via the same underlying Salesforce breach. The gap between the original compromise and these disclosures is approaching twelve months for some affected individuals.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b></p><p class="paragraph" style="text-align:left;">The Salesforce breach itself is not the primary lesson here. The lesson is the blast radius and the disclosure lag</p><p id="what-to-do" class="paragraph" style="text-align:left;">👉 What to do</p><p class="paragraph" style="text-align:left;">▶     <span style="color:rgb(26, 82, 118);"><b>Treat CRM as tier-1 cloud infrastructure.  </b></span>Apply the same access controls, anomaly detection, and logging posture to Salesforce that you apply to your data warehouse.</p><p class="paragraph" style="text-align:left;">▶     <span style="color:rgb(26, 82, 118);"><b>Renegotiate SaaS breach notification SLAs.  </b></span>If your contracts do not specify a notification timeline for platform-level incidents, you have no contractual floor.</p><p class="paragraph" style="text-align:left;">▶     <span style="color:rgb(26, 82, 118);"><b>Backdate your investigation window.  </b></span>When a downstream notification arrives, treat the compromise date   not the notification date as your start point.</p><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-ivanti-epmm-flaw-by-sunday/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"> BleepingComputer</a> |<a class="link" href="https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"> Palo Alto Unit 42</a> |<a class="link" href="https://www.cybersecuritydive.com/news/cisa-second-critical-flaw-ivanti-epmm-exploited/817080/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"> Cybersecurity Dive</a> |<a class="link" href="https://www.rapid7.com/blog/post/etr-critical-ivanti-endpoint-manager-mobile-epmm-zero-day-exploited-in-the-wild-eitw-cve-2026-1281-1340/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"> Rapid7</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-apt-41-deploys-zero-detection-clo"><b>☁️ 3. </b>⚡ APT41 Deploys Zero-Detection Cloud Credential Backdoor to Harvest Credentials Across AWS, Azure, GCP</h3><p class="paragraph" style="text-align:left;"><b>What happened:</b></p><p class="paragraph" style="text-align:left;">APT41 is harvesting credentials from AWS, Azure, and GCP using metadata APIs and hiding traffic in SMTP.</p><p class="paragraph" style="text-align:left;">Zero detections at time of discovery.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b><br>This is the most cloud-native credential theft operation we have seen from a state-sponsored actor. The backdoor does not exploit a vulnerability in your cloud environment it queries the same metadata APIs your applications use legitimately. </p><p class="paragraph" style="text-align:left;">On AWS it hits the IMDS endpoint at 169.254.169.254 for IAM role credentials. On Azure it pulls managed identity tokens. On GCP it requests service account tokens. It also sends periodic UDP broadcast beacons on port 6006 for peer-to-peer lateral coordination between compromised hosts, meaning the C2 infrastructure can go dark while the campaign continues to propagate internally.</p><p class="paragraph" style="text-align:left;"> This attack:</p><ul><li><p class="paragraph" style="text-align:left;">Uses legitimate APIs</p></li><li><p class="paragraph" style="text-align:left;">Avoids HTTP/DNS monitoring</p></li><li><p class="paragraph" style="text-align:left;">Blends into normal cloud behaviour</p></li></ul><p class="paragraph" style="text-align:left;">This bypasses:</p><ul><li><p class="paragraph" style="text-align:left;">EDR</p></li><li><p class="paragraph" style="text-align:left;">Signature detection</p></li><li><p class="paragraph" style="text-align:left;">Traditional network monitoring</p></li></ul><p class="paragraph" style="text-align:left;">This is a <b>cloud-native attack on your control plane</b></p><p class="paragraph" style="text-align:left;"><b>👉 What to do</b></p><p class="paragraph" style="text-align:left;">▶     <span style="color:rgb(26, 82, 118);"><b>Block or alert on outbound SMTP (port 25) from non-mail workloads.  </b></span>This is anomalous in cloud compute environments and should have very low false positives.</p><p class="paragraph" style="text-align:left;">▶     <span style="color:rgb(26, 82, 118);"><b>Alert on unusual reads of cloud credential files  </b></span>from non-SDK processes: ~/.aws/credentials, ~/.azure/ profile directories, GCP application default credential paths.</p><p class="paragraph" style="text-align:left;">▶     <span style="color:rgb(26, 82, 118);"><b>Enforce IMDSv2 on AWS and equivalent IMDS hardening on Azure/GCP.  </b></span>This limits the blast radius of a compromised instance by requiring session-oriented token requests.</p><p class="paragraph" style="text-align:left;">▶     <span style="color:rgb(26, 82, 118);"><b>Hunt for stripped, statically linked ELF binaries in /tmp and /var/tmp.  </b></span>These are not characteristic of legitimate cloud workloads.</p><p class="paragraph" style="text-align:left;">▶     <span style="color:rgb(26, 82, 118);"><b>Alert on UDP broadcast traffic to port 6006 from compute instances.  </b></span>This is the lateral movement beacon used by this implant.</p><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://blog.openvpn.net/this-week-in-cybersecurity-adobes-four-month-zero-day?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"> </a><a class="link" href="https://www.darkreading.com/cloud-security/apt41-zero-detection-backdoor-harvest-cloud-credentials?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow">Dark Reading</a><span style="color:rgb(174, 182, 191);">  | </span><a class="link" href="https://www.scworld.com/brief/winnti-backdoor-harvests-cloud-metadata-tokens?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"> SC Media</a><span style="color:rgb(174, 182, 191);">  | </span><a class="link" href="https://cybersecuritynews.com/apt41-turns-linux-cloud-servers-into-credential-theft/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"> CybersecurityNews</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-cisco-patches-four-critical-flaws">🏥<b> 4. </b>Cisco Patches Four Critical Flaws in Webex and ISE - Including Unauthenticated SSO Impersonation</h3><p class="paragraph" style="text-align:left;"><b>What happened:</b></p><p class="paragraph" style="text-align:left;">Cisco released patches for 15 vulnerabilities including four critical-severity flaws in Webex Services and Identity Services Engine.</p><p class="paragraph" style="text-align:left;">CVE-2026-20184 (CVSS 9.8) in Webex allows an unauthenticated remote attacker to impersonate any user by exploiting improper certificate validation in the SSO integration with Control Hub. Three critical ISE flaws (CVE-2026-20147, CVE-2026-20180, CVE-2026-20186, all CVSS 9.9) enable remote code execution on the underlying OS   critically, CVE-2026-20180 and CVE-2026-20186 are exploitable with nothing more than read-only administrative credentials. No active exploitation has been confirmed at time of disclosure.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b><br>The Webex SSO flaw has a manual remediation step that Cisco cannot complete on your behalf: admins must upload a new IdP SAML certificate to Webex Control Hub. In enterprises where Webex administration is delegated or outsourced, this step is highly likely to be missed. The ISE vulnerabilities carry a more severe operational implication: ISE underpins 802.1X authentication, NAC, and device trust for many large enterprises. An attacker with a compromised read-only monitoring account   a very common post-breach scenario   can achieve root code execution on your network access control infrastructure. CrowdStrike’s 2026 Global Threat Report notes that valid account abuse accounted for 35% of cloud incidents last year. These flaws make that even more dangerous.a</p><p class="paragraph" style="text-align:left;"><b>👉 What to do</b></p><p class="paragraph" style="text-align:left;">▶     <span style="color:rgb(26, 82, 118);"><b>Upload the new IdP SAML certificate to Webex Control Hub NOW  </b></span>if SSO is in use. This is your action item, not Cisco’s.</p><p class="paragraph" style="text-align:left;">▶     <span style="color:rgb(26, 82, 118);"><b>Patch ISE to fixed releases:  </b></span>3.1 P11 · 3.2 P10 · 3.3 P11 · 3.4 P6 · 3.5 P3. There are no workarounds.</p><p class="paragraph" style="text-align:left;">▶     <span style="color:rgb(26, 82, 118);"><b>Audit read-only admin account activity in ISE.  </b></span>Any anomalous activity on these accounts should be treated as a high-priority incident given the low privilege bar for exploitation.</p><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://techcrunch.com/2026/04/13/hack-at-anodot-leaves-over-a-dozen-breached-companies-facing-extortion/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"> </a><a class="link" href="https://www.securityweek.com/cisco-patches-critical-vulnerabilities-in-webex-ise/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek</a><span style="color:rgb(174, 182, 191);">  | </span><a class="link" href="https://www.csoonline.com/article/4159827/cisco-systems-issues-three-advisories-for-critical-vulnerabilities-in-webex-ise.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"> CSO Online</a><span style="color:rgb(174, 182, 191);">  | </span><a class="link" href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"> Cisco Security Advisories</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-vercel-breach-via-o-auth-supply-c"><b>5 — Vercel Breach via OAuth Supply Chain Attack</b></h3><p class="paragraph" style="text-align:left;"><b>What happened:</b></p><p class="paragraph" style="text-align:left;">On April 19, Vercel disclosed a security breach that began in February 2026 when a <a class="link" href="https://Context.ai?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow">Context.ai</a> employee’s machine was infected with Lumma Stealer malware after downloading a Roblox game exploit. The malware harvested Google Workspace credentials and OAuth tokens, which the attacker used to pivot through <a class="link" href="https://Context.ai?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow">Context.ai</a>’s AWS environment into a Vercel employee’s Google Workspace account   gaining access to Vercel’s internal systems and non-sensitive environment variables. A threat actor claiming ShinyHunters affiliation listed the stolen data for $2M on BreachForums, claiming the haul includes API keys, NPM tokens, GitHub tokens, and 580 employee records. Vercel confirmed the incident, published IOCs, and advised all customers to rotate environment variable credentials.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b><br>This breach chain required zero direct vulnerabilities in Vercel’s own code. The attack path was: infostealer → OAuth token theft → SaaS lateral movement → PaaS credential exposure. Every step exploited legitimate trust relationships between sanctioned enterprise applications. The structural problem is that a single developer using a third-party AI tool with overly permissive Google Workspace OAuth grants became the entry point for an incident that potentially affects hundreds of organizations.</p><p class="paragraph" style="text-align:left;"><b>👉 What to do</b></p><p class="paragraph" style="text-align:left;">▶     <span style="color:rgb(26, 82, 118);"><b>Audit all third-party OAuth authorizations in Google Workspace and Microsoft 365.  </b></span>Remove any app granted broad read/write access that is not formally inventoried and approved.</p><p class="paragraph" style="text-align:left;">▶     <span style="color:rgb(26, 82, 118);"><b>Add PaaS deployment platforms to your SBOM and TPRM register.  </b></span>Vercel, Netlify, Railway, Render   these are tier-1 supply chain dependencies, not external services.</p><p class="paragraph" style="text-align:left;">▶     <span style="color:rgb(26, 82, 118);"><b>Rotate all Vercel environment variables not marked as ‘sensitive’.  </b></span>Even without a direct notification, the exposure window spans February–April 2026.</p><p class="paragraph" style="text-align:left;">▶     <span style="color:rgb(26, 82, 118);"><b>Block or alert on ‘Allow All’ OAuth grants  </b></span>during enterprise onboarding of AI tools. This single permission pattern is the root cause of this incident.</p><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://www.securityweek.com/cybersecurity-ma-roundup-38-deals-announced-in-march-2026/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"> </a><a class="link" href="https://techcrunch.com/2026/04/20/app-host-vercel-confirms-security-incident-says-customer-data-was-stolen-via-breach-at-context-ai/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow">TechCrunch</a><span style="color:rgb(174, 182, 191);">  | </span><a class="link" href="https://www.bleepingcomputer.com/news/security/vercel-confirms-breach-as-hackers-claim-to-be-selling-stolen-data/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"> BleepingComputer</a><span style="color:rgb(174, 182, 191);">  | </span><a class="link" href="https://www.helpnetsecurity.com/2026/04/20/vercel-breached/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"> Help Net Security</a><span style="color:rgb(174, 182, 191);">  | </span><a class="link" href="https://www.trendmicro.com/en_us/research/26/d/vercel-breach-oauth-supply-chain.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"> Trend Micro Research</a><span style="color:rgb(174, 182, 191);">  | </span><a class="link" href="https://vercel.com/kb/bulletin/vercel-april-2026-security-incident?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"> Vercel Security Bulletin</a></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="agentic-cloud-security-why-the-cnap"><b>Agentic Cloud Security: Why the CNAPP Must Evolve Before Your Adversaries Do</b></h3><p class="paragraph" style="text-align:left;"> For most of the past decade, the cloud security conversation was structured around posture. Know your misconfigurations. Remediate your public S3 buckets. Track your IAM sprawl. The CSPM era gave security teams visibility, and visibility was genuinely the right place to start. But a posture score does not stop an APT41 backdoor that is already running on your Linux workload and querying your metadata API. And a misconfiguration dashboard does not help you when an attacker goes from initial access to data exfiltration in 25 minutes.</p><p class="paragraph" style="text-align:left;"> Elad Koren’s framing in this week’s episode is the clearest articulation of this shift we’ve heard: cloud security has moved from “manage your hygiene” to “protect in real time while maintaining hygiene.” The CNAPP of 2026 is not just a visibility platform. It is an autonomous response layer that can make and execute decisions faster than any human analyst can triage a ticket.</p><p class="paragraph" style="text-align:left;"> The three structural changes Koren identified as driving this shift are worth examining individually, because each one has a direct implication for how you build or upgrade your cloud security program:</p><ul><li><p class="paragraph" style="text-align:left;"><b>AI is available to adversaries. </b>Attacks that previously required days of reconnaissance and manual exploitation can now be generated and launched with a prompt. Palo Alto’s telemetry shows a 25-minute window from initial access to data exfiltration in active incidents. You cannot staff a human response team capable of operating inside that window.</p></li><li><p class="paragraph" style="text-align:left;"><b>Vibe coding has removed the development friction that security relied on. </b>When the cycle from “ideation to production” collapses to three days   including testing   the traditional shift-left security model breaks. There is no left to shift to. Security must be embedded as a continuous automated layer across the entire pipeline, not a review gate before deployment.</p></li><li><p class="paragraph" style="text-align:left;"><b>AI workloads in cloud represent a posture gap most teams cannot close manually. </b>Organizations are deploying experimental AI applications faster than their security teams can inventory, analyze, and control them. The incident Koren described   an internal AI workload accidentally exposed to the internet because the developer had no security context   is not an edge case. It is a pattern.</p><hr class="content_break"><h2 style="text-align:left;" class="heading"><b>Featured Experts This Week </b>🎤</h2></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/eladkoren/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"><b>Elad Koren</b></a><b> - </b>VP, Product Management, Cortex Cloud, Palo Alto Networks</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><b>CNAPP (Cloud-Native Application Protection Platform)</b></p><p class="paragraph" style="text-align:left;">A unified security platform that combines CSPM (posture), CWPP (workload protection), CIEM (entitlements and identity), and increasingly runtime protection and AI workload security into a single data-integrated platform. Elad Koren’s argument is that the CNAPP of 2026 must move beyond posture management into active agentic defense   where AI agents can automatically remediate tier-one issues while surfacing complex attack paths for human analysts.</p></li><li><p class="paragraph" style="text-align:left;"><b>Vibe Coding</b></p><p class="paragraph" style="text-align:left;">A term describing the practice of using AI coding assistants to generate, iterate, and deploy code at dramatically accelerated speeds   often with minimal formal review, design documentation, or security scrutiny. The term captures the intuitive, flow-state nature of AI-assisted development. Its security implication, as Koren described, is that inception-to-production cycles that previously took weeks now take days, collapsing the time window available for security review.</p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <a class="link" href="https://links.cloudsecuritypodcast.tv/orca-cloud-security-live-2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"><b>Orca Security</b></a></p><p class="paragraph" style="text-align:center;">Orca Security is hosting Cloud Security LIVE, a half-day virtual summit on Tuesday, May 12th. Join CISOs, security co-founders, and practitioners for unfiltered insight real stories and strategies from people securing the world&#39;s most complex cloud environments. </p><p class="paragraph" style="text-align:left;">Sessions include:</p><ul><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);font-family:Arial, Helvetica, sans-serif;font-size:small;">The new standard for resilience: zero-breach to zero-impact</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);font-family:Arial, Helvetica, sans-serif;font-size:small;">AI on both sides: securing models and APIs while using AI to defend your cloud</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);font-family:Arial, Helvetica, sans-serif;font-size:small;">Mastering 3rd-party and supply chain risk</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);font-family:Arial, Helvetica, sans-serif;font-size:small;">Security leadership panel on AI, risk, and driving change</span></p><p class="paragraph" style="text-align:left;"><br><span style="color:rgb(34, 34, 34);font-family:Arial, Helvetica, sans-serif;font-size:small;">Join for a chance to win* a 64GB Beelink AI PC. *US-based attendees only.</span></p></li></ul><p class="paragraph" style="text-align:center;"><a class="link" href="https://links.cloudsecuritypodcast.tv/orca-cloud-security-live-2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow">Register Today</a></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-the-25-minute-window-has-broken-t"><b>1. The 25-Minute Window Has Broken the Traditional Security Model</b></h3><p class="paragraph" style="text-align:left;">The most operationally significant data point from Elad Koren’s conversation is also the most alarming: Palo Alto’s telemetry shows that once an organization is susceptible to a particular attack pattern, a threat actor can go from initial access to data exfiltration in 25 minutes. This is not a worst-case scenario. It is a measured median.</p><p class="paragraph" style="text-align:left;"><span style="color:rgb(26, 82, 118);"><i>&quot;It can be seconds. Our latest report shows that within 25 minutes an organization can have data exfiltrated. You cannot wait for the practitioners to fix the gap.&quot;</i></span><span style="color:rgb(46, 134, 193);"><b>    Elad Koren</b></span></p><p class="paragraph" style="text-align:left;">The practical implication for cloud security architecture is that any control requiring human decision-making in the response chain   triage ticket, analyst review, change approval   cannot be the first line of defense for high-confidence threat signals. The most experienced analyst in your SOC cannot triage, escalate, approve, and contain an incident in 25 minutes when they are also managing a queue of other alerts. The response to known-pattern attacks must be automated.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-three-forces-have-changed-the-thr"><b>2. Three Forces Have Changed the Threat Model Permanently</b></h3><p class="paragraph" style="text-align:left;">Elad laid out a clear framework for why the security model that worked three years ago is structurally inadequate today, and it is worth internalizing for board-level conversations:</p><p class="paragraph" style="text-align:left;"><span style="color:rgb(26, 82, 118);"><i>&quot;There are three fundamental things that changed in the model. AI is there for the adversaries   they can move much faster. Developers are pushing code much faster with vibe coding. And we are seeing more and more AI applications running in cloud that not many organizations know how to analyze the posture of.&quot;</i></span><span style="color:rgb(46, 134, 193);"><b>    Elad Koren</b></span></p><p class="paragraph" style="text-align:left;">Each of these forces has a distinct security implication that compounds the others. AI-accelerated attacks mean your detection and response must operate at machine speed. Vibe-coded applications mean your code review pipeline will always be behind the deployment pipeline without automation. AI workloads in cloud mean your CSPM and CWPP coverage has gaps in resource types that simply did not exist 18 months ago. Combine all three, and Elad’s conclusion is apt: “combine all three and you have a time bomb basically.”</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-agentic-cloud-security-is-not-a-p"><b>3. Agentic Cloud Security Is Not a Product Pitch   It Is an Architectural Requirement</b></h3><p class="paragraph" style="text-align:left;">The framing of “agentic CNAPP” can sound like vendor positioning, but Elad’s description of what it actually means is grounded in operational reality. The core argument is not that AI agents replace your security team. It is that tier-one triage the routine fixes, the known patterns, the high-confidence remediations   should be handled autonomously, so that your analysts can focus on the cases that genuinely require human judgment.</p><p class="paragraph" style="text-align:left;"><span style="color:rgb(26, 82, 118);"><i>&quot;A good solution prioritizes making sure that your tier-one analysts   you can take 85, 90% of the things they would do, the regular fixes, automatically. You’ll have AI agents working for you. Because then you’re fighting machines with machines.&quot;</i></span><span style="color:rgb(46, 134, 193);"><b>    Elad Koren</b></span></p><p class="paragraph" style="text-align:left;">Ashish Rajan’s framing of the shift is equally direct: the agentic security era means the CNAPP must have API-level understanding of how AI agents communicate with cloud platforms, not just posture snapshots of static configurations. </p><p class="paragraph" style="text-align:left;"><span style="color:rgb(26, 82, 118);"><i>&quot;It’s no longer enough that you have a CNAPP. Having an understanding of the pathway, API capabilities, and how you can have AI agents communicate with that as a platform will become the more important thing as we move into 2026 and beyond.&quot;</i></span><span style="color:rgb(46, 134, 193);"><b>    Ashish Rajan</b></span></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-visibility-and-identity-are-the-t"><b>4. Visibility and Identity Are the Two Non-Negotiable Foundations</b></h3><p class="paragraph" style="text-align:left;">When Elad was asked directly what organizations should focus on for a durable cloud security uplift program, his answer was grounded in a specific real-world example: an experimental AI workload deployed for internal use that was accidentally exposed to the internet because the developer had no security awareness of the infrastructure it was running on.</p><p class="paragraph" style="text-align:left;"><span style="color:rgb(26, 82, 118);"><i>&quot;That AI workload was open to the world without any need of authentication. The person creating that had little to almost no knowledge or awareness for security. Somebody was able to access it   he was able to exfiltrate data. Inception to production in less than three days, including testing, including everything.&quot;</i></span><span style="color:rgb(46, 134, 193);"><b>    Elad Koren</b></span></p><p class="paragraph" style="text-align:left;">His prescription: visibility into where your AI workloads run, identity controls with least-privilege and minimal access for anything that touches those workloads, and securing the infrastructure   not just the application. This is not new advice in the abstract, but the AI workload context makes it urgent in a new way. Most organizations’ AI workload inventory is incomplete by definition   developers are spinning up new AI-powered services faster than any centralized inventory process can track them.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-the-messy-middle-is-where-we-are-"><b>5. The “Messy Middle” Is Where We Are   And That Is a Strategic Opportunity</b></h3><p class="paragraph" style="text-align:left;">Elad’s most useful framing for security leaders planning multi-year programs is what he calls the “messy middle”: the transition period between where most organizations are today (siloed, posture-focused, human-speed) and where the industry is going (platformized, agentic, machine-speed). This period is messy because no one knows exactly what the equilibrium looks like. But the direction is clear.</p><p class="paragraph" style="text-align:left;">The prescription for this period is not to wait for clarity. It is to build the foundations that will matter regardless of how the technology evolves: unified data platforms that eliminate tool silos, trust in AI-driven automation built through experimentation, and upskilling security practitioners to become orchestrators rather than ticket-processors.</p><p class="paragraph" style="text-align:left;"><span style="color:rgb(26, 82, 118);"><i>&quot;If organizations continue to build things in silos and look at security as siloed different tasks by different practitioners   adversaries will prevail. They’re like water. They’ll just find a path in. You close the door, they look at the window. You close the window, they look at the tunnel. If they don’t have a tunnel, they’ll dig a tunnel.&quot;</i></span><span style="color:rgb(46, 134, 193);"><b>    Elad Koren</b></span></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>📚 RELATED RESOURCES 🎧</b></h2><ul><li><p class="paragraph" style="text-align:left;"><b>Palo Alto Networks Cortex Cloud  </b><a class="link" href="https://www.paloaltonetworks.com/cortex/cortex-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow"> Platform Overview</a></p><p class="paragraph" style="text-align:left;">The platform Elad Koren describes in this episode. Relevant for teams evaluating agentic CNAPP capabilities.</p></li></ul><h3 class="heading" style="text-align:left;" id="podcast-episode"><b>Podcast Episode</b></h3><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/the-rise-of-agentic-cloud-security-code-to-cloud-shrinks-to-3-days?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast -Full Episode with </a><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/the-rise-of-agentic-cloud-security-code-to-cloud-shrinks-to-3-days?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow">Elad Koren</a> - Complete transcript and audio for this week&#39;s featured conversation</p></li></ul><hr class="content_break"><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔<b> </b><span style="color:rgb(20, 19, 34);"> </span> Is your AI workload inventory complete enough that you could answer ‘where does our AI run and who can reach it’ in under an hour?<br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=vercel-oauth-attack-how-ai-is-breaking-cloud-security-what-cisos-must-do-now" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=647c7699-330c-4ae5-a7e4-defaf7b8c993&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🚨 AI Discovers Thousands of Zero-Days: Lessons from Catching What EDR Can&#39;t See</title>
  <description>Microsoft&#39;s record-breaking April Patch Tuesday (167 CVEs), Anthropic&#39;s Claude Mythos autonomously discovering thousands of critical zero-days, the ShinyHunters breach of Anodot and Snowflake customer environments via stolen SaaS tokens, and the TeamPCP open-source supply chain attack stealing 10,000+ cloud credentials. </description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c818e3b7-bcae-4210-bf9f-097c1abf4784/Screenshot_2026-04-16_at_2.28.36_AM.png" length="1890037" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see</guid>
  <pubDate>Thu, 16 Apr 2026 01:34:48 +0000</pubDate>
  <atom:published>2026-04-16T01:34:48Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><h2 class="heading" style="text-align:left;" id="hello-from-the-cloudverse"><span style="background-color:#28EEDA;"><b>Hello from the Cloud-verse!</b></span></h2><p class="paragraph" style="text-align:left;">This week’s Cloud Security Newsletter topic<b>: </b><b>The Behavioral Blind Spot: Why Your Security Stack Can&#39;t See What Users Actually Do With AI</b><b> </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" rel="noopener noreferrer nofollow">(continue reading)</a> </p><hr class="content_break"><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://links.cloudsecuritypodcast.tv/tines-workflow-event-2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see"><span class="button__text" style=""> This issue is sponsored by Tines </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c818e3b7-bcae-4210-bf9f-097c1abf4784/Screenshot_2026-04-16_at_2.28.36_AM.png?t=1776303035"/></a><div class="image__source"><span class="image__source_text"><p><i>This image was generated by AI. It&#39;s still experimental, so it might not be a perfect match!</i></p></span></div></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;">The week of April 8–13 delivered a signal that the security industry has been anticipating with dread: autonomous AI vulnerability discovery at scale. Anthropic&#39;s disclosure of Claude Mythos Preview, a model that independently found thousands of high- and critical-severity zero-days across every major operating system and browser is not a research curiosity. It is a forcing function for every security program that still operates on human-speed threat models.</p><p class="paragraph" style="text-align:left;">At the same time, attackers remained methodical and thoroughly mundane. ShinyHunters did not need a novel exploit to pivot from Anodot&#39;s SaaS platform into over a dozen Snowflake customer environments, they walked in with stolen integration tokens. TeamPCP did not compromise a zero-day; they compromised a maintainer&#39;s credentials and waited for CI/CD pipelines to distribute the payload automatically.</p><p class="paragraph" style="text-align:left;">Threading these stories together this week is <b>Brandon Dixon</b>, Co-founder of <a class="link" href="https://Ent.ai?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Ent.ai</a> and one of the architects of Microsoft Defender Threat Intelligence and Microsoft Security Copilot. Brandon joined Cloud Security Podcast host Ashish Rajan to discuss why the control surfaces enterprises have built EDR, DLP, UEBA, SSPM are structurally blind to the behavioral signals that matter most: what a user actually intends to do, across every application, in real time. <i>[</i><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/solving-prompt-injection-shadow-ai-for-ai-malware?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">⚡ TL;DR for Busy Readers</h2><ul><li><p class="paragraph" style="text-align:left;">🔴 <b>Patch NOW:</b> SharePoint (active exploit), Ivanti EPMM (KEV), Adobe Reader (5 months undetected), Windows IKE RCE (CVSS 9.8, wormable)</p></li><li><p class="paragraph" style="text-align:left;">🔑 <b>SaaS tokens = your weakest link:</b> ShinyHunters breached Snowflake customers without a single vulnerability — just stolen integration tokens</p></li><li><p class="paragraph" style="text-align:left;">📦 <b>Your security tools can betray you:</b> TeamPCP compromised Trivy, KICS, Axios, LiteLLM — 10,000+ cloud creds stolen via CI/CD</p></li><li><p class="paragraph" style="text-align:left;">🤖 <b>AI offense just scaled:</b> Anthropic’s Claude Mythos found thousands of zero-days autonomously</p></li><li><p class="paragraph" style="text-align:left;">👁️ <b>EDR blind spot is real:</b> It sees processes, not intent — and attackers are now operating in that gap</p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="what-to-do-this-week">👉 WHAT TO DO THIS WEEK</h2><ul><li><p class="paragraph" style="text-align:left;"><b>Patch internet-facing systems immediately</b> (SharePoint, Ivanti, Windows services)</p></li><li><p class="paragraph" style="text-align:left;"><b>Rotate ALL third-party SaaS tokens</b> (especially Snowflake integrations)</p></li><li><p class="paragraph" style="text-align:left;"><b>Audit CI/CD pipelines</b> → lock dependencies + enforce signed artifacts</p></li><li><p class="paragraph" style="text-align:left;"><b>Review AI usage inside sanctioned apps</b> (Teams, Slack, WhatsApp, etc.) </p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="this-weeks-security-news">📰 <b>THIS WEEK&#39;S TOP 8 SECURITY HEADLINES</b></h2><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-microsoft-patch-tuesday-167-cv-es"><b> </b>🚨<b> 1. Microsoft Patch Tuesday (167 CVEs, Active Exploits)</b></h3><p class="paragraph" style="text-align:left;"><b>What happened:</b></p><ul><li><p class="paragraph" style="text-align:left;">167 vulnerabilities patched (largest of 2026)</p></li><li><p class="paragraph" style="text-align:left;">Active SharePoint zero-day (CVE-2026-32201)</p></li><li><p class="paragraph" style="text-align:left;">Wormable Windows IKE RCE (CVSS 9.8)</p></li><li><p class="paragraph" style="text-align:left;">Adobe Reader zero-day active for 5 months</p></li></ul><p class="paragraph" style="text-align:left;"><b>Why it matters:</b><br> This is <b>Exploit Wednesday territory</b>. Attackers are already reverse-engineering patches.</p><p class="paragraph" style="text-align:left;">👉 <b>Priority order:</b></p><ol start="1"><li><p class="paragraph" style="text-align:left;">SharePoint (active exploitation)</p></li><li><p class="paragraph" style="text-align:left;">Ivanti EPMM (KEV)</p></li><li><p class="paragraph" style="text-align:left;">Windows IKE / TCP-IP RCE</p></li><li><p class="paragraph" style="text-align:left;">Adobe Reader</p></li></ol><p class="paragraph" style="text-align:left;"><b>Sources</b>: <a class="link" href="https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> BleepingComputer</a> |<a class="link" href="https://securityaffairs.com/190831/security/microsoft-patch-tuesday-for-april-2026-fixed-actively-exploited-sharepoint-zero-day.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> Security Affairs</a> |<a class="link" href="https://www.zerodayinitiative.com/blog/2026/4/14/the-april-2026-security-update-review?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> Zero Day Initiative</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-ivanti-epmm-zero-day-kev-4400-exp">🚨<b> 2.  Ivanti EPMM Zero-Day (KEV, 4,400+ Exposed)</b></h3><p class="paragraph" style="text-align:left;"><b>What happened:</b></p><ul><li><p class="paragraph" style="text-align:left;">Third critical zero-day in Ivanti platform</p></li><li><p class="paragraph" style="text-align:left;">Active exploitation confirmed</p></li><li><p class="paragraph" style="text-align:left;">4,400+ internet-exposed instances</p></li></ul><p class="paragraph" style="text-align:left;"><b>Why it matters:</b><br> This is no longer a vulnerability issue — it’s a <b>vendor risk signal</b>.</p><p class="paragraph" style="text-align:left;">👉 Treat as:</p><ul><li><p class="paragraph" style="text-align:left;">Emergency patch</p></li><li><p class="paragraph" style="text-align:left;">Potential breach (assume compromise mindset)</p></li></ul><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-ivanti-epmm-flaw-by-sunday/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> BleepingComputer</a> |<a class="link" href="https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> Palo Alto Unit 42</a> |<a class="link" href="https://www.cybersecuritydive.com/news/cisa-second-critical-flaw-ivanti-epmm-exploited/817080/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> Cybersecurity Dive</a> |<a class="link" href="https://www.rapid7.com/blog/post/etr-critical-ivanti-endpoint-manager-mobile-epmm-zero-day-exploited-in-the-wild-eitw-cve-2026-1281-1340/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> Rapid7</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-adobe-zero-day-5-months-undetecte"><b>☁️ 3. </b>⚡ <b>Adobe Zero-Day (5 Months Undetected)</b></h3><p class="paragraph" style="text-align:left;"><b>What happened:</b></p><ul><li><p class="paragraph" style="text-align:left;">Silent exploitation via PDF for ~5 months</p></li><li><p class="paragraph" style="text-align:left;">No user interaction required beyond opening</p></li><li><p class="paragraph" style="text-align:left;">Targeting energy sector</p></li></ul><p class="paragraph" style="text-align:left;"><b>Why it matters:</b><br> Your telemetry likely showed:<br>👉 <i>“Acrobat.exe is running”</i> — nothing else.</p><p class="paragraph" style="text-align:left;">This is exactly the detection gap modern attacks exploit.</p><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://blog.openvpn.net/this-week-in-cybersecurity-adobes-four-month-zero-day?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> OpenVPN Blog</a> |<a class="link" href="https://www.zerodayinitiative.com/blog/2026/4/14/the-april-2026-security-update-review?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> Zero Day Initiative</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-shiny-hunters-saa-s-token-breach-">🏥<b> 4. ShinyHunters: SaaS Token Breach → Snowflake Customers</b></h3><p class="paragraph" style="text-align:left;">Beginning April 4, ShinyHunters compromised Anodot — an AI-powered cloud cost monitoring </p><p class="paragraph" style="text-align:left;"><b>What happened:</b></p><ul><li><p class="paragraph" style="text-align:left;">Anodot breached → integration tokens stolen</p></li><li><p class="paragraph" style="text-align:left;">Attackers accessed multiple Snowflake environments</p></li><li><p class="paragraph" style="text-align:left;">78.6M records leaked</p></li></ul><p class="paragraph" style="text-align:left;"><b>Why it matters:</b><br> No vulnerability. No exploit.</p><p class="paragraph" style="text-align:left;">👉 Just <b>trusted SaaS tokens doing their job</b></p><p class="paragraph" style="text-align:left;">This mirrors the 2025 OAuth attacks — and most orgs still haven’t fixed it.</p><p class="paragraph" style="text-align:left;"><b>Action:</b></p><ul><li><p class="paragraph" style="text-align:left;">Rotate ALL SaaS tokens</p></li><li><p class="paragraph" style="text-align:left;">Enforce short-lived credentials</p></li><li><p class="paragraph" style="text-align:left;">Audit vendor integrations post-acquisition</p></li></ul><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://techcrunch.com/2026/04/13/hack-at-anodot-leaves-over-a-dozen-breached-companies-facing-extortion/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> TechCrunch</a> |<a class="link" href="https://www.bleepingcomputer.com/news/security/snowflake-customers-hit-in-data-theft-attacks-after-saas-integrator-breach/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> BleepingComputer</a> |<a class="link" href="https://therecord.media/rockstar-hackers-cyberattack-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> The Record</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-team-pcp-supply-chain-attack-1000"><b>5 — TeamPCP Supply Chain Attack (10,000+ Orgs Impacted)</b></h3><p class="paragraph" style="text-align:left;"><b>What happened:</b></p><ul><li><p class="paragraph" style="text-align:left;">Trivy, KICS, Axios, LiteLLM compromised</p></li><li><p class="paragraph" style="text-align:left;">Malicious packages exfiltrated cloud credentials</p></li><li><p class="paragraph" style="text-align:left;">Spread via CI/CD pipelines</p></li></ul><p class="paragraph" style="text-align:left;"><b>Why it matters:</b><br> Your security scanners are now part of the attack surface.</p><p class="paragraph" style="text-align:left;">👉 If your pipeline auto-pulls latest:<br>You’re running <b>unverified code in production by design</b></p><p class="paragraph" style="text-align:left;"><b>Action:</b></p><ul><li><p class="paragraph" style="text-align:left;">Lock dependency versions</p></li><li><p class="paragraph" style="text-align:left;">Use signed artifacts</p></li><li><p class="paragraph" style="text-align:left;">Add release cooldown windows </p></li></ul><p class="paragraph" style="text-align:left;"><b>Sources</b>: <a class="link" href="https://www.sans.org/blog/axios-npm-supply-chain-compromise-malicious-packages-remote-access-trojan?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">SANS Institute</a> |<a class="link" href="https://www.zscaler.com/blogs/security-research/supply-chain-attacks-surge-march-2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> Zscaler ThreatLabz</a> |<a class="link" href="https://www.theregister.com/2026/04/11/trivy_axios_supply_chain_attacks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> The Register</a> |<a class="link" href="https://www.infoq.com/news/2026/04/trivy-supply-chain-attack/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> InfoQ</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="6-anthropics-claude-mythos-preview-"><b>6 — Anthropic&#39;s Claude Mythos Preview Autonomously Discovers Thousands of Zero-Days Across Every Major OS and Browser; Project Glasswing Launched</b></h3><p class="paragraph" style="text-align:left;"><b>What happened:</b></p><ul><li><p class="paragraph" style="text-align:left;">Claude Mythos discovered thousands of vulnerabilities</p></li><li><p class="paragraph" style="text-align:left;">72% success rate in exploit development</p></li><li><p class="paragraph" style="text-align:left;">Posted exploits autonomously in testing</p></li></ul><p class="paragraph" style="text-align:left;"><b>Why it matters:</b><br> This is a <b>category shift</b>.</p><p class="paragraph" style="text-align:left;">👉 Threat model is now:</p><ul><li><p class="paragraph" style="text-align:left;">Faster than human response</p></li><li><p class="paragraph" style="text-align:left;">Cheaper to execute</p></li><li><p class="paragraph" style="text-align:left;">Scalable by design</p></li></ul><p class="paragraph" style="text-align:left;"><b>Implication:</b><br> Detection-led security will fail.</p><p class="paragraph" style="text-align:left;">👉 You need:</p><ul><li><p class="paragraph" style="text-align:left;">Automated containment</p></li><li><p class="paragraph" style="text-align:left;">Identity-aware segmentation</p></li><li><p class="paragraph" style="text-align:left;">Sub-30 min response capability</p></li></ul><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://red.anthropic.com/2026/mythos-preview/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> Anthropic Red Team</a> |<a class="link" href="https://www.helpnetsecurity.com/2026/04/08/anthropic-claude-mythos-preview-identify-vulnerabilities/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> Help Net Security</a> |<a class="link" href="https://www.theregister.com/2026/04/07/anthropic_all_your_zerodays_are_belong_to_us/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> The Register</a> |<a class="link" href="https://www.helpnetsecurity.com/2026/04/15/anthropic-claude-mythos-ai-vulnerability-discovery/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> CSA Briefing via Help Net Security</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="7-microsoft-defender-for-cloud-ai-m"><b>7 — Microsoft Defender for Cloud → AI Model Scanning</b></h3><p class="paragraph" style="text-align:left;"><b>What happened:</b></p><ul><li><p class="paragraph" style="text-align:left;">Scans models for malware, secrets, unsafe formats</p></li><li><p class="paragraph" style="text-align:left;">Supports .pkl, .onnx, .pt, etc.</p></li><li><p class="paragraph" style="text-align:left;">Integrated into CI/CD</p></li></ul><p class="paragraph" style="text-align:left;"><b>Why it matters:</b><br> AI models = new software supply chain</p><p class="paragraph" style="text-align:left;">👉 Pickle files = built-in RCE risk</p><p class="paragraph" style="text-align:left;"><b>Action:</b></p><ul><li><p class="paragraph" style="text-align:left;">Scan all models before deployment</p></li><li><p class="paragraph" style="text-align:left;">Prefer SafeTensors over Pickle</p></li></ul><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://learn.microsoft.com/en-us/azure/defender-for-cloud/ai-model-security?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> Microsoft Learn — AI Model Security</a> |<a class="link" href="https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/new-innovations-in-microsoft-defender-to-strengthen-multi-cloud-containers-and-a/4503886?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> Microsoft Tech Community Blog</a> |<a class="link" href="https://learn.microsoft.com/en-us/azure/defender-for-cloud/release-notes?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> Defender for Cloud Release Notes</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="8-databricks-enters-siem-market-wit"><b>8 — Databricks Enters SIEM Market with &quot;Lakewatch&quot; via Dual Acquisition of Antimatter and </b><a class="link" href="https://SiftD.ai?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"><b>SiftD.ai</b></a></h3><p class="paragraph" style="text-align:left;"><b>What happened:</b></p><ul><li><p class="paragraph" style="text-align:left;">Acquires Antimatter + <a class="link" href="https://SiftD.ai?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">SiftD.ai</a></p></li><li><p class="paragraph" style="text-align:left;">Launches AI-native SIEM</p></li></ul><p class="paragraph" style="text-align:left;"><b>Why it matters:</b><br> Security is merging with data platforms.</p><p class="paragraph" style="text-align:left;">👉 This creates a new problem:<br>Who owns detection <b>security or data teams?</b></p><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://www.securityweek.com/cybersecurity-ma-roundup-38-deals-announced-in-march-2026/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"> SecurityWeek — Cybersecurity M&A Roundup March 2026</a></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="the-behavioral-blind-spot-why-your-"><b>The Behavioral Blind Spot: Why Your Security Stack Can&#39;t See What Users Actually Do With AI</b></h3><p class="paragraph" style="text-align:left;">Every major security incident discussed in this week&#39;s news brief shares a common thread: attackers and risky insiders are operating inside the legitimate workflows of sanctioned enterprise tools. ShinyHunters looked like a trusted SaaS integration. The Adobe PDF exploit ran inside a fully patched Reader process. TeamPCP&#39;s malicious Axios release ran through the same npm dependency resolution your developers use daily. The Zoom remote-control exfiltration path is invisible to EDR because EDR sees the process, not the intent.</p><p class="paragraph" style="text-align:left;">Brandon Dixon&#39;s work at <a class="link" href="https://Ent.ai?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Ent.ai</a> addresses the fundamental question this creates for enterprise security programs: if adversaries and risky insiders have moved into the behavioral layer — into the clicks, clipboard operations, drag-and-drop file transfers, and AI prompt submissions that happen inside sanctioned applications — what does your detection surface actually cover?</p><p class="paragraph" style="text-align:left;">The answer, increasingly, is less than you think. This is the topic that binds together AI security governance, insider risk, supply chain compromise, and the post-EDR detection problem. And it is the lens through which senior cloud security leaders should be evaluating both their current tooling and the programs they are building for the AI era.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="featured-experts-this-week"><b>Featured Experts This Week </b>🎤</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/brandonsdixon/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow"><b>Brandon Dixon</b></a> Co-founder & CTO , <a class="link" href="https://Ent.ai?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Ent.ai</a></p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Behavioral Layer / Endpoint Behavioral Intelligence</b> A detection approach that sits above the operating system process level and observes what users and agents actually do within and across applications — clicks, clipboard operations, file drags, AI prompt submissions, cross-app data movement — rather than simply which processes are running. This is distinct from EDR (which monitors file system and process activity) and UEBA (which typically analyzes aggregated log-derived signals).</p></li><li><p class="paragraph" style="text-align:left;"><b>Living Off the Land (LotL)</b> An attack technique in which threat actors use legitimate, pre-installed enterprise software (PowerShell, WMI, Zoom remote control, etc.) to conduct malicious activity, making detection harder because the tools themselves are not inherently suspicious. TeamPCP&#39;s use of compromised legitimate package releases is a supply-chain variant of this technique.</p></li><li><p class="paragraph" style="text-align:left;"><b>CVE / CVSS / KEV</b> CVE (Common Vulnerabilities and Exposures): the standardized identifier for a specific vulnerability. CVSS (Common Vulnerability Scoring System): a 0–10 severity score; 9.0+ is Critical. KEV (CISA&#39;s Known Exploited Vulnerabilities catalog): a list of vulnerabilities confirmed to be actively exploited in the wild, with mandatory patch deadlines for federal agencies under Binding Operational Directive 22-01.</p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <b><a class="link" href="https://links.cloudsecuritypodcast.tv/tines-workflow-event-2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Tines</a></b></p><p class="paragraph" style="text-align:center;">Move Past AI Hype to Build Secure Scalable Workflows</p><p class="paragraph" style="text-align:center;"><b><a class="link" href="https://links.cloudsecuritypodcast.tv/tines-workflow-event-2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Hear how leaders at HubSpot, Asana, Jamf, ASOS and Riot Games</a></b><b> </b>are scaling AI and automation in real security and operations workflows. AI’s real impact doesn’t happen in isolation. It comes from experimentation and learning from teams already leading the way.</p><p class="paragraph" style="text-align:center;">Join Workflow, Tines’ flagship virtual event streaming live from New York on May 6. Discover how teams are moving beyond AI paralysis, scaling automation responsibly, and building workflows that eliminate busywork. </p><p class="paragraph" style="text-align:center;">Discover how teams are moving beyond AI paralysis, scaling automation responsibly, and reducing manual security and operational work.</p><p class="paragraph" style="text-align:center;"><a class="link" href="https://links.cloudsecuritypodcast.tv/tines-workflow-event-2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Save your Spot</a></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-the-edr-gap-is-structural-not-a-c"><b>1. The EDR Gap Is Structural, Not a Configuration Problem</b></h3><p class="paragraph" style="text-align:left;">One of the most practically useful points Brandon makes — and one that directly informs how you should interpret the attack patterns in this week&#39;s news — is that EDR&#39;s visibility gap is not a tuning problem or a missed rule. It is architectural. EDR was designed in an era when malware manipulated the file system. That design decision shapes what EDR can and cannot see:</p><p class="paragraph" style="text-align:left;"><i>&quot;The adversary is now using the same software as the enterprise, and they&#39;re trying to look like an employee specifically, so they don&#39;t get detected. All we know is that Zoom&#39;s running. We don&#39;t understand why they gave remote control over and what they did after that happened.&quot;</i> — Brandon Dixon, Co-founder, <a class="link" href="https://Ent.ai?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Ent.ai</a></p><p class="paragraph" style="text-align:left;">This is not a theoretical gap. Brandon&#39;s incident response colleagues can confirm that Zoom remote control was activated — they know from SaaS logs — but they have no way to determine whether the resulting session was malicious or a legitimate help-desk handoff. That ambiguity is operationally disabling: you cannot act on an alert you cannot classify.</p><p class="paragraph" style="text-align:left;">For cloud security architects, the practical implication is that any detection program that relies exclusively on process-level telemetry (EDR) and network-level telemetry (CASB/proxy) is structurally blind to the behavioral middle layer where the most consequential decisions are made. That middle layer — drag-and-drop, clipboard contents, UI interaction within an application, cross-app data movement — is precisely where AI adoption is creating new risk vectors.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-unsanctioned-ai-inside-sanctioned"><b>2. Unsanctioned AI Inside Sanctioned Applications Is Your Next Undetectable HIPAA Violation</b></h3><p class="paragraph" style="text-align:left;">The WhatsApp/Meta AI example Brandon describes from a Fortune 500 deployment illustrates three converging risk trends simultaneously:</p><ul><li><p class="paragraph" style="text-align:left;">AI is being embedded directly into sanctioned communication tools — WhatsApp, Zoom, Slack, Teams — without requiring a separate application install or any deliberate opt-in by the enterprise.</p></li><li><p class="paragraph" style="text-align:left;">Users are not being malicious. The HR employee who pasted patient records into Meta AI to get a summary was trying to do their job efficiently. The violation was unintentional — but it was still a HIPAA violation.</p></li><li><p class="paragraph" style="text-align:left;">Traditional DLP cannot catch it. As Brandon notes, DLP runs pattern-matching against content it can observe. If you drag a file rather than copy-paste, if the pattern doesn&#39;t match a defined regex, if the AI feature is embedded within encrypted application traffic — DLP misses it.</p></li></ul><p class="paragraph" style="text-align:left;">For CISOs currently building AI governance programs, this creates a classification problem that is not solvable through policy alone. You can enumerate the authorized AI tools in your AUP. You cannot enumerate every AI feature that will be silently added to every SaaS application your users rely on. WhatsApp embedded Meta AI. Microsoft embedded Copilot into Teams and Word. Google embedded Gemini into Workspace. The AI surface within sanctioned applications is growing faster than any policy review cycle can track.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-context-aware-anomaly-detection-t"><b>3. Context-Aware Anomaly Detection: The Lessons of Failed UEBA Programs</b></h3><p class="paragraph" style="text-align:left;">Many senior security professionals carry institutional scar tissue from UEBA deployments that generated high false-positive rates and were eventually deprioritized or abandoned. Brandon&#39;s analysis of why those programs struggled is directly relevant to evaluating the next generation of behavioral detection platforms:</p><p class="paragraph" style="text-align:left;"><i>&quot;Where those [UEBA systems] struggled is they simply tried to model independent variables or anomalies. Working late at night is potentially not a big deal, but working late at night and giving remote control of your system to someone else outside the business — well, you know, that&#39;s kind of odd. That context has historically been missing.&quot;</i> — Brandon Dixon, Co-founder, <a class="link" href="https://Ent.ai?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Ent.ai</a></p><p class="paragraph" style="text-align:left;">The distinction Brandon draws is between modeling independent behavioral variables (login time, geo-location, process list) versus modeling behavioral context — understanding what a user was doing immediately before, during, and after an action in order to evaluate whether the combination of behaviors constitutes risk. This is a fundamentally different technical approach from statistical anomaly detection, and it requires a different data source: behavioral telemetry captured at the endpoint in real time, not reconstructed from logs after the fact.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-endpoint-behavior-as-the-foundati"><b>4. Endpoint Behavior as the Foundation for AI Agent Oversight</b></h3><p class="paragraph" style="text-align:left;">For cloud security leaders currently building AI governance frameworks, Brandon introduces a detection surface that most programs have not yet addressed: AI agents running locally on endpoints. As local model inference becomes more practical on modern hardware, AI agents that perform autonomous tasks — file access, web browsing, application control, code execution — are increasingly running at the endpoint level rather than exclusively in the cloud.</p><p class="paragraph" style="text-align:left;">Brandon&#39;s approach at <a class="link" href="https://Ent.ai?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Ent.ai</a> is to proxy that agent traffic at the endpoint layer, enabling visibility into the handoff between human instruction, AI execution, and the resulting system actions. This creates a detection capability that cloud-only monitoring misses entirely: you can observe what instruction the user gave the agent, what the agent did with it, and whether the resulting system interaction (file writes, process spawns, network calls) is consistent with the stated instruction and role-appropriate behavior.</p><p class="paragraph" style="text-align:left;">For DevSecOps teams deploying AI coding assistants (GitHub Copilot, Cursor, Claude Code) and enterprise AI workflow tools, this framing suggests a near-term requirement: you need observability not just into which AI tools are authorized, but into what those tools do on the endpoint when they execute.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-what-to-actually-build-first-bran"><b>5. What to Actually Build First: Brandon&#39;s Program Guidance</b></h3><p class="paragraph" style="text-align:left;">When Ashish pressed Brandon on what a security leader should actually do before investing in behavioral detection tooling, his answer reframes the question in a way that is immediately actionable for senior practitioners:</p><p class="paragraph" style="text-align:left;"><i>&quot;Do you actually understand who your risky users are? And more importantly, why are they risky? Because most people can&#39;t answer the question: what&#39;s actually happening in their business. They have these draconian policies that they draft... and it&#39;s only as good as its ability to enforce it at a control point. And the problem is, those policies are overly broad and the control points are not sufficiently deep, and they miss context.&quot;</i> — Brandon Dixon, Co-founder, <a class="link" href="https://Ent.ai?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Ent.ai</a></p><p class="paragraph" style="text-align:left;">The practical starting point this suggests for programs at different maturity levels:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Foundational (no behavioral layer yet):</b> Start by mapping your highest-risk user populations — finance, HR, legal, engineering with production access — and documenting what &quot;normal&quot; looks like for each role. This baseline work is necessary regardless of what tooling you adopt.</p></li><li><p class="paragraph" style="text-align:left;"><b>Intermediate (EDR + CASB deployed):</b> Identify the behavioral gaps between what your current stack can observe and what a risky action in each high-risk role actually looks like. The WhatsApp/Meta AI example is a useful test case — can your current stack catch it? If not, you have a documented gap to drive tooling requirements.</p></li></ul><p class="paragraph" style="text-align:left;"><b>Advanced (evaluating next-generation behavioral detection):</b> Evaluate platforms that provide real-time behavioral context at the endpoint — not just process telemetry or SaaS logs — with AI agent traffic visibility and cross-application behavioral correlation. Brandon&#39;s framing is that without the actual behavioral layer, even a data lake plus AI cannot reconstruct sufficient context to make informed decisions at the speed attacks now move.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>📚 RELATED RESOURCES 🎧</b></h2><ul><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://Ent.ai?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Ent.ai</a></b> — Brandon Dixon&#39;s endpoint behavioral intelligence platform</p></li><li><p class="paragraph" style="text-align:left;"> CISA KEV Catalog  Known Exploited Vulnerabilities list including CVE-2026-1340<span style="color:#000000;"><b> </b></span><a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">→ CISA KEV Catalog</a></p></li></ul><h3 class="heading" style="text-align:left;" id="podcast-episode"><b>Podcast Episode</b></h3><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast -Full Episode with </a>Brandon Dixon- Complete transcript and audio for this week&#39;s featured conversation</p></li></ul><hr class="content_break"><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔<b> </b><span style="color:rgb(20, 19, 34);"> </span> Can your current stack tell the difference between a user legitimately using an AI assistant and one leaking sensitive data through it — and if not, what&#39;s your first step to close that gap?<br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-discovers-thousands-of-zero-days-lessons-from-catching-what-edr-can-t-see" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=335822d5-b29a-4ee7-9bb8-e284d6b1336b&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🚨 AI Agents Can Now Exploit Docker And Your CI/CD Is Next</title>
  <description>A Docker container escape that AI agents can autonomously exploit, a CI/CD breach at Cisco, and Microsoft’s 22-second attack hand-off all point to one shift: execution is now the attack surface. Identity not AppSec is emerging as the only scalable control plane for the agentic threat model.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/04954ec2-13f8-4180-b1e6-7cca691c6c4b/Screenshot_2026-04-08_at_10.11.44_PM.png" length="1533599" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/ai-agents-exploit-docker-cicd-attack-surface</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/ai-agents-exploit-docker-cicd-attack-surface</guid>
  <pubDate>Wed, 08 Apr 2026 21:36:22 +0000</pubDate>
  <atom:published>2026-04-08T21:36:22Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><h2 class="heading" style="text-align:left;" id="hello-from-the-cloudverse"><span style="background-color:#28EEDA;"><b>Hello from the Cloud-verse!</b></span></h2><p class="paragraph" style="text-align:left;">This week’s Cloud Security Newsletter topic<b>: Identity Is the Only Scalable Control Plane </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" rel="noopener noreferrer nofollow">(continue reading)</a> </p><hr class="content_break"><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://links.cloudsecuritypodcast.tv/tines-workflow-event-2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next"><span class="button__text" style=""> This issue is sponsored by Tines </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/04954ec2-13f8-4180-b1e6-7cca691c6c4b/Screenshot_2026-04-08_at_10.11.44_PM.png?t=1775682732"/></a><div class="image__source"><span class="image__source_text"><p><i>This image was generated by AI. It&#39;s still experimental, so it might not be a perfect match!</i></p></span></div></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;">The security industry has spent the past 18 months debating shadow AI as a data governance problem. This week, that framing gets a hard reset.</p><p class="paragraph" style="text-align:left;">Between Microsoft declaring that human-only defense is &quot;no longer viable,&quot; a publicly disclosed Docker zero-day that AI coding agents can autonomously discover and exploit, and a Cisco breach traced to a compromised CI/CD pipeline the threat is no longer theoretical. The attack surface has fundamentally shifted to wherever your agents, workloads, and non-human identities operate.</p><p class="paragraph" style="text-align:left;">To make sense of it, we spoke with <b>Jasson Casey</b>, Co-founder and CEO of <b>Beyond Identity</b>, one of the clearest thinkers on where identity security intersects with agentic AI risk. His argument, built from first principles, is that identity is not just one layer of your defense, it is the only control plane capable of managing the agentic threat model systematically. <i>[</i><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/solving-prompt-injection-shadow-ai-for-ai-malware?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">⚡ TL;DR for Busy Readers</h2><ul><li><p class="paragraph" style="text-align:left;">AI agents can now <b>discover + exploit Docker container escapes autonomously </b>(Docker CVE-2026-34040)</p></li><li><p class="paragraph" style="text-align:left;">Cisco was breached via a <b>trusted CI/CD tool </b>GitHub Actions<b> (not direct attack)</b></p></li><li><p class="paragraph" style="text-align:left;">Microsoft confirms <b>attack hand-off = 22 seconds </b>→ humans can’t keep up</p></li><li><p class="paragraph" style="text-align:left;">The real gap isn’t shadow AI — it’s <b>uncontrolled non-human identity</b></p></li><li><p class="paragraph" style="text-align:left;">CrowdStrike&#39;s<b> </b>$1.16B bet on<b> I</b><b>dentity + Browser</b><b>s</b></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="this-weeks-security-news">📰 <b>THIS WEEK&#39;S TOP 4 SECURITY HEADLINES</b></h2><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-ai-agents-can-exploit-docker-auto"><b> </b>🚨<b> 1. </b>🧬 AI Agents Can Exploit Docker - Autonomously</h3><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">Cyera Research Labs disclosed CVE-2026-34040 (CVSS 8.8)an incomplete fix for the 2024 perfect-10 vulnerability CVE-2024-41110. When an API request body exceeds 1 MB, Docker&#39;s middleware silently drops it before the AuthZ plugin inspects it, while the daemon processes the full payload and creates the requested container potentially with privileged access to the host filesystem. The attack requires one crafted HTTP request, no credentials, and no special tooling. Fixed in Docker Engine 29.3.1 (released March 25).</p><p class="paragraph" style="text-align:left;">What elevates this beyond a standard container escape: Cyera demonstrated that AI coding agents running inside Docker-based sandboxes can be tricked into exploiting it via prompt injection hidden in a GitHub repository and, more alarmingly, can independently discover and construct the exploit themselves while attempting legitimate debugging tasks.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> This is the first publicly documented case where an AI coding agent autonomously discovers and executes a container escape as a side-effect of a legitimate developer task. The blast radius extends from full host compromise to cloud credential theft, Kubernetes cluster takeover, and SSH access to production servers.</p><p class="paragraph" style="text-align:left;"><b>Immediate actions:</b></p><ul><li><p class="paragraph" style="text-align:left;">Patch to Docker Engine 29.3.1: verify with <span style="color:rgb(24, 128, 56);">docker version --format &#39;{{.</span><span style="color:rgb(24, 128, 56);"><span style="text-decoration:underline;">Server.Version}}</span></span><span style="color:rgb(24, 128, 56);">&#39;</span></p></li><li><p class="paragraph" style="text-align:left;">Check whether AuthZ plugins are in use: <span style="color:rgb(24, 128, 56);">docker info --format </span><span style="color:rgb(24, 128, 56);"><span style="text-decoration:underline;">&#39;{{.Plugins</span></span><span style="color:rgb(24, 128, 56);">.Authorization}}&#39;</span></p></li><li><p class="paragraph" style="text-align:left;">Scope Docker API access aggressively; enforce rootless mode where possible</p></li><li><p class="paragraph" style="text-align:left;">Treat AI agent access to the Docker socket as a privileged identity requiring governance, not a developer convenience</p></li></ul><p class="paragraph" style="text-align:left;"><i>Sources:</i><a class="link" href="https://www.cyera.io?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow"> Cyera Research</a><i> |</i><a class="link" href="https://thehackernews.com?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow"> The Hacker News</a><i> |</i><a class="link" href="https://www.esecurityplanet.com?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow"> eSecurity Planet</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-cisco-breached-via-cicd-supply-ch">🚨<b> 2. </b>💣 Cisco Breached via CI/CD Supply Chain</h3><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">Attackers exploited a compromised GitHub Action linked to the Trivy vulnerability scanner, stealing CI/CD credentials and breaching Cisco&#39;s internal development environment. Over 300 repositories and AWS keys were accessed.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> This is a textbook example of transitive trust failure in the CI/CD pipeline and it is becoming the dominant pattern for cloud infrastructure compromise. The attacker did not breach Cisco directly; they breached a tool that Cisco trusted. For cloud security leaders, this reinforces three non-negotiable controls: enforce short-lived credentials and workload identity (no static keys, ever); implement artifact integrity validation using SLSA and Sigstore; and extend your monitoring posture to detect pipeline-level anomalies, not just runtime threats. The Cisco breach also illustrates why Jasson Casey&#39;s point about identity as the systematic answer resonates if every workload, tool, and pipeline step had device-bound, attributable identity, the blast radius of a compromised GitHub Action would be dramatically contained.</p><p class="paragraph" style="text-align:left;"><i>Sources:</i><a class="link" href="https://www.darkreading.com?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow"> Dark Reading</a><i> |</i><a class="link" href="https://www.bleepingcomputer.com?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow"> BleepingComputer</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-microsoft-human-only-defense-is-d"><b>☁️ 3. </b>⚡ Microsoft: Human-Only Defense Is Dead</h3><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">Microsoft&#39;s Security Blog, published April 2 from RSAC 2026, reveals that AI is no longer just a tool for attackers it now accelerates every phase of the kill chain from reconnaissance to persistence. Microsoft&#39;s Threat Intelligence team introduced the &quot;agentic threat model&quot; as the new defensive paradigm, citing Tycoon2FA (linked to Storm-1747), which generated tens of millions of phishing emails monthly and compromised roughly 100,000 organizations. Mandiant&#39;s M-Trends 2026 report documented attacker hand-off time collapsing to just 22 seconds. Microsoft declared human-only defense is no longer viable.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> This isn&#39;t a vendor positioning statement, it&#39;s a structural shift in the threat model that should directly inform SOC staffing strategy, tool investment, and AI security governance. The 22-second hand-off figure means that detection-to-containment workflows built around human review cycles are architecturally insufficient. Security leaders building 2026 roadmaps need to factor agentic playbooks and AI-assisted response into their operating model, not as aspirational initiatives, but as baseline requirements. This directly reinforces the conversation with Jasson Casey this week about why security teams not adopting agentic workflows are already behind.</p><p class="paragraph" style="text-align:left;"><i>Sources:</i><a class="link" href="https://www.microsoft.com/en-us/security/blog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow"> Microsoft Security Blog</a><i> |</i><a class="link" href="https://www.mandiant.com?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow"> Mandiant M-Trends 2026</a><i> |</i><a class="link" href="https://siliconangle.com?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow"> SiliconANGLE</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-crowd-strike-bets-116-b-on-identi">🏥<b> 4. </b>🧠 CrowdStrike Bets $1.16B on Identity + Browser</h3><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">CrowdStrike&#39;s two Q1 mega-dealsSGNL ($740M, continuous identity authorization) and Seraphic Security ($420M, enterprise browser protection)closed this month, representing $1.16B in combined spend and the platform&#39;s most significant capability expansion since the Humio acquisition. SGNL replaces static RBAC with real-time, context-aware authorization decisions for every API call, SaaS session, and AI workload. Seraphic adds a browser-native agent to Falcon, targeting the exploding threat surface created by browser-based SaaS access and AI coding assistants.</p><p class="paragraph" style="text-align:left;"><b>Why it matters:</b> For enterprise buyers already on Falcon, this is a consolidation forcing function. SGNL&#39;s continuous authorization capability directly addresses AI non-human identity risk gap that most identity programs currently leave wide open. Seraphic&#39;s approach of instrumenting the browser runtime (rather than deploying a proxy) produces richer telemetry and lower latency, which matters for high-frequency SaaS and developer workflows. Expect Palo Alto, Microsoft, and SentinelOne to respond with counter-positioning. Security architects should revisit their CrowdStrike roadmap conversations now, but with realistic expectations: integration lags are real, and buying into a new module 6–9 months post-close carries meaningful integration risk. This acquisition also validates exactly what Jasson Casey describes this week that continuous, data-plane identity enforcement is becoming the core of the modern security stack.</p><p class="paragraph" style="text-align:left;"><i>Sources:</i><a class="link" href="https://www.bankinfosecurity.com?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow"> BankInfoSecurity</a><i> |</i><a class="link" href="https://www.csoonline.com?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow"> CSO Online</a><i> |</i><a class="link" href="https://www.globenewswire.com?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow"> GlobeNewswire</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="what-you-should-do-this-week">🛠️ WHAT YOU SHOULD DO THIS WEEK </h3><h3 class="heading" style="text-align:left;" id="immediate-actions">Immediate actions:</h3><ul><li><p class="paragraph" style="text-align:left;">Patch Docker → <b>29.3.1</b></p></li><li><p class="paragraph" style="text-align:left;">Treat AI agents as <b>privileged identities (not tools)</b></p></li><li><p class="paragraph" style="text-align:left;">Kill static credentials in CI/CD → move to <b>workload identity</b></p></li><li><p class="paragraph" style="text-align:left;">Add <b>runtime visibility for tool execution</b></p></li><li><p class="paragraph" style="text-align:left;">Audit which tools your agents can call</p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="why-identity-is-the-only-systematic"><b>Why Identity Is the Only Systematic Answer to the Agentic Threat Model</b></h3><p class="paragraph" style="text-align:left;">The conversation this week with Jasson Casey surfaces a problem that most enterprise security programs have not yet structurally addressed: AI agents are not users, not services, and not endpoints in the traditional sense but they behave like all three simultaneously. That gap is precisely where adversaries are beginning to operate.</p><p class="paragraph" style="text-align:left;">The agentic threat model is not a future concern. It is happening in your developer workflows right now, on managed machines, unmanaged machines, and contractor devices alike. And the controls that most organizations have network controls, DLP, SIEM, EDR were not designed with this operating model in mind. The question is no longer whether you have an AI security gap. It is whether you have a systematic way to close it.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="featured-experts-this-week"><b>Featured Experts This Week </b>🎤</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/jassoncasey/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow"><b>Jasson Casey</b></a><b> - </b>Co-founder & CEO, Beyond Identity</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Non-Human Identity (NHI):</b> Machine identities associated with workloads, agents, scripts, and services rather than human users. AI coding agents create a new and particularly complex category of NHI because they operate autonomously, call tools, access credentials, and make decisions without direct human supervision at the moment of action.</p></li><li><p class="paragraph" style="text-align:left;"><b>Device-Bound Identity:</b> An authentication credential cryptographically tied to the physical device hardware, making it non-exportable and non-phishable. Unlike session tokens or API keys, device-bound credentials cannot be stolen and replayed from a different machine.</p></li><li><p class="paragraph" style="text-align:left;"><b>Prompt Injection:</b> An attack technique where malicious instructions are embedded in content that an AI agent will process through tool outputs, file contents, web pages, or API responses causing the agent to take actions that were not intended by the user or operator. Jasson Casey notes that prompt injection does not have to happen all at once; it can be staged across multiple tool calls, leveraging how transformers associate related context.</p></li><li><p class="paragraph" style="text-align:left;"><b>Living Off the Land (LoTL):</b> An attack technique where adversaries use legitimate system tools and processes already present on a target to conduct malicious activity, avoiding the need to introduce new malware. Casey draws a direct parallel between this and AI agent tool execution, every tool call is a potential LoTL vector.</p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <a class="link" href="https://links.cloudsecuritypodcast.tv/tines-workflow-event-2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow"><b>Tines</b></a></p><p class="paragraph" style="text-align:center;">Move Past AI Hype to Build Secure Scalable Workflows</p><p class="paragraph" style="text-align:center;"><a class="link" href="https://links.cloudsecuritypodcast.tv/tines-workflow-event-2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow"><b>Hear how leaders at HubSpot, Asana, Jamf, ASOS and Riot Games</b></a><b> </b>are scaling AI and automation in real security and operations workflows. AI’s real impact doesn’t happen in isolation. It comes from experimentation and learning from teams already leading the way.</p><p class="paragraph" style="text-align:center;">Join Workflow, Tines’ flagship virtual event streaming live from New York on May 6. Discover how teams are moving beyond AI paralysis, scaling automation responsibly, and building workflows that eliminate busywork. </p><p class="paragraph" style="text-align:center;">Discover how teams are moving beyond AI paralysis, scaling automation responsibly, and reducing manual security and operational work.</p><p class="paragraph" style="text-align:center;"><a class="link" href="https://links.cloudsecuritypodcast.tv/tines-workflow-event-2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">Save your Spot</a></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><hr class="content_break"><h3 class="heading" style="text-align:left;" id="the-shadow-ai-framing-is-costing-yo"><b>The Shadow AI Framing Is Costing You Time You Don&#39;t Have</b></h3><p class="paragraph" style="text-align:left;">Organizations are spending enormous cycles trying to enumerate and govern unauthorized AI tool usage shadow AI discovery products are already advertising in airport terminals, as Casey noted. But shadow AI governance is, at best, a starting point. It answers the &quot;what do we have&quot; question. It does not answer the &quot;how do we systematically secure it&quot; question.</p><p class="paragraph" style="text-align:left;">As Casey put it: <i>&quot;Shadow AI is kind of the way of getting the conversation started. A lot of organizations are kind of thinking about, well, let&#39;s just number one figure out what we have. And that&#39;s a great way to start because again, like without identify, you can&#39;t really run the other CSF functions. But I would argue it is just the tip of the iceberg.&quot;</i></p><p class="paragraph" style="text-align:left;">The real problem is not that employees are using AI tools without permission. The real problem is that those AI tools, code assistants, agents, browser plugins are running on machines with access to your intellectual property, your credentials, and your production infrastructure, with no systematic visibility into what they are doing at the tool execution level.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="every-tool-call-is-a-security-event"><b>Every Tool Call Is a Security Event</b></h3><p class="paragraph" style="text-align:left;">This is the conceptual shift that most security programs have not yet made. When a developer runs Claude Code or Cursor on their laptop, the AI model is not the risk surface the tools the model calls are. Every tool execution is a potential data exfiltration event. Every tool result is a potential prompt injection vector. And because modern agents have memory and can compact context across sessions, a prompt injection can be staged across multiple tool calls over an extended period functioning, as Casey describes, like malware persistence.</p><p class="paragraph" style="text-align:left;"><i>&quot;Every time your agent executes a tool, it&#39;s a chance for proprietary information to basically be exfil. It&#39;s a chance for maybe that tool, if it&#39;s not actually authorized or maybe even malicious, to send C2 commands back to the agent. And the agent, just like Ron Burgundy, will happily do whatever&#39;s on the teleprompter.&quot;</i></p><p class="paragraph" style="text-align:left;">The Docker CVE-2026-34040 disclosure this week makes this concrete: an AI coding agent, pursuing a legitimate debugging task, can now autonomously discover and execute a container escape. This is not a hypothetical. It is a documented proof of concept.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="control-plane-identity-is-not-enoug"><b>Control Plane Identity Is Not EnoughYou Need Data Plane Enforcement</b></h3><p class="paragraph" style="text-align:left;">Most enterprise identity programs operate at the control plane: IAM, SSO, MFA, user lifecycle management. These controls answer the question &quot;who is this user?&quot; at the moment of authentication. They do not answer the question &quot;what is this workload doing right now, and should it be allowed to continue?&quot;</p><p class="paragraph" style="text-align:left;">Casey&#39;s argument is direct: <i>&quot;It&#39;s not enough to only be in the control plane. You have to also be in the data plane. Otherwise you cannot be a point of enforcement. And we think code assistant agents, specifically AI agents in general, are kind of the forcing function for that.&quot;</i></p><p class="paragraph" style="text-align:left;">The practical implication for enterprise security architects is significant. The security stack you have todaySIEM, EDR, IAMwas designed around a human-centric, session-based model of access. AI agents operate continuously, autonomously, and across multiple systems simultaneously. Retrofitting human-oriented identity controls onto agentic workloads is not a solution; it is a temporary mitigation at best.</p><p class="paragraph" style="text-align:left;">What the new model requires is device-bound identity for every workload including the AI agent itself so that every tool call, every API interaction, and every data access is attributable to a specific, verified identity. This gives you the chain of provenance needed to detect anomalies, respond to incidents, and reason about blast radius.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="the-systematic-answer-identity-as-t"><b>The Systematic Answer: Identity as the Security Architecture Core</b></h3><p class="paragraph" style="text-align:left;">Rather than choosing between blocking all AI usage and accepting all AI risk the &quot;barbell&quot; that both Casey and Ashish Rajan observe across their customer baseCasey&#39;s framework offers a third path: a lightweight, identity-anchored security context that wraps the agent at launch, monitors its behavior continuously, and kills the session when risk thresholds are crossed.</p><p class="paragraph" style="text-align:left;">This approach addresses multiple problems simultaneously:</p><p class="paragraph" style="text-align:left;"><b>Credential theft and session hijacking</b> are eliminated when agent credentials are device-bound and non-exportable. The Reddit story Casey references an $80,000 Anthropic API bill after a key was compromised becomes structurally impossible when keys cannot be stolen and replayed.</p><p class="paragraph" style="text-align:left;"><b>Prompt injection management</b> becomes tractable when every tool and every agent has an attributed identity, creating a chain of provenance across the entire interaction. You may not be able to prevent every prompt injection attempt, but you can detect when an agent&#39;s behavior deviates from expected patterns and terminate the session.</p><p class="paragraph" style="text-align:left;"><b>Discovery </b>the first function of the NIST CSF becomes automated rather than manual, because the identity system that launches the agent also inventories the tools, MCP connections, plugins, sub-agents, and local permissions it has access to.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="agentic-security-playbooks-are-not-"><b>Agentic Security Playbooks Are Not Optional</b></h3><p class="paragraph" style="text-align:left;">For SOC teams and detection engineers, Casey&#39;s message is direct: if your security team is not building agentic playbooks now, you are already behind. The model he describes is not simply &quot;use AI in your SOC.&quot; It is a specific architectural pattern: decompose your security workflows into probabilistic nodes (where LLM judgment is appropriate) and deterministic nodes (where a script executes with perfect fidelity). Connect them deliberately.</p><p class="paragraph" style="text-align:left;"><i>&quot;If your security teams aren&#39;t building this out already number one, they&#39;re getting behind. Number two, you can use that for controls verification, controls research, detection playbooks, actual detection. It&#39;s actually really, really good at prototyping.&quot;</i></p><p class="paragraph" style="text-align:left;">Casey&#39;s own team demonstrated this in practice: in four hours, using open-source models from Hugging Face, they built a real-time audio impersonation capability capable of producing convincing voicemails from just seven seconds of audio sampling with zero-shot training and no fine-tuning. The point is not that this specific capability is the threat. The point is that your adversaries have access to the same tools, the same models, and the same four-hour build timeline. The security teams who have internalized this reality are building defenses that match it. The ones who haven&#39;t are waiting to be surprised.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="architecture-is-the-forcing-functio"><b>Architecture Is the Forcing Function</b></h3><p class="paragraph" style="text-align:left;">One of the most practically useful frames from Casey&#39;s conversation is the question he poses about enterprise architecture: if you were starting your business today, what would you actually need? GitHub for code. Claude Code or Codex for AI-native development. Email. What else is genuinely necessary, versus a legacy of tools acquired when those were the only options available?</p><p class="paragraph" style="text-align:left;">This is not an argument for reckless consolidation. It is an argument for honest architectural review specifically, for identifying which elements of your current security stack were designed for a human-centric, session-based threat model and which can genuinely extend to cover agentic workloads. Casey&#39;s view is that the simplifying architecture for the new stack places identity at the core, with SIEM and EDR retaining their value for behavioral analytics and data collection, but many workflow-centric SaaS products becoming candidates for replacement by AI-native alternatives.</p><p class="paragraph" style="text-align:left;">For security leaders building 2026 roadmaps, this conversation is a prompt to ask: what in my current architecture assumes a human is making every decision? And what happens to those assumptions when the answer is increasingly no?</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>📚 RELATED RESOURCES 🎧</b></h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://beyondidentity.ai?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">Beyond Identity Ceros Product (Free Trial)</a> - The product Jasson Casey references for AI agent identity and secure context management</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.nist.gov/system/files/documents/2023/01/26/AI-RMF-001.pdf?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">NIST AI Risk Management Framework (AI RMF)</a> - Foundational framework for governing AI systems in enterprise environments</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cisa.gov/ai?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">CISA Guidance on AI-Enabled Threats</a> - Federal guidance on securing AI systems and defending against AI-enhanced attacks</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://sigstore.dev?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">SigstoreSoftware Supply Chain Signing</a> - Open-source tooling for artifact integrity, directly relevant to CI/CD pipeline defense</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://slsa.dev?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">SLSA Framework</a> - Supply chain integrity levels for software artifacts</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.microsoft.com/en-us/security/blog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">Microsoft Security BlogRSAC 2026 Coverage</a> - Primary source for the agentic threat model and Mandiant M-Trends 2026 data</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cyera.io?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">Cyera Research CVE-2026-34040 Disclosure</a> - Technical details on the Docker AuthZ bypass and AI agent exploitation proof of concept</p></li></ul><h3 class="heading" style="text-align:left;" id="podcast-episode"><b>Podcast Episode</b></h3><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/solving-prompt-injection-shadow-ai-for-ai-malware?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast -Full Episode with Jasson Casey</a> - Complete transcript and audio for this week&#39;s featured conversation</p></li></ul><hr class="content_break"><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔<b> </b><span style="color:rgb(20, 19, 34);"> </span> If your AI agents had identities today, what’s the first behavior you’d monitor?<br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-can-now-exploit-docker-and-your-ci-cd-is-next" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=9a2f8e0a-3fe6-406e-8237-e7f5b0c9bc67&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🚨TeamPCP  &amp; Axios Supply Chain Under Siege: Lessons from the CISO Playbook for AI-Accelerated AppSec</title>
  <description>This edition covers the most consequential software supply chain attack since XZ Utils the TeamPCP campaign that compromised Trivy, LiteLLM, Telnyx, and the Axios npm package across five developer ecosystems while Cloudflare&#39;s former CSO Joe Sullivan and StackHawk co-founder Scott Gerlach share hard-won lessons on why Application Security, runtime testing, and AI-augmented development teams are reshaping the CISO&#39;s mandate in 2026. Keywords: supply chain attack, AppSec, DAST, CI/CD security, Vertex AI permissions, CISO operating model, AI-accelerated development, runtime security.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a37f8079-ed75-47b1-8be7-673552d697e1/Screenshot_2026-04-01_at_10.47.08_PM.png" length="1737010" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/supply-chain-attack-trivy-litellm-axios-appsec-ai-2026</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/supply-chain-attack-trivy-litellm-axios-appsec-ai-2026</guid>
  <pubDate>Wed, 01 Apr 2026 21:48:59 +0000</pubDate>
  <atom:published>2026-04-01T21:48:59Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><h2 class="heading" style="text-align:left;" id="hello-from-the-cloudverse"><span style="background-color:#28EEDA;"><b>Hello from the Cloud-verse!</b></span></h2><p class="paragraph" style="text-align:left;">This week’s Cloud Security Newsletter topic<b>: </b><b>AppSec in the AI Era: Why Your 2026 Program Is Already Broken and What to Build Instead</b><b> </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" rel="noopener noreferrer nofollow">(continue reading)</a> </p><hr class="content_break"><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec"><span class="button__text" style=""> This issue is sponsored by Varonis </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a37f8079-ed75-47b1-8be7-673552d697e1/Screenshot_2026-04-01_at_10.47.08_PM.png?t=1775080043"/></a></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;">The week of March 25–31, 2026 will be remembered as a watershed moment for cloud-native supply chain security. In the span of nine days, a single threat actor group weaponized four of the most trusted tools in the DevSecOps ecosystem turning a security scanner, an AI proxy, a telephony SDK, and a ubiquitous JavaScript HTTP client into credential harvesting machines targeting the AWS IAM keys, GCP service accounts, and Kubernetes secrets of thousands of enterprise pipelines worldwide.</p><p class="paragraph" style="text-align:left;">What makes this week&#39;s news especially instructive is its timing: it arrives just as two of the most experienced voices in enterprise security, Joe Sullivan, former CSO of Cloudflare, Facebook, and Uber, and Scott Gerlach, co-founder and CSO of StackHawk, sat down to share their unfiltered views on how Application Security must fundamentally reinvent itself for the AI era.</p><p class="paragraph" style="text-align:left;">Their conversation cuts to the heart of why this week&#39;s attacks succeeded: security teams that are reactive, tool-dependent without context, and not embedded in the engineering loop are now structurally exposed. The fix is neither simple nor quick, but the blueprint is clearer than it has ever been. <i>[</i><a class="link" href="https://www.aisecuritypodcast.com/videos/questions-every-ciso-must-ask-ai-security-vendors?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">⚡ TL;DR for Busy Readers</h2><ul><li><p class="paragraph" style="text-align:left;">The TeamPCP supply chain campaign compromised Trivy, LiteLLM, Telnyx, and 100M+ download Axios to rotate all CI/CD secrets from March 19–31 now.</p></li><li><p class="paragraph" style="text-align:left;">Citrix NetScaler CVE-2026-3055 (CVSS 9.3) is actively exploited to patch SAML IDP-configured appliances before your next maintenance window.</p></li><li><p class="paragraph" style="text-align:left;">Google Vertex AI agents inherit dangerously broad IAM permissions by default and adopt BYOSA architecture for every agentic workload immediately.</p></li><li><p class="paragraph" style="text-align:left;">AI is 10x-ing code velocity and vulnerability volume simultaneouslyAppSec must embed in the engineering loop, not review from the outside.</p></li><li><p class="paragraph" style="text-align:left;">The CISO role is expanding to own AI transformation, curiosity, adaptability, and business enablement are now core job requirements.</p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="this-weeks-security-news">📰 <b>THIS WEEK&#39;S TOP 5 SECURITY HEADLINES</b></h2><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-team-pc-ps-cascading-supply-chain"><b> </b>🚨<b> 1. TeamPCP&#39;s Cascading Supply Chain Campaign Pivots to Ransomware After Breaching Five Ecosystems</b></h3><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">Between March 19–27, the financially motivated threat group TeamPCP (also tracked as PCPcat, ShellForce, and CipherForce) executed a cascading software supply chain attack across five developer ecosystems: GitHub Actions, Docker Hub, npm, PyPI, and OpenVSX. The attack chain opened with the group force-pushing malicious code to 76 of 77 version tags of Aqua Security&#39;s Trivy container scanner exploiting an unsanitized GitHub Actions workflow to harvest credentials from thousands of CI/CD pipelines. Using those stolen credentials, TeamPCP sequentially compromised Checkmarx KICS IDE extensions, the LiteLLM AI proxy package (~480M PyPI downloads), and the Telnyx Python SDK. A credential-stealing payload tracked as CVE-2026-33634 (CVSS 9.4) was purpose-built to exfiltrate AWS IAM keys, GCP service account credentials, Azure environment variables, and Kubernetes secrets. As of March 30, TeamPCP has paused new supply chain compromises and announced a ransomware partnership with the new Vect RaaS operation with at least one confirmed Vect ransomware deployment using TeamPCP-harvested credentials.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">This is the most consequential DevSecOps supply chain attack since XZ Utils, and it carries a threat profile specific to cloud and AI infrastructure teams. Three aspects demand immediate attention.</p><p class="paragraph" style="text-align:left;">First, the attack deliberately weaponized security tooling. Trivy and Checkmarx KICS are not peripheral dependencies they are tools granted elevated pipeline access by design. Any organization that ran these tools between March 19–27 without pinning to verify commit SHAs should treat its CI/CD credentials as fully compromised. Microsoft Defender for Cloud confirmed the core attack chain harvested AWS IAM, GCP, and Azure environment variables alongside Kubernetes secret enumeration across affected runners.</p><p class="paragraph" style="text-align:left;">Second, the LiteLLM compromise represents a novel AI infrastructure attack vector. LiteLLM functions as a unified gateway to over 100 LLM APIsOpenAI, Anthropic, AWS Bedrock, Vertex AI meaning a single compromised instance exposes every AI provider credential the organization holds.</p><p class="paragraph" style="text-align:left;">Third, the pivot to ransomware monetization signals the attack is far from over. TeamPCP is estimated to hold a 300GB trove of harvested credentials. Breach disclosures and extortion attempts are expected to increase through Q2 2026.</p><p class="paragraph" style="text-align:left;"><b>Recommended Actions:</b> Immediately rotate all secrets accessible to pipeline runners that executed Trivy, Checkmarx KICS, or LiteLLM between March 19–27. Pin all GitHub Actions to full commit SHAs. Audit runner logs for outbound connections to <span style="color:rgb(24, 128, 56);">checkmarx[.]zone</span>, <span style="color:rgb(24, 128, 56);">models.litellm[.]cloud</span>, or <span style="color:rgb(24, 128, 56);">tpcp.tar.gz</span> archives. Treat low-impact credential alerts from this period as high-priority indicators of impending secondary intrusion.</p><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://www.sans.org/blog/when-security-scanner-became-weapon-inside-teampcp-supply-chain-campaign?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow"> SANS Institute</a> |<a class="link" href="https://securitylabs.datadoghq.com/articles/litellm-compromised-pypi-teampcp-supply-chain-campaign/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow"> Datadog Security Labs</a> |<a class="link" href="https://www.akamai.com/blog/security-research/2026/mar/telnyx-pypi-2026-teampcp-supply-chain-attacks?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow"> Akamai</a> |<a class="link" href="https://www.infosecurity-magazine.com/news/teampcp-litellm-pypi-supply-chain/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow"> Infosecurity Magazine</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-axios-npm-hijack-north-korean-att">🚨<b> 2. Axios npm Hijack: North Korean-Attributed RAT Hits 100M+ Weekly Downloads</b></h3><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">An unknown attacker compromised the GitHub and npm accounts of the main developer of Axios, a widely used HTTP client library, and published npm packages backdoored with a malicious dependency that triggered the installation of droppers and remote access trojans. The attack was pre-staged approximately 18 hours before detonation. The malicious versions (axios@1.14.1 and axios@0.30.4) were live for roughly three hours before removal on March 31. On April 1, 2026, Google Threat Intelligence Group publicly attributed the compromise to UNC1069, a North Korea-nexus, financially motivated threat actor, based on infrastructure overlaps and the use of WAVESHAPER.V2an updated backdoor linked to the group&#39;s earlier activity. Although the malicious versions were removed within hours, Axios&#39;s presence in roughly 80% of cloud and code environments enabled rapid exposure, with observed execution in 3% of affected environments according to Wiz researchers.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">This is arguably the highest blast-radius npm compromise on record. The attack surface is your vendor&#39;s vendor&#39;s vendor and this is what that looks like in practice. Organizations that had lockfiles pinning Axios to a specific version, or CI/CD policies that suppress automatic install scripts, were protected. Organizations that did not have a window of exposure measured in hours, with consequences that may take weeks to fully assess. The North Korean attribution connects this to a broader pattern of DPRK-linked actors targeting developer supply chains to harvest credentials and establish persistent access in cloud environments. The convergence with TeamPCP activity itself linked to LAPSUS$ extortion suggests a coordinated effort to stockpile access across enterprise environments.</p><p class="paragraph" style="text-align:left;"><b>Immediate Actions:</b> Downgrade to axios@1.14.0 (or @0.30.3 for legacy users). Rotate all cloud keys, repository tokens, and API credentials exposed in affected environments. Check for outbound connections to <span style="color:rgb(24, 128, 56);"><a class="link" href="https://sfrclak.com:8000?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow">sfrclak.com:8000</a></span>. Inspect CI/CD pipeline logs for the exposure window: 00:21–03:15 UTC, March 31, 2026.</p><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://thehackernews.com/2026/03/axios-supply-chain-attack-pushes-cross.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow"> The Hacker News</a> |<a class="link" href="https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow"> StepSecurity</a> |<a class="link" href="https://www.huntress.com/blog/supply-chain-compromise-axios-npm-package?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow"> Huntress</a> |<a class="link" href="https://www.sans.org/blog/axios-npm-supply-chain-compromise-malicious-packages-remote-access-trojan?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow"> SANS Institute</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-google-vertex-ai-double-agent-fla"><b>☁️ 3. Google Vertex AI &quot;Double Agent&quot; Flaw: AI Platform Permissions Create Cloud-Wide Exposure</b></h3><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">Palo Alto Networks Unit 42 disclosed a structural &quot;blind spot&quot; in Google Cloud&#39;s Vertex AI platform: the Per-Project, Per-Product Service Agent (P4SA) associated with AI agents deployed via the Agent Development Kit (ADK) carries dangerously broad permissions by default. An attacker can craft a malicious AI agent as a serialized Python pickle file, deploy it on Vertex AI&#39;s Reasoning Engine, query Google&#39;s metadata service to extract P4SA credentials, then break out of the isolated agent environment and operate as a highly privileged service account gaining unrestricted read access to all GCS buckets and restricted Artifact Registry repositories in the project. Google has addressed the issue by revising its documentation and now strongly recommends a Bring Your Own Service Account (BYOSA) architecture for all Vertex AI deployments.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">This research surfaces a structural risk that will only grow as enterprises accelerate agentic AI deployments. AI agents are service identities with real permissions; they must be governed through your existing IAM framework, not treated as &quot;just an app.&quot; The attack chain requires no zero-day: it abuses default configuration. Every organization running Vertex AI Agent Engine workloads should immediately audit P4SA permission scopes, move to BYOSA architectures, and apply IAM least-privilege review cycles before any agentic workload reaches production. The broader principle surfaced directly in this week&#39;s guest conversation is that non-deterministic AI code operating with overprivileged identities is the defining runtime security risk of 2026.</p><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://thehackernews.com/2026/03/vertex-ai-vulnerability-exposes-google.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow"> The Hacker News</a> |<a class="link" href="https://unit42.paloaltonetworks.com/double-agents-vertex-ai/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow"> Unit 42 / Palo Alto Networks</a> |<a class="link" href="https://www.securityweek.com/google-addresses-vertex-security-issues-after-researchers-weaponize-ai-agent/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow"> SecurityWeek</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-lapsus-claims-astra-zeneca-breach">🏥<b> 4. LAPSUS$ Claims AstraZeneca Breach: Cloud Configs, Source Code, and CI/CD Secrets for Sale</b></h3><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">LAPSUS$ claimed responsibility for an alleged breach of AstraZeneca, posting on their Tor-based leak site and dark web forums. The group asserts they exfiltrated approximately 3GB of internal data including source code (Java, Angular, Python), cloud infrastructure configurations (AWS, Azure, Terraform), employee records, and access credentials including private RSA keys, vault data, and GitHub Enterprise tokens. On March 27, LAPSUS$ released sample data and added health data company Virta Health to their target list. AstraZeneca has not issued a public statement. Attribution in cybercrime forums is inherently unverified.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">The healthcare and life sciences sector has become a primary target for data extortion, and this incident illustrates why cloud infrastructure configurationsnot source codeare the true crown jewel. If verified, the inclusion of Terraform files, AWS/Azure configs, and CI/CD secrets gives adversaries a complete blueprint of the cloud environment and the keys to access it. LAPSUS$ is evolving from public-shame extortion toward quiet data brokerage offering full datasets to vetted buyers rather than dumping them publicly. This shift demands more proactive dark-web monitoring and rapid takedown incident-response playbooks for situations where IaC configs and secrets appear for sale.</p><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://cybernews.com/security/astrazeneca-hackers-claim-source-code-breach/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow"> Cybernews</a> |<a class="link" href="https://www.securityweek.com/extortion-group-claims-it-hacked-astrazeneca/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow"> SecurityWeek</a> |<a class="link" href="https://socradar.io/blog/astrazeneca-data-breach-what-to-know/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow"> SOCRadar</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-google-workspace-deploys-ai-power"><b>🛡️ 5. Google Workspace Deploys AI-Powered Ransomware Detection at GAEnabled by Default</b></h3><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">Google moved its ransomware detection and file restoration features for Google Drive into General Availability on March 31, 2026. The updated AI model detects 14× more infections than the beta version, automatically pauses Drive file syncing upon detection, sends real-time alerts to users and admins via the Admin console Security Center, and enables bulk file restoration to pre-infection versions. Both features are enabled by default across Business, Enterprise, Education, and Frontline plans. Drive for Desktop v114 or later is required for full alert functionality on endpoints.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">This is a meaningful defensive capability at SaaS scale: automatic detection, sync interruption, and bulk file restoration without requiring a SIEM alert or analyst intervention. The operational priority is immediate: validate Drive for Desktop v114+ deployment coverage across your endpoint estate via MDM, verify admin alerting is configured in the Admin console Security Center, and confirm which OUs have the feature enabled. This is now table-stakes capability alongside Microsoft OneDrive&#39;s equivalent ransomware protection for Microsoft 365 subscribers.</p><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://workspaceupdates.googleblog.com/2026/03/ransomware-detection-and-file-restoration-for-Google-Drive-now-generally-available.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow"> Google Workspace Updates Blog</a> |<a class="link" href="https://www.bleepingcomputer.com/news/security/google-drive-ransomware-detection-now-on-by-default-for-paying-users/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow"> BleepingComputer</a></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="app-sec-in-the-ai-era-why-your-2026"><b>AppSec in the AI Era: Why Your 2026 Program Is Already Broken and What to Build Instead</b></h3><p class="paragraph" style="text-align:left;">If there is a single thread connecting every story in this week&#39;s news brief and the most important insight from Joe Sullivan and Scott Gerlach&#39;s conversation is this: the security practices that felt adequate eighteen months ago are structurally insufficient for the speed and scale at which code is now being produced.</p><p class="paragraph" style="text-align:left;">The TeamPCP and Axios supply chain attacks did not succeed because of exotic zero-days. They succeeded because developer tooling runs with elevated privileges in CI/CD pipelines, those pipelines assume everything upstream is trusted, and security teams have historically reviewed artifacts after the fact rather than validating the supply chain in motion. The attacks exploited the gap between how fast modern development moves and how slowly security has adapted to that velocity.</p><p class="paragraph" style="text-align:left;">Joe Sullivan and Scott Gerlach spent a significant portion of their conversation mapping exactly this gap and what it will take to close it.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="featured-experts-this-week"><b>Featured Experts This Week </b>🎤</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/joesu11ivan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow"><b>Joe Sullivan</b></a><b> - </b>Security Consultant & CEO of Ukraine Friends | Former CSO of Cloudflare, Uber, and Facebook | Former Federal Cybercrime Prosecutor, US Department of Justice</p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/scott-gerlach-kaakaww/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow"><b>Scott Gerlach</b></a><b> - </b>Co-founder & Chief Security Officer, StackHawk | Former CSO at Stride </p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><b>DAST (Dynamic Application Security Testing):</b> Security testing of running applications testing behavior, not just source code. Unlike SAST (Static Analysis), DAST reflects how the application actually behaves under attack conditions, dramatically reducing false positives.</p></li><li><p class="paragraph" style="text-align:left;"><b>Legacy DAST vs. Modern DAST:</b> Legacy DAST tests known, publicly facing production assets on a quarterly or annual cadence generating high false positive rates due to WAFs, CDNs, and incomplete coverage. Modern DAST tests every microservice, every PR/MR, 5–10 times per day in the pre-production environment, with near-zero false positives and developer-attributed findings.</p></li><li><p class="paragraph" style="text-align:left;"><b>BYOSA (Bring Your Own Service Account):</b> Google&#39;s recommended architecture for Vertex AI deployments, in which each AI agent is assigned a customer-managed service account with scoped, least-privilege permissions rather than inheriting the default P4SA with its dangerously broad default access.</p></li><li><p class="paragraph" style="text-align:left;"><b>P4SA (Per-Project, Per-Product Service Agent):</b> The default privileged identity automatically assigned to AI agents deployed on Google Cloud&#39;s Vertex AI platform. Unit 42 demonstrated that P4SA credentials can be extracted and abused to gain unrestricted access to GCS buckets, Artifact Registry, and Google Workspace data.</p></li><li><p class="paragraph" style="text-align:left;"><b>Supply Chain Attack:</b> A cyberattack that compromises software, tooling, or dependencies upstream of the target reaching downstream victims automatically when they install or update the poisoned component.</p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <b><a class="link" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow">Varonis</a></b></p><p class="paragraph" style="text-align:center;"><i>AI Security Requires More Than Visibility. It Requires Control. </i></p><p class="paragraph" style="text-align:left;"><i>Security leaders are under pressure to enable AI innovation while managing a rapidly expanding attack surface across cloud, identity, and data layers. AI agents and copilots can introduce new access paths, automated high-impact actions, and accelerate threat timelines. </i></p><p class="paragraph" style="text-align:left;"><i><a class="link" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow">Varonis Atlas</a></i><i> helps organizations secure AI end-to-end - from understanding usage and enforcing guardrails to detecting suspicious activity and reducing risk dynamically. Join our </i><i><a class="link" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(17, 85, 204)">upcoming webinar to learn how Varonis Atlas</a></i><i> can help security teams operationalize AI security at scale. </i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><hr class="content_break"><h3 class="heading" style="text-align:left;" id="the-ai-development-tidal-wave-has-o"><b>The AI Development Tidal Wave Has Outpaced Every AppSec Program Built Before 2026</b></h3><p class="paragraph" style="text-align:left;">Scott Gerlach opens the conversation with a statement that every security leader should internalize: <i>&quot;Before, I would say even the end of last year, the AppSec programs were really still kind of reactive and just trying to keep up as best they could. And then AI gets down and everyone&#39;s like, wow, we&#39;re way behind now.&quot;</i>Scott Gerlach</p><p class="paragraph" style="text-align:left;">This is not a theoretical concern, it is the structural reality that allowed the TeamPCP campaign to succeed. Developers using AI-assisted coding tools are generating code at a pace that far outstrips the traditional security review cadence. When a security team is still triaging tickets from the last sprint while this sprint&#39;s code has already shipped, they are not operating a security program, they are operating an audit log.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="the-10-x-vulnerability-problem-and-"><b>The 10x Vulnerability Problem and Why Tickets Are the Wrong Unit of Work</b></h3><p class="paragraph" style="text-align:left;">Joe Sullivan adds precision to Gerlach&#39;s observation with a point that should reframe how every AppSec team measures its own effectiveness: <i>&quot;The volume of code that they&#39;re sending over to security is 10 Xing. And unfortunately, the vulnerability volume is 10 Xing as well. And so if we&#39;re not careful, we&#39;re gonna be pushing back at them 10 x the volume of issues. And we were already in trouble for pushing back too much at them.&quot;</i>Joe Sullivan</p><p class="paragraph" style="text-align:left;">Gerlach&#39;s framing of the ticket-centric model as the telltale sign of an immature program cuts to the same point: <i>&quot;If you&#39;re making tickets, it&#39;s probably not mature enough.&quot;</i>Scott Gerlach</p><p class="paragraph" style="text-align:left;">Tickets are a batched, asynchronous communication channel. Supply chain attacks, exploited zero-days, and AI-generated vulnerabilities operate on a real-time, continuous basis. The mismatch is not recoverable through better ticket prioritization it requires a fundamentally different testing architecture.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="legacy-dast-vs-modern-dast-the-arch"><b>Legacy DAST vs. Modern DAST: The Architecture Decision That Determines Your Blast Radius</b></h3><p class="paragraph" style="text-align:left;">Gerlach&#39;s distinction between legacy and modern DAST is one of the most practically actionable frameworks in this week&#39;s conversation and it maps directly onto the supply chain risk profile of TeamPCP.</p><p class="paragraph" style="text-align:left;">Legacy DAST tests known, public-facing production applications from outside the network perimeter, through WAFs and CDNs that generate false signals. The result: 90% false positive rates, sparse coverage, and findings that arrive too late. Modern DAST runs 5–10 times per day, tests every micro service and API as it moves through the CI/CD pipeline, runs inside the development environment, and delivers findings directly to the developer who introduced the change at the moment they can actually fix it. <i>&quot;We just talked to a customer the other day who was talking about their DAST program. They&#39;re switching out they had like a 90% false positive rate. And when they test with Stack Hawk able to test closer to the thing you&#39;re testing, have more of a white box, gray box it&#39;s 90% true positive rate versus 90% false positive rate.&quot;</i>Scott Gerlach</p><p class="paragraph" style="text-align:left;">The operational implication is direct: organizations with security testing embedded inside their CI/CD pipelines have detection opportunities for compromised tooling that legacy scanning from outside production simply cannot provide.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="ai-agents-in-the-development-loop-o"><b>AI Agents in the Development Loop: Opportunity, Risk, and the Identity Model Problem</b></h3><p class="paragraph" style="text-align:left;">Gerlach describes the ideal agentic state: Claude Code or Cursor, having written a new feature, automatically triggers a DAST scan against the running application, consumes the findings, and fixes them all within the same agent loop, before a human even reviews the PR. <i>&quot;When Claude Code is done writing its feature that you ask it to write and it goesI see a hook for, I should run the app, run StackHawk against the app, and then consume the findings from that and fix them as part of the Claude Code loop. Now you&#39;re actually getting real security work into that and not burdening the developer with what is this ticket, where does this live.&quot;</i>Scott Gerlach</p><p class="paragraph" style="text-align:left;">But Sullivan immediately surfaces the counterweight and it maps precisely onto the Vertex AI &quot;Double Agent&quot; vulnerability disclosed this week: <i>&quot;A year from now, companies are gonna say, all right, we let you all run AI for a year, and you burn hundreds of thousands, if not millions of dollars on tokens. Can we get back to some deterministic software solution?&quot;</i>Joe Sullivan</p><p class="paragraph" style="text-align:left;">Gerlach captures the identity model risk that connects both threads: <i>&quot;When you&#39;re rolling those things out, thinking about the identity model and the security model that it inherits from you and you&#39;re like, wait a second, I don&#39;t want it to have this much access. How can I limit that access? And then what does that do for the enterprise? What does that scale?&quot;</i>Scott Gerlach</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="the-cis-os-expanding-mandate-from-s"><b>The CISO&#39;s Expanding Mandate: From Security Gatekeeper to AI Transformation Lead</b></h3><p class="paragraph" style="text-align:left;"><i>&quot;In 2026, the CEO is turning to IT and saying, I want you to lead the AI transformation for the company. And that person is the security leader too. So we have more responsibility and we have more interaction with the CEO. And that&#39;s not gonna go backwards.&quot;</i>Joe Sullivan</p><p class="paragraph" style="text-align:left;">For cloud security professionals, the implication is not abstract: if your CEO is asking the head of security to be the AI governance and transformation lead, the skills you invested in securing cloud-native infrastructure need to extend to governing non-deterministic, agentic systems that, as the Vertex AI research demonstrates, can become inside threats when misconfigured.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="what-the-next-generation-security-t"><b>What the Next-Generation Security Team Looks Like</b></h3><p class="paragraph" style="text-align:left;">Gerlach names the anti-pattern explicitly: <i>&quot;The people that have to have well-defined procedures and they wanna stay in the box, that&#39;s probably the anti-pattern for the next-gen security team.&quot;</i>Scott Gerlach</p><p class="paragraph" style="text-align:left;">Sullivan&#39;s prescription is equally directcuriosity is now a core security competency: <i>&quot;If you&#39;re not excited about AI and digging in and playing around with the new things, how are you going to keep up with the product and engineering teams? We can&#39;t fall for that sunk cost fallacy. We can&#39;t be resistant to change at this time. We have to be in discovery mode.&quot;</i>Joe Sullivan</p><p class="paragraph" style="text-align:left;">Security teams that embed themselves in engineering conversations about AI tooling adoptionnot auditing from outside after the fact will be in a structurally better position six months from now.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="practical-takeaways-for-cloud-secur"><b>Practical Takeaways for Cloud Security Leaders</b></h3><ul><li><p class="paragraph" style="text-align:left;"><b>Embed AppSec in the engineering loop not after it.</b> If your team is still receiving code and generating tickets, you are operating legacy AppSec. Start conversations with engineering about where security testing can run inside the CI/CD pipeline itself.</p></li><li><p class="paragraph" style="text-align:left;"><b>Shift from false positive tolerance to true positive precision.</b> A 90% false positive rate is a testing architecture problem, not a signal problem. Test inside the development environment to eliminate WAF and CDN interference.</p></li><li><p class="paragraph" style="text-align:left;"><b>Treat AI agents as service identities, not applications.</b> Apply your IAM governance framework to every agentic workload before production deployment. Default permissions are almost always too broad. BYOSA on Vertex AI; scoped service accounts everywhere else.</p></li><li><p class="paragraph" style="text-align:left;"><b>Audit your CI/CD supply chain assumptions today.</b> Pin GitHub Actions to full commit SHAs, not floating tags. Assume any runner that executed Trivy, LiteLLM, Telnyx, or Axios between March 19–31 is compromised until proven otherwise.</p></li></ul><p class="paragraph" style="text-align:left;"><b>Position security as a business enabler for AI transformation.</b> CISOs who approach AI as purely a risk management exercise will be sidelined. Those who help engineering teams ship AI features securely and at speed will own one of the most important mandates in their organization.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>📚 RELATED RESOURCES 🎧</b></h2><p class="paragraph" style="text-align:left;"><b>AppSec & DevSecOps Guidance</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.stackhawk.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow">StackHawk: Modern DAST for DevSecOps Teams</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://owasp.org/www-project-software-component-verification-standard/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow">OWASP: Software Component Verification Standard (SCVS) for Supply Chain Security</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow">CISA: Known Exploited Vulnerabilities Catalog</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.stepsecurity.io/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow">StepSecurity: Harden-RunnerFree CI/CD Pipeline Security Tool</a></p></li></ul><h3 class="heading" style="text-align:left;" id="podcast-episode"><b>Podcast Episode</b></h3><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a><b>   Episode with Scott & Joe</b></p></li></ul><hr class="content_break"><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔<b> </b><span style="color:rgb(20, 19, 34);"> </span> Is your AppSec team embedded inside the engineering AI loop or are they still reviewing tickets after the code ships?<br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=teampcp-axios-supply-chain-under-siege-lessons-from-the-ciso-playbook-for-ai-accelerated-appsec" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=b898c999-20eb-4af2-b199-5f9c7ea798f9&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🚨 Lovable&#39;s Blueprint for Security in the Age of Vibe-Coding and Agentic AI</title>
  <description>This week’s breakdown with Igor Andriushchenko (Head of Security, Lovable) shows how AI-native companies are already redesigning security for this new reality. Topics include agentic AI governance, identity and access controls for AI agents, SCA in the LLM era, AI-assisted AppSec workflows, and the Mandiant M-Trends 2026 findings on cloud initial-access vectors.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f58fb9e5-f0a5-4a34-8079-271ec928c1ed/Screenshot_2026-03-26_at_12.20.58_AM.png" length="4481696" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/ai-agents-identity-risk-supply-chain-attack-2026</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/ai-agents-identity-risk-supply-chain-attack-2026</guid>
  <pubDate>Thu, 26 Mar 2026 07:45:22 +0000</pubDate>
  <atom:published>2026-03-26T07:45:22Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><h2 class="heading" style="text-align:left;" id="hello-from-the-cloudverse"><span style="background-color:#28EEDA;"><b>Hello from the Cloud-verse!</b></span></h2><p class="paragraph" style="text-align:left;">This week’s Cloud Security Newsletter topic<b>: </b><b>Governing AI Agents as Federated Developers: The New Identity and Access Frontier</b><b> </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" rel="noopener noreferrer nofollow">(continue reading)</a> </p><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai"><span class="button__text" style=""> This issue is sponsored by Varonis </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f58fb9e5-f0a5-4a34-8079-271ec928c1ed/Screenshot_2026-03-26_at_12.20.58_AM.png?t=1774509711"/></a></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;">The velocity of change inside AI-first engineering organizations is no longer a competitive talking point; it is a security crisis hiding in plain sight. When a single developer can generate and deploy more code in a day than an entire team could in a week, every assumption your AppSec program was built on needs to be re-examined.</p><p class="paragraph" style="text-align:left;">This week we sit down with <a class="link" href="https://www.linkedin.com/in/igor-andriushchenko/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">Igor Andriushchenko</a>, Head of Security at Lovable, one of Europe&#39;s fastest-growing AI-native companies (the platform that lets anyone build fully functional web apps without writing a line of code). Igor joined when Lovable had 40 employees; six months later it had grown to 150+. He brings a rare vantage point: operating security at the bleeding edge of the agentic AI revolution, at a company where developers are not just using AI tools, they are building AI-native products at scale. Hosted by Ashish Rajan of the Cloud Security Podcast and AI Security Podcast, this conversation maps exactly what enterprise security leaders need to rethink now before the volume of AI-driven change overwhelms their existing controls.</p><p class="paragraph" style="text-align:left;">We also cover the week&#39;s most critical news, including the Stryker cyberattack, a claimed 100GB breach at Crunchyroll, Mandiant&#39;s M-Trends 2026 cloud findings, and the AI-powered supply chain threat campaigns that are directly relevant to every organization adopting agentic developer tooling. <i>[</i><a class="link" href="https://www.aisecuritypodcast.com/videos/questions-every-ciso-must-ask-ai-security-vendors?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">⚡ TL;DR for Busy Readers</h2><ul><li><p class="paragraph" style="text-align:left;">AI-generated code is producing 100× the change velocity your SAST, DAST, and SCA pipelines are already load-failing; retool now.</p></li><li><p class="paragraph" style="text-align:left;">Treat AI agents like federated developers: they inherit every credential and permission their human operator holds, apply PAM, least privilege, and human-in-the-loop escalation for privileged actions.</p></li><li><p class="paragraph" style="text-align:left;">AI hallucinated supply chain risk is real: LLMs recommend abandoned or phantom packages; layer AI-native SCA with dependency pinning and registry controls.</p></li><li><p class="paragraph" style="text-align:left;">Mandiant M-Trends 2026: voice phishing (23%) and SaaS token theft are your top cloud initial-access vectors not exploits (only 6%). Rethink your detection priorities.</p></li><li><p class="paragraph" style="text-align:left;">The winning AI adoption play is not top-down mandate; it is building the internal skills, MCP server ecosystem, and data connections that make AI genuinely useful to security teams in their actual daily work.</p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="this-weeks-security-news">📰 <b>THIS WEEK&#39;S TOP 4 SECURITY HEADLINES</b></h2><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-healthcare-giant-stryker-hit-by-c"><b> 1. Healthcare Giant Stryker Hit by Cyberattack</b></h3><p class="paragraph" style="text-align:left;">📰<b> What Happened:</b> Medical technology leader Stryker confirmed it suffered a cyberattack, with containment measures underway and external forensic incident response firms engaged. Investigations are ongoing and the full scope has not yet been disclosed.</p><p class="paragraph" style="text-align:left;"><b>🔍 Why It Matters:</b> Healthcare remains the highest-value target in critical infrastructure, not only for ransomware groups but for nation-state actors interested in supply chain leverage. Stryker&#39;s sprawling ecosystem of connected medical devices, SaaS platforms, and vendor integrations exemplifies the modern enterprise attack surface, one where a compromise upstream can cascade into clinical environments. This incident is a sharp reminder that IT/OT convergence risk is no longer theoretical: segmentation gaps between cloud workloads, operational technology, and SaaS-connected clinical systems are actively being exploited.</p><p class="paragraph" style="text-align:left;">✅<b> Key Actions:</b></p><ul><li><p class="paragraph" style="text-align:left;">Validate third-party access controls enforce ZTNA and least-privilege for all vendor and partner integrations.</p></li><li><p class="paragraph" style="text-align:left;">Harden segmentation between IT, OT, and cloud workloads; assume lateral movement paths exist until tested.</p></li><li><p class="paragraph" style="text-align:left;">Exercise your ransomware response playbook across hybrid environments, including cloud failover and clinical backup systems.</p></li></ul><p class="paragraph" style="text-align:left;">🔗 Source: <a class="link" href="https://www.bleepingcomputer.com/news/security/stryker-attack-wiped-tens-of-thousands-of-devices-no-malware-needed/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer / Stryker Incident Coverage </a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-120-m-funding-round-for-agentic-a"><b>2. $120M Funding Round for Agentic Access Management Signals the NHI Security Era Has Arrived</b></h3><p class="paragraph" style="text-align:left;"><b>What Happened: </b>On March 19, 2026, Oasis Security announced $120 million in Series B funding led by Craft Ventures, with participation from Sequoia Capital and Accel, bringing total funding to $195 million. The round reflects the rise of AI agents becoming embedded across enterprise infrastructure.Over the past year, Oasis has seen new ARR growing 5x year over year, with a majority of its client base coming from the Fortune 500.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters: </b>Machine identities now outnumber humans 82:1. The systems designed to govern access were built for people, not autonomous systems.<a class="link" href="https://www.accessnewswire.com/newsroom/en/computers-technology-and-internet/oasis-security-raises-120m-series-b-to-secure-the-rise-of-enterpr-1149255?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow"> </a>The Oasis round is venture capital confirming what CISOs are already experiencing: AI agents with cloud permissions are the fastest-growing and least-governed identity class in enterprise environments today.</p><p class="paragraph" style="text-align:left;">The Trivy supply chain attack this week — where stolen CI/CD secrets included AWS IAM keys, GCP service accounts, and Kubernetes tokens — illustrates exactly the problem Oasis is solving. Every AI agent and automation workflow introduced into cloud environments creates non-human identities that require lifecycle management, least-privilege enforcement, and real-time access governance. One survey found 79% of IT professionals feel ill-equipped to handle attacks tied to non-human identities, even as adoption of AI agents continues to climb.<a class="link" href="https://techstartups.com/2026/03/19/cybersecurity-startup-oasis-security-raises-120m-from-craft-sequoia-accel-to-tackle-ai-identity-risks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow"> </a></p><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://www.securityweek.com/oasis-security-raises-120-million-for-agentic-access-management/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow"> SecurityWeek</a> |<a class="link" href="https://www.bloomberg.com/news/articles/2026-03-19/startup-oasis-security-raises-120-million-from-craft-sequoia?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow"> Bloomberg</a><span style="color:rgb(17, 85, 204);"><span style="text-decoration:underline;"> |</span></span><a class="link" href="https://www.morningstar.com/news/accesswire/1149255msn/oasis-security-raises-120m-series-b-to-secure-the-rise-of-enterprise-ai-agents?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow"> Morningstar</a> </p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-rsa-2026-the-ai-powered-security-"><b>3. RSA 2026: The AI-Powered Security Tooling Surge and the Governance Gap</b></h3><p class="paragraph" style="text-align:left;">📰<b> What Happened:</b> At RSA Conference 2026, CrowdStrike, Palo Alto Networks, Cisco, and dozens of emerging vendors unveiled new AI-driven security capabilities spanning autonomous detection, accelerated incident response, and agentic SOC workflows. The announcements signal an arms race between attackers and defenders in which AI is the primary lever.</p><p class="paragraph" style="text-align:left;"><b>🔍 Why It Matters:</b> The RSA announcements confirm what Igor articulated clearly in this week&#39;s transcript: AI is now being deployed on both sides of every security encounter. The risk for enterprise security leaders is not falling behind on AI adoption it is the governance gap that opens when AI tooling is deployed without the data connections, tuned models, and human oversight structures needed to make it reliable. Hallucinations in security tooling are not just embarrassing they generate alert fatigue, erode analyst trust, and create the dangerous illusion of coverage. The organizations that will win are those that integrate AI into existing SecOps workflows thoughtfully, not those that deploy the most tools.</p><p class="paragraph" style="text-align:left;">✅<b> Key Actions:</b></p><ul><li><p class="paragraph" style="text-align:left;">Prioritize AI-assisted triage over full autonomy human review of AI-surfaced findings remains essential at this stage of maturity.</p></li><li><p class="paragraph" style="text-align:left;">Validate model outputs rigorously; establish guardrails against hallucinated findings before operationalizing any AI detection capability.</p></li><li><p class="paragraph" style="text-align:left;">Integrate AI tooling into your existing SecOps stack; parallel tool sprawl increases noise and management burden.</p></li></ul><p class="paragraph" style="text-align:left;">🔗 Source: <a class="link" href="https://www.rsaconference.com?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">RSA Conference 2026 Coverage</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-ai-supply-chain-attacks-target-de"><b>4. AI + Supply Chain Attacks Target Developer Ecosystems and Cloud Pipelines</b></h3><p class="paragraph" style="text-align:left;">📰<b> What Happened:</b> Recent threat intelligence documents active campaigns abusing developer tooling ecosystems including malicious VS Code extensions, poisoned GitHub repositories, and AI-themed lure packages to deliver infostealers and backdoors directly into enterprise cloud environments.</p><p class="paragraph" style="text-align:left;"><b>🔍 Why It Matters:</b> The developer is the new perimeter. Malicious packages mimicking legitimate AI coding tools are being published to npm, PyPI, and similar registries, targeting the exact toolchain that engineering teams are actively expanding as part of their AI adoption push. Igor raised precisely this risk in discussing AI-recommended abandoned packages and dependency confusion attacks: AI coding assistants can introduce compromised or phantom dependencies at a rate no human reviewer can track without automated controls. Cloud credentials harvested from a developer&#39;s environment translate directly into cloud infrastructure access.</p><p class="paragraph" style="text-align:left;">✅<b> Key Actions:</b></p><ul><li><p class="paragraph" style="text-align:left;">Enforce secure SDLC controls: mandatory SCA scanning on every PR, with AI-native tooling that understands business logic, not just CVE signature matching.</p></li><li><p class="paragraph" style="text-align:left;">Restrict use of unverified IDE extensions, MCP servers, and AI skill packages build an internal approved registry.</p></li><li><p class="paragraph" style="text-align:left;">Monitor developer credential usage patterns in cloud environments; flag anomalous API activity from developer identity paths.</p></li></ul><p class="paragraph" style="text-align:left;">🔗 <b>Source</b>: <a class="link" href="https://www.mandiant.com?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">Threat Intelligence on Developer Supply Chain</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-team-pcp-trivy-supply-chain-attac"><b>5. TeamPCP/Trivy Supply Chain Attack — 1,000+ SaaS Environments Hit, Lapsus$ Joins Extortion Wave</b></h3><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">On March 19, 2026, threat actor TeamPCP compromised Aqua Security&#39;s Trivy vulnerability scanner, injecting a credential-stealing payload into CI/CD pipelines across thousands of repositories by force-pushing 75 version tags in aquasecurity/trivy-action to malicious commits. The attack exploited credentials retained from an incomplete remediation of a prior breach.</p><p class="paragraph" style="text-align:left;">The campaign has since escalated significantly. Mandiant CTO Charles Carmakal confirmed 1,000+ enterprise SaaS environments are actively compromised, with projections of &quot;another 10,000&quot; downstream victims as fallout continues. TeamPCP is now confirmed to be channeling stolen access to Lapsus$, converting a credential theft operation into an active extortion campaign. Attackers also pivoted into LiteLLM — a widely used AI middleware library — using stolen Trivy credentials, and deployed CanisterWorm to backdoor 29+ npm packages. Notably, the LiteLLM attack was deliberately timed to coincide with the RSA Conference, while defenders were distracted. Cached malicious Trivy Docker images (0.69.4–0.69.6) continue to circulate via <a class="link" href="https://mirror.gcr.io?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">mirror.gcr.io</a> despite takedowns.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">The payload targeted the full cloud credential stack — AWS IAM keys, GCP service account tokens, Azure service principals, Kubernetes tokens, SSH keys, and Docker registry credentials. The Lapsus$ involvement means stolen credentials are already distributed and monetized; the remediation window has passed for affected environments. The LiteLLM pivot signals that AI/ML pipeline infrastructure is now a direct lateral movement target. Three structural lessons: tag-based GitHub Actions provide no integrity guarantee; incomplete credential rotation turns one breach into a campaign; and runtime detection outperformed every static control deployed.</p><p class="paragraph" style="text-align:left;"><b>Immediate Actions</b></p><ul><li><p class="paragraph" style="text-align:left;">Audit GitHub Actions logs for trivy-action or setup-trivy runs between 17:00–23:13 UTC on March 19; search for tpcp-docs repos in your GitHub org</p></li><li><p class="paragraph" style="text-align:left;">Treat all CI/CD secrets as compromised if affected Actions ran — rotate immediately</p></li><li><p class="paragraph" style="text-align:left;">Pin all GitHub Actions to full commit SHAs, not version tags</p></li><li><p class="paragraph" style="text-align:left;">Audit LiteLLM deployments and associated credentials in AI/ML pipelines</p></li><li><p class="paragraph" style="text-align:left;">Verify npm and PyPI dependency integrity against Socket&#39;s CanisterWorm IOCs</p></li><li><p class="paragraph" style="text-align:left;">Do not assume takedowns ended exposure — check <a class="link" href="https://mirror.gcr.io?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">mirror.gcr.io</a> and other caches</p></li><li><p class="paragraph" style="text-align:left;">Block domain scan.aquasecurtiy[.]org and IP 45.148.10.212</p></li></ul><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://www.sysdig.com/blog/teampcp-expands-supply-chain-compromise-spreads-from-trivy-to-checkmarx-github-actions?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow"> Sysdig TRT</a> |<a class="link" href="https://www.wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow"> Wiz Blog</a> |<a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/03/24/detecting-investigating-defending-against-trivy-supply-chain-compromise/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow"> Microsoft Security Blog</a> |<a class="link" href="https://thehackernews.com/2026/03/teampcp-hacks-checkmarx-github-actions.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow"> The Hacker News</a> |<a class="link" href="https://blog.gitguardian.com/trivys-march-supply-chain-attack-shows-where-secret-exposure-hurts-most/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow"> GitGuardian</a></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="governing-ai-agents-as-federated-de"><b>Governing AI Agents as Federated Developers: The New Identity and Access Frontier</b></h3><p class="paragraph" style="text-align:left;">The most consequential security architecture challenge of 2026 is not a new vulnerability class it is the identity question posed by AI agents operating autonomously inside enterprise environments. When a developer runs ten AI coding agents overnight, each agent is not just generating code. It is operating with that developer&#39;s credentials, accessing that developer&#39;s permitted systems, and taking actions that the organization&#39;s existing IAM, PAM, and audit frameworks were never designed to capture or govern.</p><p class="paragraph" style="text-align:left;">Igor Andriushchenko frames this with unusual clarity: the mental model shift required is from thinking of AI agents as tools to recognizing them as delegated principals  agents that inherit the permissions, credentials, and organizational trust of the human who invoked them. That reframing has immediate, practical implications for how cloud security architects design access controls, audit trails, and escalation paths in an agentic world.</p><p class="paragraph" style="text-align:left;">This week, we go deep on what that actually looks like in practice from PAM-enforced human-in-the-loop escalation for privileged actions, to deny-list prompting strategies, to the skills and MCP server ecosystem that makes AI genuinely useful to security teams rather than just a mandate to fulfill.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="featured-experts-this-week"><b>Featured Experts This Week </b>🎤</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/igor-andriushchenko/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow"><b>Igor Andriushchenko</b></a> Head of Security, Lovable </p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Agentic AI / AI Agents</b> AI systems that do not just respond to prompts but autonomously take multi-step actions writing code, calling APIs, browsing the web, running commands on behalf of a user. The key security distinction: agents act, not just advise. When agents run with real credentials and real system access, the blast radius of a compromise or error scales accordingly.</p></li><li><p class="paragraph" style="text-align:left;"><b>MCP Server (Model Context Protocol)</b> An emerging open standard that allows AI agents to connect to external tools, data sources, and APIs in a structured way. MCP servers define what capabilities an agent can invoke. Analogous to API integrations in traditional software, but with the critical difference that AI agents can discover and chain MCP capabilities dynamically. Supply chain attacks targeting MCP marketplaces are already documented.</p></li><li><p class="paragraph" style="text-align:left;"><b>PAM (Privileged Access Management)</b> A security discipline and tooling category focused on controlling, monitoring, and auditing access to privileged accounts and credentials. In the context of AI agents, PAM provides the mechanism for requiring human escalation before an agent can access production secrets, high-privilege API keys, or sensitive system operations creating the &quot;healthy friction&quot; Igor describes.</p></li><li><p class="paragraph" style="text-align:left;"><b>SCA (Software Composition Analysis)</b> Automated tooling that identifies open-source and third-party components in a codebase, mapping them against known vulnerabilities (CVEs), license issues, and increasingly supply chain risk signals. In the AI coding era, SCA is under new pressure: LLMs can recommend abandoned, fictional, or malicious packages, and the volume of dependencies introduced per day has multiplied dramatically.</p></li><li><p class="paragraph" style="text-align:left;"><b>SAST / DAST</b> Static Application Security Testing (SAST) analyzes source code for security issues without executing it. Dynamic Application Security Testing (DAST) tests a running application by simulating attacks. Both categories are being disrupted by AI-native alternatives that build semantic models of application business logic rather than relying on pattern matching to find high-signal, low-noise findings like broken access control and business logic flaws.</p></li><li><p class="paragraph" style="text-align:left;"><b>Dependency Confusion Attack</b> An attack technique in which a threat actor publishes a malicious package to a public registry (npm, PyPI, etc.) with a name that matches or closely resembles a private internal package name. AI coding assistants that recommend package names without verifying their provenance or freshness can be manipulated into recommending the malicious public package over the intended private one.</p></li><li><p class="paragraph" style="text-align:left;"><b>OAuth Token Harvesting</b> The theft of OAuth access tokens  short-lived credentials used by SaaS applications to authorize access to impersonate legitimate users or service accounts. Per M-Trends 2026, this is a primary technique in cloud initial-access campaigns, particularly when tokens are embedded in SaaS vendor environments with broad downstream permissions.</p></li><li><p class="paragraph" style="text-align:left;"><b>Voice Phishing (Vishing)</b> Social engineering attacks conducted via telephone or voice-over-IP, often combined with AI voice synthesis to impersonate executives, IT help desks, or vendors. M-Trends 2026 identifies vishing as responsible for 23% of cloud intrusions frequently used to convince targets to approve MFA push notifications or surrender credentials verbally.</p></li><li><p class="paragraph" style="text-align:left;"><b>Prompt Injection</b> An attack against AI systems in which malicious instructions are embedded in content that the AI processes (documents, web pages, API responses), causing the AI agent to take unintended actions. In the context of AI coding agents with cloud access, successful prompt injection can result in credential exfiltration, data destruction, or unauthorized API calls.</p></li><li><p class="paragraph" style="text-align:left;"><b>ASBOM (AI Software Bill of Materials)</b> An emerging practice of documenting the AI models, datasets, and AI-dependent components within a software product analogous to a traditional SBOM for open-source dependencies. Igor describes using ASBOM in enterprise sales contexts, where banks are beginning to require vulnerability disclosure and reachability analysis for AI-dependent components before procurement approval.</p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <a class="link" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow"><b>Varonis</b></a></p><p class="paragraph" style="text-align:center;"><i>AI Security Requires More Than Visibility. It Requires Control. </i></p><p class="paragraph" style="text-align:left;"><i>Security leaders are under pressure to enable AI innovation while managing a rapidly expanding attack surface across cloud, identity, and data layers. AI agents and copilots can introduce new access paths, automated high-impact actions, and accelerate threat timelines. </i></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow"><i>Varonis Atlas</i></a><i> helps organizations secure AI end-to-end - from understanding usage and enforcing guardrails to detecting suspicious activity and reducing risk dynamically. Join our </i><a class="link" href="https://links.cloudsecuritypodcast.tv/atlas-webinar-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(17, 85, 204)"><i>upcoming webinar to learn how Varonis Atlas</i></a><i> can help security teams operationalize AI security at scale. </i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><hr class="content_break"><h3 class="heading" style="text-align:left;" id="the-cicd-pipeline-is-being-load-tes"><b>The CI/CD Pipeline Is Being Load-Tested to Failure</b></h3><p class="paragraph" style="text-align:left;">Igor&#39;s opening framing is the most important thing any security leader can hear right now: the infrastructure that enterprise security programs were built on the code review gates, the SAST scan cadences, the human-in-the-loop approval workflows is failing not because it was badly designed, but because it is being subjected to a load it was never engineered to handle.&quot;<i>These old rails that CI/CDs run on, they are just getting load tested and reaching its limits in every organization.</i>&quot; Igor, Lovable</p><p class="paragraph" style="text-align:left;">A developer running ten AI coding agents in parallel overnight can produce more PRs in eight hours than a traditional team produced in a month. Each of those PRs represents state change in the system. Each state change is a potential security regression. And the tooling that security teams depend on to catch those regressions SAST scanners, human reviewers, manual threat models cannot keep pace with the throughput.</p><p class="paragraph" style="text-align:left;">The practical implication for enterprise security architects is urgent: the right question is not &quot;how do we improve our existing SAST pipeline?&quot; It is &quot;what does a security program look like that was designed for 1,000 commits per day?&quot; That requires AI-native tooling with semantic code understanding, not pattern matching; autonomous triage agents that can investigate findings without waiting for analyst bandwidth; and a risk acceptance framework that explicitly acknowledges the speed-security tradeoff rather than pretending it does not exist.</p><p class="paragraph" style="text-align:left;">🔑 <b>Action:</b> Conduct a throughput stress-test of your existing security tooling: how many PRs per day can your current SAST, SCA, and code review process handle before coverage degrades? That number is your current security ceiling and AI adoption is almost certainly pushing your organization toward it.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="ai-agents-are-federated-developers-"><b>AI Agents Are Federated Developers Govern Them Accordingly</b></h3><p class="paragraph" style="text-align:left;">The most architecturally important insight from the conversation is Igor&#39;s framing of AI agents as delegated principals. When a developer invokes a coding agent, they are not just using a smart autocomplete tool they are federating their credentials, their access scope, and their organizational trust to an autonomous system that will act on their behalf without human review of each individual action. <i>&quot;Developer federates its access, its credentials, its knowledge to the AI. So you should almost see it as like another developer, essentially.</i>&quot; Igor, Lovable</p><p class="paragraph" style="text-align:left;">This reframing has immediate, practical consequences. If your IAM architecture allows a developer to access production secrets on-demand, then an AI agent running as that developer can also access production secrets on-demand and can do so thousands of times per day, silently, without any of the human judgment that (sometimes) catches misuse. The solution Igor implements at Lovable is elegant: PAM-enforced escalation for privileged actions. Developers can freely use AI agents for development-scoped work, but anything requiring production credential access requires a human to explicitly perform an escalation step that the agent cannot complete autonomously.</p><p class="paragraph" style="text-align:left;">This is not a new concept, it is the principle of least privilege applied to a new class of principal. But its implementation requires deliberate architectural decisions: which actions should require human escalation? Where does the PAM boundary sit? How do you enforce it when AI agents are being invoked from developer machines, CI/CD pipelines, and SaaS platforms simultaneously?</p><p class="paragraph" style="text-align:left;">🔑 <b>Action:</b> Map your current developer access entitlements and identify which of those entitlements an AI agent inheriting that access could abuse autonomously. For each high-risk entitlement, evaluate whether PAM-enforced human escalation is technically feasible and operationally acceptable given your speed-security tradeoff.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="the-deny-list-paradox-why-standard-"><b>The Deny-List Paradox: Why Standard Security Prompting Logic Fails for Agents</b></h3><p class="paragraph" style="text-align:left;">One of the most counterintuitive insights from the conversation addresses a subtle but consequential difference between how security professionals think about access control and how AI agents process instructions. Security practitioners are trained to prefer allow-lists over deny-lists to define what is permitted and block everything else. Igor explains why this logic inverts AI agents. &quot;<i>For the agents, it&#39;s reversed. Because if you do an allow list, it&#39;ll always focus against that.The real world has so many more paths, but it will always choose the paths that you say you are allowed to do this.</i>&quot; Igor, Lovable</p><p class="paragraph" style="text-align:left;">When you give an AI agent a list of permitted actions, the agent optimizes toward executing those actions treating the allow-list as a set of objectives rather than a boundary. The agent will find paths to those permitted actions that you did not anticipate and did not sanction.The more effective approach, Igor argues, is to explicitly instruct agents on what not to do providing a security context document (embedded in the agent&#39;s system prompt or knowledge file) that defines the threat model, the sensitive components, and the prohibited actions.This is analogous to a new-hire security briefing: rather than listing every permitted workflow, you explain the business, what needs protecting, and what constitutes a security incident.</p><p class="paragraph" style="text-align:left;">🔑 <b>Action:</b> For every AI coding agent or security agent your team deploys, create a security context document a structured summary of your threat model, sensitive components, and prohibited actions and embed it in the agent&#39;s knowledge file or system prompt. Treat it as a living document that security updates as the codebase and threat landscape evolve.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="ai-native-sca-the-overlooked-surfac"><b>AI-Native SCA: The Overlooked Surface That LLMs Are Actively Expanding</b></h3><p class="paragraph" style="text-align:left;">Igor raises a specific, concrete risk that deserves standalone attention: AI coding assistants are actively introducing supply chain vulnerabilities that existing SCA tooling is not equipped to catch. The mechanism is hallucination LLMs confidently recommending libraries that do not exist at the specified version, have not been maintained in years, or share names with malicious packages published by attackers. &quot;<i>I asked AI about what is a good library for PII sanitization in Go, and it gave me a library and said it&#39;s actively maintained and the last commit was eight years ago.</i>&quot; Igor, Lovable</p><p class="paragraph" style="text-align:left;">This is not an edge case. Research presented at Black Hat has demonstrated methods for generating package names that, in some percentage of LLM invocations, cause the model to recommend a malicious attacker-controlled package over the intended legitimate one. As AI-generated code becomes the majority of enterprise commits, the aggregate risk from hallucinated or manipulated package recommendations becomes a meaningful supply chain vector, one that bypasses traditional SCA scanners that only check for known-bad CVEs against packages that are correctly installed.</p><p class="paragraph" style="text-align:left;">The defensive architecture requires layering: AI-native SCA tools that understand the semantic context of dependency introduction (not just CVE signature matching), registry-level controls that restrict installation to approved package sources, and dependency pinning policies that prevent silent version drift. Critically, the AI agent&#39;s code generation pipeline itself must be instrumented not just the final PR.</p><p class="paragraph" style="text-align:left;">🔑 <b>Action:</b> Audit your current SCA tooling against the AI-hallucination threat model: does it flag packages that are minimally maintained, have suspicious commit histories, or share names with known internal packages? If not, evaluate AI-native SCA vendors that surface these signals.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="building-the-skills-ecosystem-the-u"><b>Building the Skills Ecosystem: The Unsexy Work That Determines AI Security ROI</b></h3><p class="paragraph" style="text-align:left;">A recurring theme in the conversation is the gap between announcing an &quot;AI adoption strategy&quot; and actually making AI useful to security teams in their day-to-day work. Igor&#39;s experience at Lovable building an incident responder skill that allows analysts to trigger autonomous investigation of suspicious alerts with a single command illustrates what genuine AI value looks like versus performative tooling deployment. &quot;<i>The overlooked part is that non-sexy work building skills, making connections, building MCP servers. Organizations usually just put Copilot into everyone&#39;s environment. But then what? What is it connected to? What can it do?</i>&quot; Igor, Lovable</p><p class="paragraph" style="text-align:left;">The insight here is structural. The value of an AI agent in a security context is almost entirely determined by the quality of the data connections and skills it has access to the MCP servers that connect it to your SIEM, your cloud audit trails, your vulnerability management platform, your ticketing system. An AI agent without those connections is a sophisticated chat interface. An AI agent with them is a force multiplier.</p><p class="paragraph" style="text-align:left;">Ashish reinforces this from a practitioner standpoint: the path to genuine AI security capability is iterative start with a single, high-value connection (e.g., &quot;query AWS CloudTrail for this suspicious IP&quot;), validate the output, add the next connection, and gradually build toward multi-step autonomous workflows that would previously have required hours of analyst time.</p><p class="paragraph" style="text-align:left;">🔑 <b>Action:</b> Identify the three highest-friction, highest-repetition tasks your security team performs (e.g., alert triage, vulnerability verification, IOC lookups across multiple platforms). For each, map the data connections required and evaluate whether an MCP server or skills-based agent could automate the retrieval and initial analysis steps.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="the-crawl-walk-run-model-for-ai-sec"><b>The Crawl-Walk-Run Model for AI Security Adoption</b></h3><p class="paragraph" style="text-align:left;">Both Igor and Ashish push back firmly against the organizational tendency to jump from zero AI usage to fully autonomous agentic workflows, a pattern that consistently produces failed implementations and organizational backlash. Igor&#39;s &quot;air pocket&quot; metaphor is instructive: within any organization, there are specific, bounded use cases where AI can be deployed safely and generate clear value without requiring a complete overhaul of security architecture.</p><p class="paragraph" style="text-align:left;">For a large bank with significant regulatory exposure and risk aversion, the air pocket might be internal tooling prototyping with no production data involved. For a fast-moving scale-up, it might be PR-creation by non-developers with mandatory human review before merge. For a security team overwhelmed by SAST findings, it might be an AI agent that fetches the relevant code context and performs initial triage reducing analyst time-to-decision from thirty minutes to three.</p><p class="paragraph" style="text-align:left;">The principle generalizes: find the smallest, highest-value problem that AI can solve today, solve it well, generate internal credibility, and use that credibility to expand the scope of AI deployment incrementally. Organizations that attempt to solve the entire class of problems simultaneously deploying fully autonomous security operations without the foundational skills, data connections, and governance frameworks are the ones that end up publicly reversing their AI strategy.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>📚 RELATED RESOURCES 🎧</b></h2><p class="paragraph" style="text-align:left;"><b>Threat Intelligence & Research</b></p><ul><li><p class="paragraph" style="text-align:left;">Google Cloud / Mandiant M-Trends 2026 Report <a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026</a></p></li><li><p class="paragraph" style="text-align:left;">OWASP Top 10 for LLM Applications (2025) <a class="link" href="https://owasp.org/www-project-top-10-for-large-language-model-applications/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">https://owasp.org/www-project-top-10-for-large-language-model-applications/</a></p></li><li><p class="paragraph" style="text-align:left;">NIST AI Risk Management Framework (AI RMF) <a class="link" href="https://www.nist.gov/system/files/documents/2023/01/26/AI%20RMF%201.0.pdf?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">https://www.nist.gov/system/files/documents/2023/01/26/AI%20RMF%201.0.pdf</a></p></li></ul><p class="paragraph" style="text-align:left;"><b>Cloud-Native Guidance & Tools</b></p><ul><li><p class="paragraph" style="text-align:left;">AWS IAM Best Practices for Least Privilege <a class="link" href="https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html</a></p></li><li><p class="paragraph" style="text-align:left;">Model Context Protocol (MCP) Specification <a class="link" href="https://modelcontextprotocol.io?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">https://modelcontextprotocol.io</a></p></li><li><p class="paragraph" style="text-align:left;">Socket Security AI-Native SCA <a class="link" href="https://socket.dev?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">https://socket.dev</a></p></li><li><p class="paragraph" style="text-align:left;">OpenSSF Scorecard <a class="link" href="https://securityscorecards.dev?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">https://securityscorecards.dev</a></p></li></ul><h3 class="heading" style="text-align:left;" id="podcast-episode"><b>Podcast Episode</b></h3><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a><b>   Episode with Igor Andriushchenko</b></p></li></ul><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6d149e97-210c-4cf6-bdd7-3a5bbebb2241/S04EP06.png?t=1774509538"/></div><hr class="content_break"><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔<b> </b><span style="color:rgb(20, 19, 34);"> </span>Has your organization mapped which developer entitlements an AI agent could inherit and defined the PAM boundary that requires a human in the loop?<br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=lovable-s-blueprint-for-security-in-the-age-of-vibe-coding-and-agentic-ai" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=c223fc70-e4ef-41c8-a727-0ce3f01aa669&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🚨Zero  Day Exploit Windows Shrink to Hours: Is Your Security Stack Built for an AI  Accelerated Threat Landscape?</title>
  <description>This week Google&#39;s closes $32B acquisition of Wiz to reshape cloud security, and  Google also patches two in the wild Chrome zero days added to CISA KEV; LeakNet ransomware pivots to ClickFix and Deno in  memory loaders to evade detection. Plus: Ashish Rajan &amp; Caleb Sima on why the vendor consolidation era is arriving, why AI agent security remains an open book, and why the window from vulnerability to exploitation now closes in under two days.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ec268b92-0136-4663-a0f2-ee52d47010bf/Screenshot_2026-03-18_at_8.29.41_PM.png" length="1981831" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/chrome-zero-days-google-wiz-ai-security-consolidation</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/chrome-zero-days-google-wiz-ai-security-consolidation</guid>
  <pubDate>Wed, 18 Mar 2026 20:48:01 +0000</pubDate>
  <atom:published>2026-03-18T20:48:01Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><h2 class="heading" style="text-align:left;" id="hello-from-the-cloudverse"><span style="background-color:#28EEDA;"><b>Hello from the Cloud-verse!</b></span></h2><p class="paragraph" style="text-align:left;">This week’s Cloud Security Newsletter topic<b>: Why AI May Finally Let CISOs Simplify Their Security Stack </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" rel="noopener noreferrer nofollow">(continue reading)</a> </p><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://links.cloudsecuritypodcast.tv/2026-browser-attack-techniques-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape"><span class="button__text" style=""> This issue is sponsored by Push Security </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ec268b92-0136-4663-a0f2-ee52d47010bf/Screenshot_2026-03-18_at_8.29.41_PM.png?t=1773865802"/></a><div class="image__source"><span class="image__source_text"><p><i>This image was generated by AI. It&#39;s still experimental, so it might not be a perfect match!</i></p></span></div></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;">The security landscape accelerated again this week, and the numbers tell the story bluntly: what once took five months from a public vulnerability disclosure to confirmed in  the  wild exploitation now closes in under two days in 2026. That compression isn&#39;t theoretical. It&#39;s documented at<a class="link" href="https://zerodayclock.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> </a><a class="link" href="https://ZeroDayClock.com?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">ZeroDayClock.com</a>, and it showed up in real time this week when a Chrome renderer flaw and a new ransomware initial access chain both arrived simultaneously, demanding immediate enterprise response.</p><p class="paragraph" style="text-align:left;">Against that backdrop, this week&#39;s newsletter brings together three breaking security stories and a frank, unfiltered conversation with Caleb Sima veteran CISO, investor, and co  host of the AI Security Podcast   recorded live ahead of RSAC 2026. Caleb and Ashish Rajan (<a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a>) cut through the conference noise to address something most vendors won&#39;t talk about: the case for radical vendor consolidation powered by internal AI teams, and why the current wave of &quot;AI agent security&quot; products largely can&#39;t back up their claims. <i>[</i><a class="link" href="https://www.aisecuritypodcast.com/videos/questions-every-ciso-must-ask-ai-security-vendors?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">⚡ TL;DR for Busy Readers</h2><ul><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>Google closes $32B Wiz acquisition</b></span><br><span style="color:rgb(20, 19, 34);"> Expect tighter CNAPP + threat intelligence integration and potential licensing shifts.</span></p></li><li><p class="paragraph" style="text-align:left;"><b>Patch Chrome now CVE 2026 3909 and CVE  2026  3910</b> are actively exploited zero days in Skia and V8; CISA KEV deadline is March 27. All Chromium based enterprise browsers are in scope.</p></li><li><p class="paragraph" style="text-align:left;"><b>LeakNet ditches broker access New ClickFix + Deno</b> in memory loader chain leaves minimal forensic artifacts; flag Deno.exe in non developer endpoints and tune PsExec detection rules.</p></li><li><p class="paragraph" style="text-align:left;"><b>Vendor consolidation thesis</b> gains momentum episode where Ashish Rajan & Caleb Sima argue the AI era enables CISOs to go all  in on 2–3 platform vendors and use internal AI teams to close the capability gap.</p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="this-weeks-security-news">📰 <b>THIS WEEK&#39;S TOP 4 SECURITY HEADLINES</b></h2><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><h3 class="heading" style="text-align:left;" id="1-march-patch-tuesday-azure-mcp-ser"><b>1. 🛡️ March Patch Tuesday: Azure MCP Server SSRF, Copilot Zero-Click Exfiltration Bug, & Two Public Zero-Days</b></h3><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">Microsoft&#39;s March 2026 Patch Tuesday addresses 79 security vulnerabilities, including two publicly disclosed zero-days. The most urgent concern is CVE-2026-26144, a critical information disclosure vulnerability in Microsoft Excel that can cause Copilot Agent mode to silently exfiltrate data with no user interaction requiredSeparately, CVE-2026-26118 is an elevation of privilege vulnerability in Azure MCP Server Tools (CVSS 8.8). An attacker could exploit this by sending a crafted input to a vulnerable Azure MCP Server that accepts user-provided parameters. The MCP Server then sends an outbound request to an attacker-controlled URL, potentially including its managed identity token, allowing the attacker to capture that token and inherit the permissions associated with the MCP Server&#39;s managed identity.<a class="link" href="https://blog.talosintelligence.com/microsoft-patch-tuesday-march-2026/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> </a></p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">Two distinct cloud-AI attack vectors are in play here. First, CVE-2026-26144 represents a new class of threat: an attacker can deliver a malicious Excel file and if Microsoft 365 Copilot is enabled, trigger automatic, zero-click data exfiltration through the AI agent itself. No macro, no user action. Second, CVE-2026-26118 strikes at the emerging MCP ecosystem directly. MCP was designed to give AI agents safe, structured access to tools and data. CVE-2026-26118 shows that the protocol infrastructure itself can become an attack vector and that AI agent infrastructure expands the privilege escalation surface.<a class="link" href="https://awesomeagents.ai/news/microsoft-patch-tuesday-march-2026-ai-copilot/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> </a>For M365 Copilot deployments: patch immediately and audit Copilot Agent mode permissions. For Azure MCP implementations: update Azure MCP Server Tools and review managed identity scopes to enforce least privilege.</p><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://blog.talosintelligence.com/microsoft-patch-tuesday-march-2026/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> Talos Intelligence</a> ·<a class="link" href="https://www.tenable.com/blog/microsofts-march-2026-patch-tuesday-addresses-83-cves-cve-2026-21262-cve-2026-26127?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> Tenable</a> ·<a class="link" href="https://thehackernews.com/2026/03/microsoft-patches-84-flaws-in-march.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> The Hacker News</a> ·<a class="link" href="https://www.securityweek.com/microsoft-patches-83-vulnerabilities/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> SecurityWeek</a><span style="color:rgb(17, 85, 204);"><span style="text-decoration:underline;"> </span></span><a class="link" href="https://zecurit.com/endpoint-management/patch-tuesday/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">Zecurit</a> <a class="link" href="https://awesomeagents.ai/news/microsoft-patch-tuesday-march-2026-ai-copilot/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">Awesome Agents</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-google-patches-two-actively-explo"><b>2. </b>🚨<span style="color:rgb(0, 0, 0);"><b> </b></span><b>Google Patches Two Actively Exploited Chrome Zero Days CISA Adds Both to KEV (CVE  2026  3909 & CVE  2026  3910)</b></h3><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">Google issued emergency out  of  band patches for two high  severity Chrome vulnerabilities confirmed as exploited in the wild: an out  of  bounds write in the Skia graphics library (CVE  2026  3909) and an inappropriate implementation flaw in the V8 JavaScript and WebAssembly engine (CVE  2026  3910). CISA added both to its Known Exploited Vulnerabilities catalogue with a federal remediation deadline of March 27, 2026. Chrome&#39;s third zero  day pair of 2026. Technical exploitation details are restricted pending broad patch deployment.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">This is a patch now CVE. Skia and V8 are core rendering and execution components present across all Chromium  based browsers Chrome, Edge, Brave, Opera, and any Electron based enterprise applications. The V8 flaw carries implicit RCE risk within the browser sandbox and is a historically favoured APT initial access surface. Key actions:</p><ul><li><p class="paragraph" style="text-align:left;">Verify the patched version is deployed fleet  wide   enterprise Chrome auto  update is frequently delayed or disabled in managed environments.</p></li><li><p class="paragraph" style="text-align:left;">Flag Electron  based internal tooling (Slack, VS Code, internal apps) and track vendor patch timelines for each.</p></li><li><p class="paragraph" style="text-align:left;">Review browser isolation and RBI policies for high  risk user populations (finance, exec, privileged users).</p></li><li><p class="paragraph" style="text-align:left;">Treat the March 27 KEV deadline as your internal SLA if you operate in regulated sectors or hold federal contracts.</p></li></ul><p class="paragraph" style="text-align:left;">This story also illustrates the zero day clock compression that Caleb Sima references in this week&#39;s expert interview: browser  level disclosures are now exploited within days, not weeks. Detection and patch velocity must match that pace.</p><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> CISA KEV Catalogue</a> |<a class="link" href="https://thehackernews.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> The Hacker News</a> |<a class="link" href="https://zerodayclock.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> </a><a class="link" href="https://ZeroDayClock.com?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">ZeroDayClock.com</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-leak-net-ransomware-adopts-click-"><b>3. </b><span style="color:rgb(22, 60, 119);">🔍</span><span style="color:rgb(0, 0, 0);"><b> </b></span><b>📦 LeakNet Ransomware Adopts ClickFix Social Engineering and Deno InMemory Loader drops Reliance on Access Brokers</b></h3><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">ReliaQuest threat intelligence published on March 17 identifies LeakNet ransomware operators adopting a previously unreported initial access chain: ClickFix lures delivered through compromised legitimate websites, paired with a Deno JavaScript runtime loader that executes a Base64  encoded payload almost entirely in memory, fingerprints the victim machine, and establishes C2. This marks a deliberate departure from initial access brokers (IABs) giving LeakNet direct, lower  cost access at greater scale. Every confirmed LeakNet incident shares a deterministic post  exploitation chain: <i>jli.dll</i> sideloading into Java within the USOShared directory → PsExec lateral movement → S3 bucket payload staging and exfiltration.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">The Deno loader is the standout technical detail. Rather than deploying custom malware, attackers install the legitimate Deno executable and use it to run malicious code via VBS and PowerShell scripts named with Romeo/Juliet naming patterns. The activity presents as normal developer tooling. Minimal forensic artifacts remain. Three strategic implications:</p><ul><li><p class="paragraph" style="text-align:left;">Dark web IAB monitoring is no longer sufficient: LeakNet&#39;s shift to self  directed ClickFix campaigns removes the IAB dependency that previously provided early  warning telemetry for threat intelligence teams.</p></li><li><p class="paragraph" style="text-align:left;">Detection engineering updates required: Flag Deno.exe executing in non  developer contexts. Create detection rules for VBS/PowerShell scripts with Romeo*/Juliet* naming. Alert on <i>jli.dll</i> sideloading events and anomalous PsExec usage at scale.</p></li><li><p class="paragraph" style="text-align:left;">Use the deterministic kill chain as a containment trigger: Automated host isolation on confirmed <i>jli.dll</i> sideloads and anomalous PsExec activity can compress mean  time  to  contain from hours to minutes.</p></li></ul><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://reliaquest.com/blog/threat-spotlight-casting-a-wider-net-clickfix-deno-and-leaknets-scaling-threat?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> ReliaQuest   LeakNet Threat Spotlight</a> |<a class="link" href="https://thehackernews.com/2026/03/leaknet-ransomware-uses-clickfix-via.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> The Hacker News</a> |<a class="link" href="https://www.bleepingcomputer.com/news/security/leaknet-ransomware-uses-clickfix-and-deno-runtime-for-stealthy-attacks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> BleepingComputer</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-google-closes-32-b-wiz-acquisitio"><b>4. </b><span style="color:rgb(22, 60, 119);">⚠️</span><span style="color:rgb(22, 60, 119);"><b> </b></span><b>Google Closes $32B Wiz Acquisition — Biggest Deal in Cloud Security History</b></h3><p class="paragraph" style="text-align:left;"><b>What Happened</b></p><p class="paragraph" style="text-align:left;">On March 11, 2026, Google announced the completion of its acquisition of Wiz, a leading cloud and AI security platform headquartered in New York.<a class="link" href="https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/wiz-acquisition/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> </a>The deal received antitrust approval from U.S. regulators in November 2025 and from the European Commission in February 2026.<a class="link" href="https://techcrunch.com/2026/03/11/google-completes-32b-acquisition-of-wiz/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> </a>Wiz will maintain its brand and continue providing cybersecurity solutions for all major cloud platforms, including AWS, Azure, and Oracle Cloud.</p><p class="paragraph" style="text-align:left;"><b>Why It Matters</b></p><p class="paragraph" style="text-align:left;">This is the defining consolidation event in cloud security for the decade. For enterprise teams, the immediate implication is not product disruption Wiz has been explicit about multi-cloud continuity but strategic positioning. By integrating Wiz&#39;s advanced cloud security capabilities with Google&#39;s security operations platform, the company aims to provide organizations with a comprehensive defense platform designed for modern cloud and AI-driven infrastructures.<a class="link" href="https://cyberpress.org/google-finalizes-32-billion-acquisition/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> </a>The long-term question for CISOs: does a Google-owned CNAPP still serve as a neutral arbiter across your AWS, Azure, and GCP estate, or does procurement pressure shift? Wiz&#39;s $1B+ ARR base means your peer organizations are paying close attention. Evaluate your CNAPP and multi-cloud security stack posture now before renewal cycles hit during integration.</p><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/wiz-acquisition/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> Google Press Release</a><b> ·</b><a class="link" href="https://techcrunch.com/2026/03/11/google-completes-32b-acquisition-of-wiz/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> TechCrunch</a><b> ·</b><a class="link" href="https://www.securityweek.com/wiz-joins-google-cloud-as-landmark-acquisition-closes/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> SecurityWeek</a><span style="color:rgb(17, 85, 204);"><span style="text-decoration:underline;"><b> </b></span></span></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="the-vendor-consolidation-thesis-why">The Vendor Consolidation Thesis: <br>Why AI May Finally Let CISOs Simplify Their Security Stack</h3><p class="paragraph" style="text-align:left;">At RSAC 2026, the vendor floor will be louder, more crowded, and harder to navigate than ever. Vibe coding and AI tooling have spawned what Caleb Sima estimates to be a thousand new cybersecurity startups   all with the same marketing, the same branding, and the same AI agent claims. But beneath the noise, a structural shift is underway that smart CISOs are already moving on: the possibility of radical stack consolidation, powered by internal AI capability teams.</p><p class="paragraph" style="text-align:left;">This week&#39;s expert conversation with Caleb and Ashish tackles the question most vendors don&#39;t want practitioners asking: what if the best  of  breed era is ending, and good  enough  plus  AI is the winning architecture?</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="featured-experts-this-week"><b>Featured Experts This Week </b>🎤</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/calebsima/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">Caleb Sima</a><span style="color:rgb(20, 19, 34);"> </span><b>- </b> <span style="color:rgba(0, 0, 0, 0.9);font-family:-apple-system, system-ui, &quot;system-ui&quot;, &quot;Segoe UI&quot;, Roboto, &quot;Helvetica Neue&quot;, &quot;Fira Sans&quot;, Ubuntu, Oxygen, &quot;Oxygen Sans&quot;, Cantarell, &quot;Droid Sans&quot;, &quot;Apple Color Emoji&quot;, &quot;Segoe UI Emoji&quot;, &quot;Segoe UI Emoji&quot;, &quot;Segoe UI Symbol&quot;, &quot;Lucida Grande&quot;, Helvetica, Arial, sans-serif;font-size:16px;">CSO | CEO | Founder </span><a class="link" href="https://wr.vc/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">WhiteRabbit Ventures</a> | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> </p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><b>MCP: (Model Context Protocol) </b>  An emerging standard for exposing tool and data APIs to AI agents. Mentioned in the transcript as a potential interoperability layer for security vendor integration, though its implementation depth varies widely.</p></li><li><p class="paragraph" style="text-align:left;"><b>Zero Day Clock:</b>  A project tracking time  to  exploitation metrics across disclosed vulnerabilities. In 2026, the median window from public disclosure to confirmed exploitation has compressed to approximately 1.5 days.</p></li><li><p class="paragraph" style="text-align:left;"><b>Vibe Coding: </b>Colloquial term for AI assisted, low  friction software development using LLMs (e.g., Claude Code, GitHub Copilot). Referenced by Caleb Sima as a driver of rapid cybersecurity startup proliferation.</p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <b><a class="link" href="https://links.cloudsecuritypodcast.tv/2026-browser-attack-techniques-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">Push Security</a></b></p><p class="paragraph" style="text-align:center;"><b>Learn how browser-based attacks have evolved</b> — <a class="link" href="https://links.cloudsecuritypodcast.tv/2026-browser-attack-techniques-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">get the 2026 report</a></p><p class="paragraph" style="text-align:left;">Most breaches today start with an attacker targeting cloud and SaaS apps directly over the internet. In most cases, there’s no malware or exploits. Attackers are abusing legitimate functionality, dumping sensitive data, and holding companies to ransom. This is now the standard playbook. </p><p class="paragraph" style="text-align:left;">The common thread? It&#39;s all happening in the browser. </p><p class="paragraph" style="text-align:left;"><a class="link" href="https://links.cloudsecuritypodcast.tv/2026-browser-attack-techniques-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">Get the latest report from Push Security</a> to understand how browser-based attacks work, and where they’ve been used in the wild, breaking down AitM attacks, ClickFix, malicious extensions, OAuth consent attacks, and more.<span style="color:rgb(0, 0, 0);font-family:&quot;DM Sans&quot;, sans-serif;"> </span></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-the-rsa-noise-problem-is-structur"><span style="color:rgb(0, 0, 0);"><b>1. </b></span><b>The RSA Noise Problem Is Structural And It&#39;s Getting Worse</b></h3><p class="paragraph" style="text-align:left;">Caleb Sima doesn&#39;t sugarcoat the RSAC experience for practitioners. With AI tooling and vibe coding lowering the barrier to startup creation, this year&#39;s show floor may have genuinely doubled in density from 2025. The challenge isn&#39;t finding good vendors, it&#39;s that all the signal  to  noise filters have failed. <i>&quot;I cannot tell the difference, man. I personally, who have been in this industry since its inception, cannot tell the difference because all the marketing is the same, all the branding is the same. The only thing that stands out is what gorilla marketing tactic you have decided to use at RSA.&quot;</i> Caleb Sima</p><p class="paragraph" style="text-align:left;">For practitioners walking the floor this year, both speakers converge on a pragmatic filter: stop evaluating vendors on their marketing pitch and start evaluating their API surface. Ashish Rajan frames it cleanly. The minimum viable question for any vendor in 2026 is whether their product is API  accessible and AI  ready. Not whether they have an AI agent story, but whether <i>your</i> internal AI can query, orchestrate, and automate against their platform.<span style="color:rgb(20, 19, 34);">.</span></p><h3 class="heading" style="text-align:left;" id="2-the-ai-enabled-vendor-consolidati"><span style="color:rgb(0, 0, 0);"><b>2. </b></span><b>The AI Enabled Vendor Consolidation Thesis</b></h3><p class="paragraph" style="text-align:left;">The most provocative idea in this week&#39;s transcript is Caleb&#39;s consolidation hypothesis   and it has teeth. The traditional argument for best  of  breed security tooling is that attackers move faster than platform vendors, so you need specialised point solutions at each layer. But that argument breaks down when AI can close the capability gap between a mediocre platform native tool and a category leading specialist. <i>&quot;What if I were a CISO and said, I&#39;m done with this. I&#39;m done with the 500 vendors that I&#39;m dealing with. I&#39;m going to pick one or two that solve 95% of it. I&#39;m gonna be all in on Palo Alto. I&#39;m gonna clear everything out. And where I&#39;ll make up the difference, I&#39;ll use AI.&quot;</i> Caleb Sima</p><p class="paragraph" style="text-align:left;">The logic: consolidate onto two or three major platform vendors to gain deep hooks into your data plane, drive pricing leverage through committed spend, and reduce integration overhead. Then invest in an internal AI platform team  modelled on how cloud platform teams were built in the early 2010s to build vertical automation layers on top of that standardised infrastructure.</p><p class="paragraph" style="text-align:left;">Ashish Rajan notes this isn&#39;t purely theoretical: publicly listed security companies are already acquiring toward this vision. The key CISO  level question Caleb poses is whether the gap between a platform vendor&#39;s mediocre native capability and a best  of  breed specialist is <i>large enough that AI cannot close it</i>. For a growing number of security functions, his answer is: no, it isn&#39;t.</p><p class="paragraph" style="text-align:left;">Caleb&#39;s two  part test for any product pitch at RSAC:</p><ul><li><p class="paragraph" style="text-align:left;">Is the API accessible and cost  reasonable at agent  scale usage? Security vendors price for human  triggered queries   not 24/7 AI automation loops. Probe for usage  based pricing cliffs.</p></li><li><p class="paragraph" style="text-align:left;">Does AI usage of their product give me personalisation and customisation that I couldn&#39;t achieve with the platform vendor&#39;s native tool? If not, consolidate.</p></li></ul><h3 class="heading" style="text-align:left;" id="3-building-the-internal-ai-security"><span style="color:rgb(0, 0, 0);"><b>3. </b></span><b>Building the Internal AI Security Platform Team</b></h3><p class="paragraph" style="text-align:left;">Before there was a cloud team, every business unit bought its own infrastructure. The formation of centralised cloud platform teams with governance, standardisation, and cost management was the architectural move that made cloud scale possible. Caleb argues security is at exactly that inflection point with AI. <i>&quot;Everyone, at least so far, is similar to an enterprise company; they&#39;re all independently working on things that help them automate. Detection response has AI in the SOC, the vuln management team has AI in scanning, red teaming has AI. They&#39;re all separate. There needs to be a centralised function that looks across all of these and finds ways of pulling these things together.&quot;</i>   Caleb Sima</p><p class="paragraph" style="text-align:left;">The centralised AI security platform team&#39;s mandate would span: cross team AI abstraction and cost management; identification of capability gaps that no single vertical owns (executive reporting, cross  domain risk correlation); and providing the internal &quot;glue&quot; that connects enterprise search (Glean, Databricks, Atlassian), security tooling APIs, and AI orchestration layers.</p><p class="paragraph" style="text-align:left;">Ashish adds an important accessibility dimension: this function doesn&#39;t require every team member to be a terminal  level engineer. Enterprise search APIs, MCP connectors, and AI coding agents can enable security professionals with moderate technical fluency to build meaningful automation without deep programming backgrounds.</p><h3 class="heading" style="text-align:left;" id="4-ai-agent-security-still-an-open-b"><span style="color:rgb(0, 0, 0);"><b>4. </b></span><b>AI Agent Security: Still an Open Book</b></h3><p class="paragraph" style="text-align:left;">For practitioners evaluating the wave of AI agent security vendors at RSAC, both speakers deliver a clear  eyed verdict: the category is real, the tooling is largely not ready, and the vendor claims rarely survive first contact with hard questions.</p><p class="paragraph" style="text-align:left;"><i>&quot;I ask them first: can you define to me what an agent is? And I think 70% of the people can&#39;t answer that. So then clearly you can&#39;t track it if you don&#39;t even know what an agent is or how to define an agent.&quot;</i>   Caleb Sima</p><p class="paragraph" style="text-align:left;">The three specific capability gaps where no vendor has a credible answer today:</p><ul><li><p class="paragraph" style="text-align:left;">Agent observability and intent: Distinguishing a security  relevant AI action from an operational or legitimate action requires organisational context that no third  party vendor currently holds. Continuous eval loops are the only current mechanism, and they don&#39;t scale.</p></li><li><p class="paragraph" style="text-align:left;">Identity chain  of  custody across agent hops: In multi  agent architectures, an identity traverses five or six system hops. No current tooling provides a reliable, tamper  evident audit trail for this traversal.</p></li><li><p class="paragraph" style="text-align:left;">Good decision vs. bad decision detection: Full end  to  end visibility of an agent&#39;s actions does not equate to knowing whether those actions are benign or malicious. Context  aware decision classification is still unsolved at production scale.</p></li></ul><p class="paragraph" style="text-align:left;">The actionable implication: when a vendor at RSAC claims full AI agent security coverage, ask them Caleb&#39;s questions. If they can&#39;t define what an agent is in your specific deployment context (workforce laptop vs. Kubernetes production vs. MCP  connected SaaS), they cannot protect it. Treat AI agent controls as incomplete and layer in: retrieval controls, output filtering, tool use restrictions, egress monitoring, and separation of sensitive data from model context.</p><h3 class="heading" style="text-align:left;" id="4-ai-agent-security-still-an-open-b"><span style="color:rgb(0, 0, 0);"><b>4. </b></span><b>The Zero Day Clock and Why Vendor Response Time Is Now Your Problem</b></h3><p class="paragraph" style="text-align:left;">One of the most operationally concrete data points in this week&#39;s conversation is Caleb&#39;s reference to<a class="link" href="https://zerodayclock.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow"> </a><a class="link" href="https://ZeroDayClock.com?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">ZeroDayClock.com</a>  a project tracking time  to  exploitation metrics across disclosed vulnerabilities.</p><p class="paragraph" style="text-align:left;">The trend line is unambiguous: in 2023, the median window from vulnerability disclosure to confirmed exploitation was approximately five months. In 2026, it is approximately 1.5 days. Caleb&#39;s own example from the week: a security researcher published a blog post about a prompt injection vulnerability in a GitHub AI triage bot. Within two days, an attacker had exploited the same company using the exact technique from that post   prompt injecting the bot via the GitHub issue title, downloading open  source tooling as a payload, and establishing C2 entirely through the publicly documented chain.</p><p class="paragraph" style="text-align:left;">This timeline compression means that patch SLAs built around 30  day or even 7  day cycles are architecturally obsolete for high  severity vulnerabilities with public PoC. The practical response is building automated patch pipeline capabilities within the security team that can identify a disclosure, assess organisational exposure, and begin deployment or compensating control activation without waiting for weekly change windows.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">🧠<span style="color:rgb(0, 0, 0);"><b>  MENTAL MODEL OF THE WEEK</b></span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(0, 0, 0);"><b>The Trust Chain Model</b></span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(0, 0, 0);"><b>Developer Workstation  →  SaaS Platform  →  CI/CD Pipeline  →  Cloud IAM Role</b></span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(52, 52, 52);">Cloud compromises rarely start with infrastructure exploitation. They begin by breaking the weakest trust relationship in the identity chain. The attacker only needs one weak link to inherit the privileges of the entire chain. Map every trust relationship in your developer ecosystem  not just your cloud environment.</span></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>📚 RELATED RESOURCES 🎧</b></h2><ul><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://ZeroDayClock.com?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">ZeroDayClock.com</a></b><b>   Track real  time time  to  exploitation metrics across disclosed CVEs</b></p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://techcommunity.microsoft.com/blog/microsoftsentinelblog/accelerate-your-ueba-journey-introducing-the-microsoft-sentinel-ueba-behaviors-workbo/4488278?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">Microsoft Sentinel UEBA Behaviors Workbook</a></b><b>   Official deployment guide and workbook</b></p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">CISA Known Exploited Vulnerabilities Catalogue</a></b><b>   Current KEV list including CVE  2026  3909/3910</b></p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://reliaquest.com/blog/threat-spotlight-casting-a-wider-net-clickfix-deno-and-leaknets-scaling-threat?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">ReliaQuest: LeakNet Threat Spotlight (ClickFix + Deno)</a></b><b>   Full TTP breakdown with detection guidance</b></p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://owasp.org/www-project-top-10-for-large-language-model-applications/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">OWASP Top 10 for LLM Applications</a></b><b>   Framework for AI/LLM risk in enterprise deployments</b></p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://unit42.paloaltonetworks.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">Unit 42: Prompt Guardrail Evasion Research</a></b><b>   March 2026 research on prompt fuzzing evasion rates</b></p></li></ul><h3 class="heading" style="text-align:left;" id="podcast-episode"><b>Podcast Episode</b></h3><ul><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.aisecuritypodcast.com/videos/questions-every-ciso-must-ask-ai-security-vendors?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast   RSAC 2026 Special</a></b><b>  - Full Episode featuring Caleb Sima and Ashish Rajan</b></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a><b>   Weekly cloud security practitioner insights from Ashish Rajan</b></p></li></ul><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a7fcec10-5d00-47b2-a0f2-d7336ac4ddc8/S04EP05.jpg?t=1773864653"/></div><hr class="content_break"><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔<b> </b><span style="color:rgb(20, 19, 34);">Does your security team have explicit ownership of browser-based identity threats  or is the browser still a gap between IT, SOC, and identity?</span><br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=zero-day-exploit-windows-shrink-to-hours-is-your-security-stack-built-for-an-ai-accelerated-threat-landscape" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=93db5df3-99ca-42bf-a271-9cbb4b012224&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🚨 Google Closes $32B Wiz Deal: Why the Browser Is Now Your Biggest Security Blind Spot</title>
  <description>This week Google&#39;s landmark $32B acquisition of Wiz reshapes cloud security, while a new coalition of identity-focused threat actors Scattered Lapsis Hunters continues to dominate enterprise breaches through browser-native attacks. Push Security co-founder Adam Bateman explains why your IDP is not a firewall, how phishing has moved far beyond the inbox, and why the browser is now the most under-protected attack surface in the enterprise. Keywords: browser security, identity attacks, cloud security M&amp;A, supply chain risk, SaaS phishing, consent phishing, Click Fix.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a91515dc-a6e6-43cb-82ad-ebf30c828814/Screenshot_2026-03-12_at_12.21.28_AM.png" length="2056865" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/google-wiz-deal-browser-identity-attacks</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/google-wiz-deal-browser-identity-attacks</guid>
  <pubDate>Thu, 12 Mar 2026 00:25:46 +0000</pubDate>
  <atom:published>2026-03-12T00:25:46Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><h2 class="heading" style="text-align:left;" id="hello-from-the-cloudverse"><span style="background-color:#28EEDA;"><b>Hello from the Cloud-verse!</b></span></h2><p class="paragraph" style="text-align:left;">This week’s Cloud Security Newsletter topic<b>: </b><b>When AI Plays Both Sides: Rethinking SOC Architecture in the Era of 29-Minute Breakouts</b><b> </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" rel="noopener noreferrer nofollow">(continue reading)</a> </p><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://links.cloudsecuritypodcast.tv/2026-browser-attack-techniques-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot"><span class="button__text" style=""> This issue is sponsored by Push Security </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a91515dc-a6e6-43cb-82ad-ebf30c828814/Screenshot_2026-03-12_at_12.21.28_AM.png?t=1773274949"/></a></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">If you had to pick one thread connecting every major enterprise breach of the last 18 months, it wouldn&#39;t be a zero-day or a misconfigured S3 bucket. It would be identity  compromised through the browser.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">This week&#39;s edition comes at a pivotal moment. Google&#39;s $32 billion Wiz acquisition, the largest cybersecurity deal in history, is closed. A coalition of identity-focused threat actors is now operating under a single banner (Scattered Lapsis Hunters), having already compromised MGM, Okta, Marks & Spencer, and Salesforce. And the attack vector enabling all of it? The browser is a surface that most enterprise security programs still treat as someone else&#39;s problem.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">To make sense of this shift, we spoke with Adam Bateman, co-founder of Push Security and former elite red teamer at MWR  whose simulations were so convincing they were mistaken for real nation-state attacks and appeared in public threat intelligence reports. Adam brings a decade of offensive security research to the question of why identity controls are failing and what defenders actually need to do about it.</span><b> </b> <i>[</i><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/browser-security-explained-consent-phishing-click-fix-attacks-the-limits-of-edr?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><p class="paragraph" style="text-align:left;">⚡<b>  ONE STAT THAT MATTERS</b></p><p class="paragraph" style="text-align:left;"><b>72 hours</b></p><p class="paragraph" style="text-align:left;">The time it took threat actor UNC6426 to escalate from a stolen developer token to full AWS administrative control — without exploiting a single infrastructure vulnerability. Identity trust chains are now the primary blast radius multiplier in cloud breaches.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">⚡ TL;DR for Busy Readers</h2><ul><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>Google closes $32B Wiz acquisition</b></span><br><span style="color:rgb(20, 19, 34);"> Expect tighter CNAPP + threat intelligence integration and potential licensing shifts.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>Scattered Lapsis Hunters coalition emerges</b></span><br><span style="color:rgb(20, 19, 34);">Identity-focused actors combining tactics from Scattered Spider, Lapsus$, and ShinyHunters.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>Supply chain breach → AWS admin in 72 hours</b></span><br><span style="color:rgb(20, 19, 34);"> GitHub OIDC trust abuse enabled full environment takeover.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>Audit your GitHub-to-AWS OIDC trust policies today</b></span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>Identity providers ≠ security boundaries</b></span><br><span style="color:rgb(20, 19, 34);"> 40%+ of SaaS apps remain invisible to most conditional access policies.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>Browser security becomes the new EDR frontier</b></span><br><span style="color:rgb(20, 19, 34);"> Modern phishing now executes </span><span style="color:rgb(20, 19, 34);"><b>entirely inside the browser.</b></span></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="this-weeks-security-news">📰 <b>THIS WEEK&#39;S TOP 6 SECURITY HEADLINES</b></h2><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><h3 class="heading" style="text-align:left;" id="1-major-ma-google-closes-32-b-wiz-a"><b>1. </b>🚨<span style="color:rgb(0, 0, 0);"><b> MAJOR M&A  Google Closes $32B Wiz Acquisition</b></span></h3><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>What Happened: </b></span><span style="color:rgb(20, 19, 34);">Google completed its $32 billion all-cash acquisition of Wiz. The deal passed U.S. antitrust review in November 2025 and received unconditional EU approval in February 2026. The combined platform merges Google&#39;s Threat Intelligence and Security Operations with Wiz&#39;s CNAPP/CSPM. Critically, Wiz remains available across AWS, Azure, and Oracle Cloud.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>Why It Matters: </b></span><span style="color:rgb(20, 19, 34);">The consolidation of Mandiant (IR + threat intel) with Wiz (CNAPP/CSPM) creates a formidable platform  and immediate pressure on Palo Alto Networks and Microsoft Defender for Cloud. For teams currently on Wiz: integration roadmap, commercial terms, and Gemini AI integration pace deserve scrutiny over the next 12 months.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(100, 100, 100);"><b>Sources: </b></span><a class="link" href="https://cloud.google.com/blog/products/identity-security/google-completes-acquisition-of-wiz?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">Google Cloud Blog</a> |<a class="link" href="https://www.securityweek.com/wiz-joins-google-cloud-as-landmark-acquisition-closes/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow"> SecurityWeek</a> |<a class="link" href="https://techcrunch.com/2026/03/11/google-completes-32b-acquisition-of-wiz/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow"> TechCrunch</a> |<a class="link" href="https://www.wiz.io/blog/google-closes-deal-to-acquire-wiz?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow"> Wiz Blog</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-supply-chain-stolen-npm-token-giv"><b>2. </b>🚨<span style="color:rgb(0, 0, 0);"><b> SUPPLY CHAIN  Stolen npm Token Gives Attacker Full AWS Admin in 72 Hours</b></span></h3><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>What Happened: </b></span><span style="color:rgb(20, 19, 34);">Threat actor UNC6426 leveraged a developer&#39;s GitHub token  stolen via the nx npm package supply chain compromise  to achieve full cloud environment takeover in under 72 hours. The attacker abused the GitHub-to-AWS OIDC trust relationship to create a new administrator role, exfiltrated Amazon S3 data, performed production data destruction, and publicly renamed all internal GitHub repositories.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>Why It Matters: </b></span><span style="color:rgb(20, 19, 34);">Any IAM role whose trust policy references </span><span style="color:rgb(176, 38, 33);"><a class="link" href="https://token.actions.githubusercontent.com?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">token.actions.githubusercontent.com</a></span><span style="color:rgb(20, 19, 34);"> without a </span><span style="color:rgb(176, 38, 33);">StringEquals</span><span style="color:rgb(20, 19, 34);"> condition on the </span><span style="color:rgb(176, 38, 33);">sub</span><span style="color:rgb(20, 19, 34);"> claim is exploitable today. Audit GitHub-to-AWS OIDC trust configurations immediately and treat overly permissive IAM roles as critical misconfigurations  not policy aspirations.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(100, 100, 100);"><b>Sources: </b></span><a class="link" href="https://thehackernews.com/2026/03/unc6426-exploits-nx-npm-supply-chain.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a> |<a class="link" href="https://labs.cloudsecurityalliance.org/research/briefing-csa-research-note-oidc-trust-chain-abuse-cloud-take/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow"> CSA Research Brief</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-cloud-vuln-leaky-looker-nine-cros"><b>3. </b><span style="color:rgb(22, 60, 119);">🔍</span><span style="color:rgb(0, 0, 0);"><b> CLOUD VULN  &quot;LeakyLooker&quot;: Nine Cross-Tenant Flaws in Google Looker Studio</b></span></h3><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>What Happened: </b></span><span style="color:rgb(20, 19, 34);">Tenable Research disclosed nine cross-tenant vulnerabilities in Google Looker Studio enabling arbitrary SQL queries against BigQuery, Google Sheets, Spanner, PostgreSQL, MySQL, and Cloud Storage. A key flaw: duplicated reports retained stored database credentials, letting the new report owner run custom SQL without knowing the password. Google has patched all issues.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>Why It Matters: </b></span><span style="color:rgb(20, 19, 34);">Analytics and BI platforms connected to sensitive cloud databases are a seriously underappreciated attack surface. The credential-inheritance flaw illustrates how feature convenience (&quot;copy this report&quot;) becomes a security liability at scale. Review access controls on shared Looker Studio reports and audit who can duplicate data-connected dashboards.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(100, 100, 100);"><b>Sources: </b></span><a class="link" href="https://www.tenable.com/blog/leakylooker-google-cloud-looker-studio-vulnerabilities?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">Tenable Research</a> |<a class="link" href="https://thehackernews.com/2026/03/new-leakylooker-flaws-in-google-looker.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow"> The Hacker News</a> |<a class="link" href="https://www.infosecurity-magazine.com/news/google-looker-studios-security-gaps/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow"> Infosecurity Magazine</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-emerging-vector-malicious-rust-cr"><b>4. </b>🚨<span style="color:rgb(0, 0, 0);"><b> EMERGING VECTOR  Malicious Rust Crates and AI-Powered CI/CD Bots Target Developer Secrets</b></span></h3><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>What Happened: </b></span><span style="color:rgb(20, 19, 34);">Researchers discovered five malicious Rust crates on </span><span style="color:rgb(20, 19, 34);"><a class="link" href="https://crates.io?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">crates.io</a></span><span style="color:rgb(20, 19, 34);"> (late February – early March 2026) disguised as time utilities, covertly exfiltrating .env file data. Simultaneously, an AI-powered bot named &quot;hackerbot-claw&quot; scanned public repositories for exploitable GitHub Actions workflows, targeting secrets at Microsoft, Datadog, and Aqua Security. In the Aqua incident, attackers pushed malicious Trivy VS Code extensions and used local AI coding agents to exfiltrate data.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>Why It Matters:</b></span><span style="color:rgb(20, 19, 34);"> .env files frequently contain cloud provider API keys, database credentials, and GitHub tokens. Mandate </span><span style="color:rgb(176, 38, 33);">cargo-audit</span><span style="color:rgb(20, 19, 34);"> and </span><span style="color:rgb(176, 38, 33);">cargo-deny</span><span style="color:rgb(20, 19, 34);"> in all Rust-based CI pipelines. Audit GitHub Actions workflows for </span><span style="color:rgb(176, 38, 33);">pull_request_target</span><span style="color:rgb(20, 19, 34);"> exposure. Treat AI coding agents on developer machines as a monitored security boundary.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(100, 100, 100);"><b>Sources: </b></span><a class="link" href="https://thehackernews.com/2026/03/five-malicious-rust-crates-and-ai-bot.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a> |<a class="link" href="https://socket.dev/blog/5-malicious-rust-crates-posed-as-time-utilities-to-exfiltrate-env-files?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow"> Socket Research</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-emerging-vector-malicious-rust-cr"><b>5. </b><span style="color:rgb(22, 60, 119);">⚠️</span><span style="color:rgb(22, 60, 119);"><b> </b></span><span style="color:rgb(0, 0, 0);"><b>AI SECURITY  OpenAI Acquires Promptfoo, Bringing AI Red-Teaming into the Core Platform</b></span></h3><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>What Happened: </b></span><span style="color:rgb(20, 19, 34);">OpenAI announced plans to acquire Promptfoo, an AI security platform for identifying and remediating vulnerabilities in AI systems. The technology integrates into OpenAI Frontier for enterprise AI agent security testing and monitoring. The open-source project continues.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>Why It Matters: </b></span><span style="color:rgb(20, 19, 34);">Agent security testing  red-teaming, indirect prompt injection, safety evals  is moving from niche AppSec work into core platform capability. Deploying AI agents without built-in red-teaming infrastructure will become a compliance gap, not just a best-practice shortfall.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(100, 100, 100);"><b>Sources: </b></span><a class="link" href="https://openai.com/index/openai-to-acquire-promptfoo/?utm_source=chatgpt.com" target="_blank" rel="noopener noreferrer nofollow">OpenAI and Promptfoo official announcements</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="6-saas-risk-salesforce-warns-of-act"><b>6. </b><span style="color:rgb(22, 60, 119);">⚠️</span><span style="color:rgb(22, 60, 119);"><b> </b></span><span style="color:rgb(0, 0, 0);"><b>SAAS RISK  Salesforce Warns of Active Data-Harvesting Against Experience Cloud Sites</b></span></h3><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>What Happened: </b></span><span style="color:rgb(20, 19, 34);">Salesforce disclosed a threat actor mass-scanning public-facing Experience Cloud sites using a modified version of Mandiant&#39;s AuraInspector to exploit overly permissive guest-user settings. ShinyHunters  part of the Scattered Lapsis Hunters coalition  has publicly claimed responsibility.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>Why It Matters: </b></span><span style="color:rgb(20, 19, 34);">SaaS risk most often sits in authorization design, not software defects. Immediate actions: review guest-user profiles, set external access defaults to private, disable unauthenticated public API access, and inspect Aura event logs for unusual query patterns.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(100, 100, 100);"><b>Sources: </b></span><a class="link" href="https://www.salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">Salesforce guidance and follow-on reporting.</a></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="the-browser-is-your-new-network-per"><span style="color:rgb(0, 0, 0);"><b>The Browser Is Your New Network Perimeter</b></span></h3><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">For most of security&#39;s history, the network was the thing you defended. EDR extended that logic to the endpoint. But there is now a third layer  one that most enterprise security programs have left almost entirely unprotected: the browser.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">The architectural shift is already complete. Employees work inside browsers, not applications. They talk to cloud services, not internal networks. Identity  not network access  is the control plane. And yet almost no organisation has deployed the equivalent of EDR for the browser. That gap is exactly what groups like Scattered Lapsis Hunters are exploiting  and it&#39;s why every major enterprise breach of the past 18 months started not with a firewall bypass, but with an identity compromise that detonated entirely inside the browser.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">This week, Adam Bateman of Push Security walked through exactly how this shift has happened, what attack patterns are dominating, and why the existing stack  IDPs, MFA, SWGs, even EDR  has a structural blind spot that only browser-native visibility can close.</span></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="featured-experts-this-week"><b>Featured Experts This Week </b>🎤</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/a-bateman/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">Adam Bateman</a><span style="color:rgb(20, 19, 34);"> </span><b>- </b> Co-Founder & CEO | <b><a class="link" href="https://links.cloudsecuritypodcast.tv/2026-browser-attack-techniques-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">Push Security</a></b></p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>IDP (Identity Provider):</b></span><span style="color:rgb(37, 96, 167);"><b> </b></span><span style="color:rgb(52, 52, 52);">A centralised platform (e.g., Okta, Entra ID) that manages authentication across applications. Adam&#39;s key point: IDPs function more like domain controllers than firewalls  they provide a management layer, but attackers bypass them by targeting local accounts or SaaS apps users access outside SSO flows.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(0, 0, 0);"><b>OIDC (OpenID Connect)</b></span><span style="color:rgb(37, 96, 167);"><b>:</b></span><span style="color:rgb(37, 96, 167);"> </span><span style="color:rgb(52, 52, 52);">An authentication protocol built on OAuth 2.0. The GitHub-to-AWS OIDC trust is a common CI/CD pattern  but without a StringEquals condition on the sub claim, any attacker with a GitHub token can assume privileged IAM roles.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(0, 0, 0);"><b>Click Fix Attack:</b></span><span style="color:rgb(37, 96, 167);"><b> </b></span><span style="color:rgb(52, 52, 52);">A social engineering technique that injects a malicious command into the user&#39;s clipboard via JavaScript. The user is prompted to paste and execute via Windows Run  downloading malware. EDR often misses it because the command runs as a direct user action, not a suspicious process chain.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(0, 0, 0);"><b>Consent Fix Attack:</b></span><span style="color:rgb(37, 96, 167);"><b> </b></span><span style="color:rgb(52, 52, 52);">Push Security&#39;s newly named variant combining Click Fix with OAuth consent phishing, attributed to Midnight Blizzard. The user is tricked into performing actions granting an attacker full Azure control  entirely inside the browser, with zero code executed on the endpoint.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(0, 0, 0);"><b>Consent Phishing </b></span><span style="color:rgb(37, 96, 167);"><b>: </b></span><span style="color:rgb(52, 52, 52);">An attack tricking users into granting OAuth permissions to a malicious application. The attacker then controls it via API, accessing email and files and performing password resets  bypassing MFA entirely by using a legitimate token rather than logging in.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(0, 0, 0);"><b>Omni-channel Phishing : </b></span><span style="color:rgb(52, 52, 52);">The evolution of credential phishing beyond email. Attackers now deliver phishing links through LinkedIn DMs, SMS, social media comments, Google Ads sponsored results, and personal email inboxes  all detonating inside the browser.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(0, 0, 0);"><b>Scattered Lapsis Hunters:</b></span><span style="color:rgb(37, 96, 167);"><b> </b></span><span style="color:rgb(52, 52, 52);">The newly-formed coalition of Scattered Spider, Lapsus$, and ShinyHunters  collectively responsible for breaches at MGM, Okta, Microsoft, JLR, Marks & Spencer, and Salesforce. Their MO is purely identity-first; none of their major breaches started on the network.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(0, 0, 0);"><b>Secure Web Gateway (SWG):</b></span><span style="color:rgb(37, 96, 167);"><b> </b></span><span style="color:rgb(52, 52, 52);">A proxy-based solution for monitoring web traffic via SSL interception. Adam&#39;s analysis: modern JavaScript-heavy SaaS apps stage their payloads client-side  meaning the SWG never sees the full application. Browser-native tools have the full runtime context the SWG never will.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(0, 0, 0);"><b>CNAPP: </b></span><span style="color:rgb(52, 52, 52);">Cloud-Native Application Protection Platform  an integrated platform combining CSPM, workload protection, network security, and IaC scanning. Wiz is the defining product in this category, now integrated with Google&#39;s Mandiant threat intelligence and Security Operations.</span></p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <b><a class="link" href="https://links.cloudsecuritypodcast.tv/2026-browser-attack-techniques-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">Push Security</a></b></p><p class="paragraph" style="text-align:center;"><b>Learn how browser-based attacks have evolved</b> — <a class="link" href="https://links.cloudsecuritypodcast.tv/2026-browser-attack-techniques-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">get the 2026 report</a></p><p class="paragraph" style="text-align:left;">Most breaches today start with an attacker targeting cloud and SaaS apps directly over the internet. In most cases, there’s no malware or exploits. Attackers are abusing legitimate functionality, dumping sensitive data, and holding companies to ransom. This is now the standard playbook. </p><p class="paragraph" style="text-align:left;">The common thread? It&#39;s all happening in the browser. </p><p class="paragraph" style="text-align:left;"><a class="link" href="https://links.cloudsecuritypodcast.tv/2026-browser-attack-techniques-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">Get the latest report from Push Security</a> to understand how browser-based attacks work, and where they’ve been used in the wild, breaking down AitM attacks, ClickFix, malicious extensions, OAuth consent attacks, and more.<span style="color:rgb(0, 0, 0);font-family:&quot;DM Sans&quot;, sans-serif;"> </span></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-the-idp-is-not-a-firewall-and-att"><span style="color:rgb(0, 0, 0);"><b>1. The IDP Is Not a Firewall  And Attackers Know It</b></span></h3><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">The central misconception Adam targets is the assumption that deploying Okta or Entra ID creates a security perimeter analogous to a firewall. It doesn&#39;t. It creates a management layer  and like every management layer, it can be bypassed.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><i>&quot;People take their IDP, whether it be Okta, Entra, whatever it might be, and they say: yeah, it&#39;s this with a hundred SaaS applications behind it and everything&#39;s got MFA on it. When you actually dig into it... it&#39;s not a firewall, it&#39;s an overarching management layer. If you gained access to Okta, you could compromise everything beneath it  but you can also get into those underlying apps in lots of other ways as well.&quot;</i></span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(100, 100, 100);"> </span><span style="color:rgb(20, 19, 34);">The practical mechanism: when users encounter an application login page, they often bypass SSO entirely by clicking &quot;Sign in with Google&quot; or creating a local account outside the IDP. Adam&#39;s data shows this happening across thousands of applications, including services like Zapier that can be weaponised to send internal Slack messages once compromised.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(37, 96, 167);"><b>What this means for your architecture:</b></span></p><ul><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">Your IDP policy is only as effective as your enforcement coverage. 40%+ of SaaS apps in most organisations are shadow IT, invisible to your IDP.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">Credential stuffing attacks bypass IDP entirely. Attackers don&#39;t need to defeat MFA if they can log in with a local credential that was never federated.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">OAuth and consent-phishing attacks bypass MFA regardless of strength  including hardware keys and passkeys.</span></p></li></ul><h3 class="heading" style="text-align:left;" id="2-the-architectural-shift-most-secu"><span style="color:rgb(0, 0, 0);"><b>2. The Architectural Shift Most Security Teams Haven&#39;t Accounted For</b></span></h3><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">The shift Adam describes is structural, not incremental. In the legacy model, the attack surface was open ports. In the modern model, applications live in the cloud; identity is the only path to them. And identity lives in the browser.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><i>&quot;We used to work on our laptops with applications talking to the network. And now we work inside our browsers with our browsers talking to the cloud. The laptop to the network was bound together with ports and protocols. The browser to cloud is bound together with identity. So the modern attacks are now: how do I get access to this identity in a creative way to get access to the cloud services where all the critical data is?&quot; - </i></span><span style="color:rgb(100, 100, 100);"><b>Adam Bateman</b></span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">This is why groups like Scattered Lapsis Hunters are so effective. They&#39;re not finding novel exploits, they&#39;re applying sound offensive logic to an architecture most defenders are still protecting with the wrong tools. Even organisations that are 50% on-premise have a cloud and SaaS footprint that represents an uncovered attack surface. It&#39;s not a transition problem, it&#39;s a permanent gap without browser-level visibility.</span></p><h3 class="heading" style="text-align:left;" id="3-phishing-has-outgrown-the-inbox"><span style="color:rgb(0, 0, 0);"><b>3. Phishing Has Outgrown the Inbox</b></span></h3><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">Two distinct evolutions of phishing that bypass both traditional email security and endpoint detection entirely:</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(37, 96, 167);"><b>Omni-channel Phishing</b></span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">Push Security has documented campaigns where attackers compromised LinkedIn accounts and used them to DM phishing links to high-profile CEOs  from a known, trusted contact. The corporate email gateway saw nothing. Adam&#39;s team has also observed delivery via SMS, social media comments, and legitimate SaaS apps including DocuSign documents with embedded phishing links and Google Ads-distributed phishing via sponsored results.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(37, 96, 167);"><b>Legitimate SaaS as a Phishing Vehicle</b></span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">Traditional email security works by identifying illegitimate sending domains. Attackers have neutralised that control by sending phishing from legitimate SaaS platforms. A $20 DocuSign account, a real-looking court order with a large signing button  and the email arrives from </span><span style="color:rgb(20, 19, 34);"><a class="link" href="https://docusign.com?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">docusign.com</a></span><span style="color:rgb(20, 19, 34);">, which is legitimate. The phish happens when the user opens the browser to sign.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(37, 96, 167);"><b>Click Fix & Consent Fix: Browser-Native Payload Chains</b></span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">Click Fix (clipboard injection → user pastes and executes) is now prolific. The Consent Fix variant  attributed to Midnight Blizzard  is the most technically significant development: a user hits a watering-hole site, performs browser actions, and the result is a full Azure compromise. No PowerShell. No endpoint execution. No EDR alert.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><i>&quot;Email is no longer the target anymore. Phishing has evolved to a lot more things happening inside the browser.&quot; - Ashish</i></span></p><h3 class="heading" style="text-align:left;" id="4-what-browser-security-actually-lo"><span style="color:rgb(0, 0, 0);"><b>4. What Browser Security Actually Looks Like  And Who Owns It</b></span></h3><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">The ownership question for browser security is unresolved in most enterprises. IT owns browser deployment. But browser security  detection and response for identity compromise, phishing, malicious extensions, session hijacking  belongs to no one.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">Push Security positions itself as detection and response tooling bought by the same team that runs EDR. The mechanism: a browser extension that observes logins across all SaaS applications  including shadow IT, inspects the DOM, profiles login pages, and detects cloned phishing pages. Because it covers every identity event across every app (not just IDP-managed ones), it closes the gap SSPM tools can&#39;t reach via API alone.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">The longer-term category play: the displacement of Secure Web Gateways. The same evolutionary logic that transformed AV → EDR is now playing out with SWG → Browser Security.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(0, 0, 0);"><b>Practical steps for security architects:</b></span></p><ul><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">Map your SaaS footprint honestly  including shadow IT. 40%+ of SaaS apps are unmanaged. You cannot secure what you cannot see.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">Audit your IDP coverage. Identify every application where users can log in without SSO and either enforce federated identity or accept and monitor the risk.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">Review OAuth app permissions across M365 and Google Workspace for apps with </span><span style="color:rgb(20, 19, 34);"><a class="link" href="https://Mail.Read?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">Mail.Read</a></span><span style="color:rgb(20, 19, 34);">, Mail.Send, or Files.ReadWrite granted by individual users.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">Add browser security to your stack evaluation  Push Security, enterprise browser tooling, or managed browser solutions.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);">Assign ownership. SOC, identity team, or cloud security  someone needs to own this explicitly, or it will remain unowned.</span></p></li></ul><p class="paragraph" style="text-align:left;">✅<span style="color:rgb(0, 0, 0);"><b> WHAT SECURITY LEADERS SHOULD DO THIS WEEK</b></span></p><ol start="1"><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>Audit GitHub-to-AWS OIDC roles </b></span><span style="color:rgb(20, 19, 34);">for missing </span><span style="color:rgb(176, 38, 33);">sub</span><span style="color:rgb(20, 19, 34);"> claim restrictions  the misconfiguration that enabled the 72-hour AWS takeover.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>Review SaaS analytics access controls </b></span><span style="color:rgb(20, 19, 34);">for dashboards connected to production databases, particularly duplication and sharing permissions.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>Add dependency-scanning to Rust pipelines </b></span><span style="color:rgb(20, 19, 34);">using </span><span style="color:rgb(176, 38, 33);">cargo-audit</span><span style="color:rgb(20, 19, 34);"> and </span><span style="color:rgb(176, 38, 33);">cargo-deny</span><span style="color:rgb(20, 19, 34);"> to detect malicious crates.</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>Audit Salesforce Experience Cloud guest user profiles </b></span><span style="color:rgb(20, 19, 34);">to ensure anonymous users cannot access internal objects or APIs.</span></p></li></ol><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 19, 34);"><b>Map your full SaaS footprint </b></span><span style="color:rgb(20, 19, 34);"> including shadow IT  and assign explicit ownership of browser-based identity threat detection.</span></p><hr class="content_break"><p class="paragraph" style="text-align:left;">🧠<span style="color:rgb(0, 0, 0);"><b>  MENTAL MODEL OF THE WEEK</b></span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(0, 0, 0);"><b>The Trust Chain Model</b></span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(0, 0, 0);"><b>Developer Workstation  →  SaaS Platform  →  CI/CD Pipeline  →  Cloud IAM Role</b></span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(52, 52, 52);">Cloud compromises rarely start with infrastructure exploitation. They begin by breaking the weakest trust relationship in the identity chain. The attacker only needs one weak link to inherit the privileges of the entire chain. Map every trust relationship in your developer ecosystem  not just your cloud environment.</span></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>📚 RELATED RESOURCES 🎧</b></h2><ul><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://pushsecurity.com/blog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(46, 117, 182)">Push Security Research Blog</a></b> — Click Fix, Consent Fix, and Omnichannel Phishing</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://cloud.google.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(46, 117, 182)">Google Cloud Threat Horizons Report H1 2026</a></b> — Supply chain and OIDC trust analysis</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://tenable.com/blog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(46, 117, 182)">Tenable LeakyLooker Research</a></b> — Cross-tenant flaws in cloud analytics platforms</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://cisa.gov/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(46, 117, 182)">CISA GitHub Actions Security Hardening Guide</a></b></p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://cheatsheetseries.owasp.org/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(46, 117, 182)">OWASP OAuth Security Cheatsheet</a></b> — Consent phishing and OAuth app risks</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://socket.dev/blog?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(46, 117, 182)">Socket Research</a></b> — Malicious Rust crates and supply chain detection</p></li></ul><h3 class="heading" style="text-align:left;" id="cloud-security-podcast"><b>Cloud Security Podcast</b></h3><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/browser-security-explained-consent-phishing-click-fix-attacks-the-limits-of-edr?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow"><b>Cloud Security Podcast Episode with Adam Bateman</b></a></p></li></ul><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c611ea95-0551-4401-a841-794bda7aecbf/Screenshot_2026-03-12_at_12.20.06_AM.png?t=1773275004"/></div><hr class="content_break"><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔<b> </b><span style="color:rgb(20, 19, 34);">Does your security team have explicit ownership of browser-based identity threats  or is the browser still a gap between IT, SOC, and identity?</span><br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=google-closes-32b-wiz-deal-why-the-browser-is-now-your-biggest-security-blind-spot" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=b29b404a-e812-4b27-bbec-6385381ed7c5&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🚨 The 29-Minute SOC: Why AI-Accelerated Attacks Are Forcing Security Teams to Rethink Response</title>
  <description>CrowdStrike’s 2026 report reveals attackers breaking out in minutes while espionage groups hide command-and-control traffic inside cloud APIs. This week’s Cloud Security Brief examines what this means for enterprise SOC architecture and why AI-assisted investigations are becoming unavoidable.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/30491288-9a63-4c9c-bc64-ea9ba2d58ad0/Screenshot_2026-03-04_at_10.33.35_PM.png" length="1876222" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/29-minute-soc-ai-attacks</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/29-minute-soc-ai-attacks</guid>
  <pubDate>Wed, 04 Mar 2026 23:21:00 +0000</pubDate>
  <atom:published>2026-03-04T23:21:00Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><h2 class="heading" style="text-align:left;" id="hello-from-the-cloudverse"><span style="background-color:#28EEDA;"><b>Hello from the Cloud-verse!</b></span></h2><p class="paragraph" style="text-align:left;">This week’s Cloud Security Newsletter topic<b>: </b><b>When AI Plays Both Sides: Rethinking SOC Architecture in the Era of 29-Minute Breakouts</b><b> </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" rel="noopener noreferrer nofollow">(continue reading)</a> </p><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://links.cloudsecuritypodcast.tv/2026-browser-attack-techniques-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response"><span class="button__text" style=""> This issue is sponsored by Push Security </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/30491288-9a63-4c9c-bc64-ea9ba2d58ad0/Screenshot_2026-03-04_at_10.33.35_PM.png?t=1772663875"/></a><div class="image__source"><span class="image__source_text"><p>This image was generated by AI. It&#39;s still experimental, so it might not be a perfect match!</p></span></div></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;">The security landscape shifted this week not because of a single breach, but because of <b>three signals that point to a structural change in cyber defense.</b></p><p class="paragraph" style="text-align:left;">First, CrowdStrike’s 2026 Global Threat Report revealed that the average adversary breakout time is now 29 minutes, with the fastest intrusion completing lateral movement in 27 seconds.</p><p class="paragraph" style="text-align:left;">Second, IBM’s X-Force Index shows vulnerability exploitation overtaking phishing as the #1 initial access vector, driven by automated vulnerability discovery and AI-assisted attacks.</p><p class="paragraph" style="text-align:left;">Third, Google and Mandiant disrupted a PRC-linked campaign that hid command-and-control traffic inside Google Sheets API calls, bypassing traditional allowlists.</p><p class="paragraph" style="text-align:left;">Together, these developments point to a clear conclusion:</p><p class="paragraph" style="text-align:left;">Defensive response timelines are now measured in minutes, not hours.</p><p class="paragraph" style="text-align:left;">To understand what this means for enterprise SOC architecture, this week’s featured expert Edward Wu, Founder of <a class="link" href="https://links.cloudsecuritypodcast.tv/dropzone-request-demo-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">DropZone AI</a>, explains why the future SOC model is increasingly becoming:</p><p class="paragraph" style="text-align:left;"><b>“Humans set strategy. AI executes.” </b> <i>[</i><a class="link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">⚡ TL;DR for Busy Readers</h2><ul><li><p class="paragraph" style="text-align:left;"><b>Attackers now break out in 29 minutes.</b><br>If your MTTD + MTTR exceeds this, lateral movement is statistically likely.</p></li><li><p class="paragraph" style="text-align:left;"><b>PRC-linked attackers used Google Sheets as covert C2.</b><br>➡️ Audit Google API usage and service account behavior now.</p></li><li><p class="paragraph" style="text-align:left;"><b>Microsoft launched native CIEM across AWS, GCP, and Azure.</b><br>➡️ Expect a surge of overprivileged identity findings after enabling.</p></li><li><p class="paragraph" style="text-align:left;"><b>Vulnerability exploitation is now the #1 attack vector (IBM).</b><br>➡️ Prioritize unauthenticated CVE patching and AI-generated code scanning.</p></li><li><p class="paragraph" style="text-align:left;"><b>AI SOC analysts can now perform tier-1 investigations autonomously.</b><br>➡️ Start documenting environment context and response authorization policies.</p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="this-weeks-security-news">📰 <b>THIS WEEK&#39;S TOP 4 SECURITY HEADLINES</b></h2><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><h3 class="heading" style="text-align:left;" id="1-crowd-strike-2026-global-threat-r"><b>1. CrowdStrike 2026 Global Threat Report: AI Compresses Adversary Breakout Time to 29 Minutes</b></h3><p class="paragraph" style="text-align:left;"><b>WHAT HAPPENED</b></p><p class="paragraph" style="text-align:left;">CrowdStrike&#39;s 2026 Global Threat Report documents a 65% increase in attack speed year-over-year. The average eCrime breakout time is now 29 minutes; the fastest observed breakout: 27 seconds; in one intrusion, exfiltration began within four minutes of initial access. AI is operating as both accelerant and new attack surface: adversaries exploited legitimate GenAI tools at 90+ organizations via malicious prompt injection; exploited vulnerabilities in AI development platforms for persistence and ransomware staging; and published malicious AI servers impersonating trusted services. Russia-nexus FANCY BEAR deployed LLM-enabled malware (LAMEHUG) for automated recon; DPRK-nexus FAMOUS CHOLLIMA scaled insider operations via AI-generated personas. 82% of 2025 detections were malware-free.</p><p class="paragraph" style="text-align:left;"><b>WHY IT MATTERS</b></p><p class="paragraph" style="text-align:left;">The 29-minute figure is not a metric to track it&#39;s a hard architectural constraint. If your MTTD + MTTR combined exceeds 29 minutes, lateral movement is statistically likely before containment begins. In cloud environments, where identity federation and service account trust chains enable rapid cross-account traversal, this window compresses further.</p><p class="paragraph" style="text-align:left;">The GenAI prompt injection finding is the most operationally novel data point in the report. Adversaries are no longer exploiting software they are socially engineering software, tricking AI-enabled applications into misusing their own service credentials. This is insider threat detection applied to non-human identities.</p><p class="paragraph" style="text-align:left;">🎯 <b>Action:</b> </p><ul><li><p class="paragraph" style="text-align:left;">Validate EDR/XDR detection coverage for malware-free intrusion patterns; establish DLP and governance controls for enterprise GenAI tool usage; </p></li><li><p class="paragraph" style="text-align:left;">Pressure-test detection gaps in AI development platform access (MLflow, SageMaker, Vertex AI); </p></li><li><p class="paragraph" style="text-align:left;">Benchmark MTTD + MTTR against the 29-minute breakout threshold.</p></li></ul><p class="paragraph" style="text-align:left;">👉 <a class="link" href="https://www.crowdstrike.com/en-us/global-threat-report/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow"><b>Read the CrowdStrike Threat Report →</b></a></p><p class="paragraph" style="text-align:left;"><b>👉🏾 </b><a class="link" href="https://links.cloudsecuritypodcast.tv/2026-browser-attack-techniques-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow"><b>Read the 2026 Browser Attack Techniques Report → </b></a></p><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://www.crowdstrike.com/en-us/press-releases/2026-crowdstrike-global-threat-report/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow"> CrowdStrike Press Release</a> |<a class="link" href="https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-global-threat-report-findings/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow"> CrowdStrike Blog</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-microsoft-embeds-native-ciem-acro"><b>2. Microsoft Embeds Native CIEM Across Azure, AWS, and GCP in Defender for Cloud</b></h3><p class="paragraph" style="text-align:left;"><b>WHAT HAPPENED</b></p><p class="paragraph" style="text-align:left;">Cloud Infrastructure Entitlement Management (CIEM) is now a native capability in Microsoft Defender for Cloud across all three major cloud platforms. Key changes: inactive identity detection now evaluates unused role assignments (not sign-in activity); the inactivity lookback window extends to 90 days (up from 45); CIEM onboarding no longer requires elevated high-risk permissions; and GCP Cloud Logging ingestion is available in preview. This update follows Microsoft&#39;s announced retirement of Entra Permissions Management Defender CSPM is now the defined migration destination.</p><p class="paragraph" style="text-align:left;"><b>WHY IT MATTERS</b></p><p class="paragraph" style="text-align:left;">This is a meaningful consolidation with real procurement implications. Enterprises running Entra Permissions Management as a standalone CIEM tool now have a clear migration path. More consequentially, the shift from sign-in-based to role-assignment-based inactivity detection will surface a materially larger set of overprivileged identities especially service principals and managed identities in AWS and GCP that authenticate via service accounts rather than interactive login.</p><p class="paragraph" style="text-align:left;">Expect an initial wave of new CIEM findings post-migration. The right move is to build a remediation workflow and establish a baseline before enabling at scale not to be caught flat-footed by hundreds of new recommendations on day one.</p><p class="paragraph" style="text-align:left;">🎯 <b>Action:</b> </p><ul><li><p class="paragraph" style="text-align:left;">Plan CIEM migration from Entra Permissions Management before the retirement deadline; </p></li><li><p class="paragraph" style="text-align:left;">pre-build remediation workflows for the likely surge in overprivileged identity findings; </p></li><li><p class="paragraph" style="text-align:left;">pay particular attention to non-human identities (service principals, managed identities) that don&#39;t generate sign-in events.</p></li></ul><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://learn.microsoft.com/en-us/azure/defender-for-cloud/release-notes?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow"> Microsoft Learn Release Notes</a> |<a class="link" href="https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/the-future-of-ciem-in-microsoft-defender-for-cloud/4398169?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow"> Microsoft Tech Community</a> |<a class="link" href="https://learn.microsoft.com/en-us/azure/defender-for-cloud/permissions-management?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow"> Microsoft Learn CIEM Overview</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-google-and-mandiant-disrupt-prc-e"><b>3. Google and Mandiant Disrupt PRC Espionage Campaign Abusing Google Sheets as Covert C2</b></h3><p class="paragraph" style="text-align:left;"><b>WHAT HAPPENED</b></p><p class="paragraph" style="text-align:left;">Google Threat Intelligence Group (GTIG), Mandiant, and partners took action to disrupt a global espionage campaign targeting telecommunications and government organizations across four continents. The threat actor UNC2814, a suspected PRC-nexus group tracked since 2017 achieved confirmed intrusions across 53 victims in 42 countries. Central to the campaign was the GRIDTIDE backdoor: a C-based malware that abuses the Google Sheets API as a communication channel to disguise C2 traffic. Google terminated all attacker-controlled Cloud Projects and released indicators of compromise.</p><p class="paragraph" style="text-align:left;"><b>WHY IT MATTERS</b></p><p class="paragraph" style="text-align:left;">This campaign is a direct operational threat to any enterprise running Google Workspace or permitting Google APIs through their perimeter which is nearly every large organization. GRIDTIDE hides malicious traffic within legitimate cloud API requests, requiring no exploit and leaving no conventional network indicator: the backdoor is just another HTTPS call to <a class="link" href="https://googleapis.com?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">googleapis.com</a>.</p><p class="paragraph" style="text-align:left;">Post-intrusion, the group moved laterally via SSH, escalated privileges, and deployed SoftEther VPN Bridge for persistent encrypted egress infrastructure metadata suggests active use since July 2018. Google expects UNC2814 to work to re-establish its footprint: this campaign is disrupted, not finished.</p><p class="paragraph" style="text-align:left;">🎯 <b>Action:</b> </p><ul><li><p class="paragraph" style="text-align:left;">Audit Google Service Account creation and API access patterns in GCP/GWS; </p></li><li><p class="paragraph" style="text-align:left;">Deploy Google-provided search queries to scan for GRIDTIDE IOCs; </p></li><li><p class="paragraph" style="text-align:left;">build SIEM/NDR rules to flag anomalous Sheets API call volumes from non-browser user agents; </p></li><li><p class="paragraph" style="text-align:left;">treat SoftEther VPN traffic as a high-fidelity indicator.</p></li></ul><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/disrupting-gridtide-global-espionage-campaign?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow"> Google Cloud Blog / GTIG</a> |<a class="link" href="https://thehackernews.com/2026/02/google-disrupts-unc2814-gridtide.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow"> The Hacker News</a> |<a class="link" href="https://www.cybersecuritydive.com/news/china-cyberattacks-telecommunications-google-sheets/813082/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow"> Cybersecurity Dive</a> |<a class="link" href="https://www.theregister.com/2026/02/25/google_and_friends_disrupt_unc2814/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow"> The Register</a> |<a class="link" href="https://www.infosecurity-magazine.com/news/google-prolific-china-hacking/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow"> Infosecurity Magazine</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-ibm-x-force-2026-vulnerability-ex"><b>4. IBM X-Force 2026: Vulnerability Exploitation Overtakes Phishing as #1 Attack Vector</b></h3><p class="paragraph" style="text-align:left;"><b>WHAT HAPPENED</b></p><p class="paragraph" style="text-align:left;">IBM&#39;s 2026 X-Force Threat Intelligence Index reports that vulnerability exploitation became the leading cause of attacks in 2025, accounting for 40% of incidents. A 44% increase in public-facing application attacks was driven by missing authentication controls and AI-enabled vulnerability discovery. Large supply chain and third-party compromises nearly quadrupled since 2020. X-Force tracked nearly 40,000 vulnerabilities in the year 56% of disclosed flaws required no authentication to exploit. AI-assisted coding tools are compounding the exposure, with unvetted generated code feeding insecure pipelines. Infostealer malware drove the exposure of 300,000+ ChatGPT credentials on dark web marketplaces, signaling that AI platforms now carry credential risk on par with core enterprise SaaS.</p><p class="paragraph" style="text-align:left;"><b>WHY IT MATTERS</b></p><p class="paragraph" style="text-align:left;">The displacement of phishing by vulnerability exploitation as the leading initial access vector is a structural signal that should directly influence defensive investment allocation. The 56% of vulnerabilities requiring no authentication is particularly alarming in cloud-native environments, where public-facing APIs, serverless functions, and container ingress points routinely bypass traditional perimeter controls.</p><p class="paragraph" style="text-align:left;">The 4x supply chain increase since 2020 is a direct indictment of CI/CD pipeline security maturity industry-wide. For teams embracing AI-assisted development, the risk compounds: AI-generated code is entering pipelines faster than security reviews can keep pace, and attackers know it.</p><p class="paragraph" style="text-align:left;">🎯 <b>Action:</b> </p><ul><li><p class="paragraph" style="text-align:left;">Prioritize unauthenticated CVE remediation in patch queues; </p></li><li><p class="paragraph" style="text-align:left;">extend SAST/SCA coverage into AI-generated code outputs; </p></li><li><p class="paragraph" style="text-align:left;">audit third-party SaaS integration trust chains; </p></li><li><p class="paragraph" style="text-align:left;">apply credential hygiene controls to enterprise AI platform accounts (ChatGPT Enterprise, Copilot, Claude) as you would to identity providers.</p></li></ul><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://newsroom.ibm.com/2026-02-25-ibm-2026-x-force-threat-index?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow"> IBM Newsroom</a> |<a class="link" href="https://www.ibm.com/reports/threat-intelligence?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow"> IBM X-Force Report</a> |<a class="link" href="https://industrialcyber.co/reports/ibm-x-force-reports-44-surge-in-exploitation-of-public-facing-applications-as-supply-chain-and-identity-attacks-intensify/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow"> Industrial Cyber</a></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="when-ai-plays-both-sides-rethinking"><b>When AI Plays Both Sides: </b><br>Rethinking SOC Architecture in the Era of 29-Minute Breakouts</h3><p class="paragraph" style="text-align:left;">There is a quiet but consequential arms race underway inside enterprise security operations, and it&#39;s not playing out in the way most security leaders initially anticipated. The fear was that AI would produce dramatically more sophisticated attacks autonomous, multi-stage campaigns executing end-to-end. The reality, as Drop Zone AI&#39;s Edward Wu explains, is more operationally challenging in a different way: AI has fundamentally changed the economics and speed of attack preparation and initial access, even before it automates full campaigns end-to-end.</p><p class="paragraph" style="text-align:left;">This week&#39;s CrowdStrike report puts a precise figure on what that means for defenders: 29 minutes from initial access to lateral movement, with a fastest-ever 27-second observed breakout. The question for every cloud security leader is not whether their SIEM caught the alert, it&#39;s whether their entire detection and response pipeline, from signal to containment action, can complete within that window.</p><p class="paragraph" style="text-align:left;">For cloud environments specifically, the challenge is amplified. Identity federation, service account trust chains, and cross-account IAM relationships mean that a single compromised credential can traverse from one AWS account to an entire organization&#39;s environment far faster than a traditional on-prem lateral movement scenario. The GRIDTIDE campaign disclosed this week is a concrete illustration: no exploit, no conventional indicator, just legitimate API calls that an overwhelmed tier-1 analyst reviewing a queue of 300 alerts would have no reasonable way to flag in time.</p><p class="paragraph" style="text-align:left;">Edward Wu&#39;s framing of the solution is worth sitting with: not &quot;AI replaces humans in the SOC,&quot; but &quot;humans set strategy, AI executes.&quot; The three components of human strategy he identifies: scope of work, scope of authorization, and business context are exactly the kinds of decisions that cannot be automated, and exactly what most security teams are still trying to find time to make amid a flood of alerts. That is the real asymmetry to close.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="featured-experts-this-week"><b>Featured Experts This Week </b>🎤</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/edwardxwu/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow"><b>Edward Wu</b></a><b>- </b> Founder & CEO | <a class="link" href="https://links.cloudsecuritypodcast.tv/dropzone-request-demo-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">Dropzone AI</a></p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><b>AI SOC Analyst</b> An AI agent category designed to autonomously investigate security alerts at tier-1 analyst quality or above. Tools in this category (such as Drop Zone AI) analyze alert data, correlate with environmental context, and produce investigation outputs without requiring a human analyst to review each alert from scratch.</p></li><li><p class="paragraph" style="text-align:left;"><b>Prompt Injection</b> An attack technique targeting AI-enabled applications whereby malicious input is crafted to override or manipulate the application&#39;s intended behavior. In an enterprise security context, this translates to a service account being &quot;social engineered&quot; tricked into performing actions outside its intended scope, generating behavioral anomalies detectable by SOC tooling.</p><p class="paragraph" style="text-align:left;"></p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <a class="link" href="https://links.cloudsecuritypodcast.tv/2026-browser-attack-techniques-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow"><b>Push Security</b></a></p><p class="paragraph" style="text-align:center;"><b>Learn how browser-based attacks have evolved</b> — <a class="link" href="https://links.cloudsecuritypodcast.tv/2026-browser-attack-techniques-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">get the 2026 report</a></p><p class="paragraph" style="text-align:left;">Most breaches today start with an attacker targeting cloud and SaaS apps directly over the internet. In most cases, there’s no malware or exploits. Attackers are abusing legitimate functionality, dumping sensitive data, and holding companies to ransom. This is now the standard playbook. </p><p class="paragraph" style="text-align:left;">The common thread? It&#39;s all happening in the browser. </p><p class="paragraph" style="text-align:left;"><a class="link" href="https://links.cloudsecuritypodcast.tv/2026-browser-attack-techniques-mar2026?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">Get the latest report from Push Security</a> to understand how browser-based attacks work, and where they’ve been used in the wild, breaking down AitM attacks, ClickFix, malicious extensions, OAuth consent attacks, and more.<span style="color:rgb(0, 0, 0);font-family:&quot;DM Sans&quot;, sans-serif;"> </span></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><h3 class="heading" style="text-align:left;" id="keeping-up-with-the-29-min-attacker"><b>Keeping up with the 29min Attacker Window as SOC</b><b> (</b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow"><b>Full Episode here</b></a><b>)</b></h3><hr class="content_break"><h3 class="heading" style="text-align:left;" id="the-analytics-gap-is-not-a-headcoun"><b>The Analytics Gap Is Not a Headcount Problem It&#39;s an Architecture Problem</b></h3><p class="paragraph" style="text-align:left;">Edward Wu has spent more than a decade at the intersection of alert generation and alert investigation. Eight years at Actual Hub Networks building NDR detection systems gave him an unusually clear view of a dynamic that most security teams experience as a chronic background stressor: the volume of alerts is structurally outpacing the capacity to process them. What&#39;s changed and why he founded Drop Zone AI is that AI agents have reached the point where they can close that gap operationally, not just theoretically.</p><p class="paragraph" style="text-align:left;"><i>&quot;We believe that humans alone are insufficient to close this asymmetric capacity gap. Silicon and electricity can perform a lot of analysis for pennies on the dollar and can really help plug this ever-expanding analytical gap between the analytics required to sufficiently protect the organization and the limited capacity constrained by headcount, budget, and staffing.&quot;</i> Edward Wu</p><p class="paragraph" style="text-align:left;">This isn&#39;t a vendor pitch, it&#39;s a structural observation that the CrowdStrike and IBM data this week substantiates. Alert volumes are growing 30% year-over-year, attack surfaces are expanding as cloud-native infrastructure proliferates, and the window between initial access and lateral movement has collapsed to 29 minutes. The math has changed. A human-only tier-1 process simply cannot operate at the required speed and scale.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="what-ai-can-actually-do-today-and-w"><b>What AI Can Actually Do Today And What It Can&#39;t</b></h3><p class="paragraph" style="text-align:left;">Wu is careful to distinguish between the current reality of AI-assisted attacks and the inevitable future. Today, attackers are using LLMs for the early stages of campaigns, highly personalized spear-phishing at scale, automated reconnaissance, and AI-assisted vulnerability discovery and exploit generation in the AppSec domain. Full end-to-end autonomous attack campaigns of 10 to 15 steps? Not yet. But trending there quickly.</p><p class="paragraph" style="text-align:left;"><i>&quot;We have not seen AI agents end-to-end performing a 10-step or 15-step attack campaign but we have absolutely seen a lot of cases of AI-generated, very personalized spear-phishing emails, and AI utilization in the early reconnaissance phase. And the world is trending toward autonomous end-to-end campaigns.&quot;</i> Edward Wu</p><p class="paragraph" style="text-align:left;">On the defense side, the picture is more mature. Wu reports that Drop Zone&#39;s AI SOC analyst is delivering investigation quality at or above a typical tier-1 human analyst, autonomously and at scale, across 300+ customer environments. The company has processed the equivalent of 160 years of human alert investigations through software alone. Hallucination concerns, once a legitimate objection, have proven to be largely an artifact of poor context management rather than fundamental model limitations.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="the-mssp-model-is-transforming-whet"><b>The MSSP Model Is Transforming Whether MSSPs Know It Or Not</b></h3><p class="paragraph" style="text-align:left;">One of the most practically useful threads in Wu&#39;s conversation concerns managed security service providers. The traditional MSSP model allocating fractional analyst time across dozens of clients has a structural flaw that Wu names directly: customizability. An analyst covering 50 clients cannot internalize what constitutes normal behavior in each environment. Clients consistently cite this as their primary complaint.</p><p class="paragraph" style="text-align:left;">What Wu observes at the leading edge of the MSSP market is a shift from 100% human-delivered service models to 80–90% AI-delivered outcomes, with human analysts focused on the final 10%. This is not cost-cutting, it&#39;s the only viable model at the speed and accuracy levels the threat landscape now demands. Simultaneously, some enterprises that previously outsourced tier-1 triage to MSSPs are bringing that function in-house, replacing the MSSP relationship with AI tooling for staff augmentation.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="the-human-strategy-ai-execution-mod"><b>The &#39;Human Strategy, AI Execution&#39; Model</b></h3><p class="paragraph" style="text-align:left;">Wu&#39;s clearest articulation of how this architecture works in practice centers on three components of human responsibility that AI cannot substitute for:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Scope of work:</b> Humans must define what the AI investigates, what alert types matter, and what threat hunts are in scope for the organization&#39;s risk profile.</p></li><li><p class="paragraph" style="text-align:left;"><b>Scope of authorization:</b> Humans must determine what actions the AI can take autonomously containing a host, disabling a user account, escalating an alert and under what conditions. This is a governance and liability question, not just a technical one.</p></li><li><p class="paragraph" style="text-align:left;"><b>Business context:</b> No AI system can read minds. The organization&#39;s operational knowledge which service account behaviours are normal, which integrations are expected, which IP ranges belong to trusted partners must be materialized in an accessible format.</p></li></ul><p class="paragraph" style="text-align:left;"><i>&quot;Making your context knowledge accessible to that system whether it&#39;s an AI agent like Drop Zone, or a human coworker is vitally important. We&#39;ve seen cases where using AI to generate a structured onboarding survey, then having practitioners fill it out, can bootstrap an AI agent&#39;s understanding of your environment very quickly.&quot;</i> Edward Wu</p><p class="paragraph" style="text-align:left;">This framing has direct implications for how cloud security teams should approach AI adoption in their SOC. The work of writing down your environmental context: what&#39;s normal, what matters, what the AI is authorized to do is not overhead. It is the core governance activity that makes the entire model functional. It also doubles as institutional knowledge documentation that survives analyst turnover.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="prompt-injection-as-a-soc-detection"><b>Prompt Injection as a SOC Detection Problem</b></h3><p class="paragraph" style="text-align:left;">Wu&#39;s perspective on prompt injection offers a useful reframe for security teams trying to operationalize this emerging risk. Prompt injection, he argues, is not a new detection category requiring a new toolset. It is insider threat detection applied to non-human identities.</p><p class="paragraph" style="text-align:left;">When a malicious prompt tricks a GenAI application into misusing its service credential to read 50GB of data from an internal repository, that activity shows up as an anomalous behavioural alert the same kind a behavioural analytics engine would generate for a compromised human account. The investigation question is identical. The difference is that cloud security teams may not have yet baselined their AI application service accounts with the same rigor they apply to privileged human identities.</p><p class="paragraph" style="text-align:left;">This is an under appreciated gap. As enterprises deploy AI assistants, code generation tools, and agent workflows, each operates with a service credential. Until those identities are baselined, monitored, and governed with the same discipline applied to human privileged access, they represent an uninvestigated attack surface.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>RELATED RESOURCES 🎧</b></h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://dropzone.ai/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">Drop Zone AI</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cisa.gov/artificial-intelligence?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">CISA AI Security Guidance for Critical Infrastructure</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.nist.gov/system/files/documents/2023/01/26/AI%20RMF%201.0.pdf?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">NIST AI Risk Management Framework</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://atlas.mitre.org/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">MITRE ATLAS Adversarial Threat Landscape for AI Systems</a></p></li></ul><h3 class="heading" style="text-align:left;" id="cloud-security-podcast"><b>Cloud Security Podcast</b></h3><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cloudsecuritypodcast.tv/videos?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow"><b>Cloud Security Podcast Episode with Edward Wu</b></a></p></li></ul><hr class="content_break"><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔<b> </b>If your SOC deployed an AI investigation agent tomorrow, what is the first action you would allow it to take autonomously?</p><p class="paragraph" style="text-align:left;">• Disable user account<br>• Isolate host<br>• Block token/session<br>• None — humans only<br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=the-29-minute-soc-why-ai-accelerated-attacks-are-forcing-security-teams-to-rethink-response" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=82e50951-b028-4e3a-a147-c8d62105cdc9&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>🚨 AI Agents Are Now the Attack Surface &amp; Building an AI Security Blueprint Before It&#39;s Too Late</title>
  <description>This week&#39;s brief covers the Cline npm supply chain attack weaponising prompt injection against CI/CD pipelines, BeyondTrust CVE-2026-1731 now confirmed in active ransomware campaigns across 11,000+ exposed instances. Alongside the Cisco State of AI Security 2026 report and Microsoft&#39;s new Security Dashboard for AI, TrendAI&#39;s Shannon Murphy outlines a pragmatic AI security blueprint centred on data governance, agent identity, and cross-functional ownership for organisations at every stage of AI adoption. Key themes: agentic AI security, AI asset inventory, DSPM, supply chain risk, and enterprise AI governance frameworks.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9bb33b40-97ba-4083-8391-6b9f2e6fa481/Screenshot_2026-02-25_at_10.02.49_PM.png" length="2171072" type="image/png"/>
  <link>https://www.cloudsecuritynewsletter.com/p/ai-agents-security-blueprint</link>
  <guid isPermaLink="true">https://www.cloudsecuritynewsletter.com/p/ai-agents-security-blueprint</guid>
  <pubDate>Wed, 25 Feb 2026 22:58:22 +0000</pubDate>
  <atom:published>2026-02-25T22:58:22Z</atom:published>
    <dc:creator>Ashish Rajan</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><h2 class="heading" style="text-align:left;" id="hello-from-the-cloudverse"><span style="background-color:#28EEDA;"><b>Hello from the Cloud-verse!</b></span></h2><p class="paragraph" style="text-align:left;">This week’s Cloud Security Newsletter topic<b>: The AI Security Blueprint: A Maturity-Staged Framework for Enterprise AI Governance </b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" rel="noopener noreferrer nofollow">(continue reading)</a> </p><div class="button" style="text-align:center;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="https://www.aisecuritypodcast.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late"><span class="button__text" style=""> This issue is sponsored by AI Security Podcast </span></a></div><hr class="content_break"><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos/why-ai-infrastructure-is-harder-to-secure-than-cloud?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9bb33b40-97ba-4083-8391-6b9f2e6fa481/Screenshot_2026-02-25_at_10.02.49_PM.png?t=1772057144"/></a><div class="image__source"><span class="image__source_text"><p><i>This image was generated by AI. It&#39;s still experimental, so it might not be a perfect match!</i></p></span></div></div><p class="paragraph" style="text-align:left;"><b>Incase, this is your 1st Cloud Security Newsletter! You are in good company! </b><br>You are reading this issue along with your friends and colleagues from companies like <i>Netflix</i>, Citi, <i>JP Morgan, Linkedin, Reddit, Github, Gitlab, CapitalOne, Robinhood, HSBC, British Airways, Airbnb, Block, Booking Inc & more</i> who subscribe to this newsletter, who like you want to learn what’s new with Cloud Security each week from their industry peers like many others who listen to <a class="link" href="https://open.spotify.com/show/6LZgeh4GecRYPc0WrwMB4I?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a> & <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> every week.</p><hr class="content_break"><p class="paragraph" style="text-align:left;">Welcome to this week’s Cloud Security Newsletter</p><p class="paragraph" style="text-align:left;">If this week had a single unifying signal it was this: the AI systems your organisation is deploying faster than ever are becoming the attack surface. From a weaponised npm package silently installing an autonomous AI agent on developer machines, to a Russian nation-state actor using legitimate SaaS webhooks to exfiltrate data without touching a single CVE, to ransomware operators now confirmed exploiting a CVSS 9.9 pre-auth RCE in one of the enterprise&#39;s most privileged remote access tools   the threat actors are not waiting for your AI governance programme to catch up.</p><p class="paragraph" style="text-align:left;">This week&#39;s guest, Shannon Murphy, Senior Researcher and AI Security Strategist at TrendAI, has spent the last five years working directly with CISOs, CTOs, and cloud security architects on exactly this problem. In a wide-ranging conversation with Cloud Security Podcast host Ashish Rajan, Shannon lays out a clear-eyed AI security blueprint   grounded not in theory but in the patterns she observes across enterprise field engagements   covering data governance, agent identity, shift-left for AI, and how to build a cross-functional governance committee that actually holds.</p><p class="paragraph" style="text-align:left;">We also cover the Cisco State of AI Security 2026 report revealing that 71% of enterprises are deploying agentic AI they cannot secure, and Microsoft&#39;s new Security Dashboard for AI now in public preview. The news this week is not background noise, it is a live demonstration of every risk Shannon describes.<i>[</i><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/how-to-build-an-ai-security-program-from-scratch?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">Listen to the episode</a><i>]</i></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="two-actions-to-take-this-week">🎯 Two Actions to Take This Week</h2><p class="paragraph" style="text-align:left;">👉 <b>Patch or isolate BeyondTrust immediately</b><br>👉 <b>Audit every AI agent in CI/CD and restrict token scope</b></p><p class="paragraph" style="text-align:left;">The AI readiness gap is no longer theoretical.<br>It’s operational risk.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="tldr-for-busy-readers">📰 TL;DR for Busy Readers</h2><ul><li><p class="paragraph" style="text-align:left;"><b>BeyondTrust CVE-2026-1731 (CVSS 9.9) is confirmed</b><br>Patch to RS 25.3.2 / PRA 25.1.1 immediately or isolate from internet exposure.</p></li><li><p class="paragraph" style="text-align:left;"><b>Cline npm supply chain attack </b></p><ul><li><p class="paragraph" style="text-align:left;">Prompt injection used to steal publish credentials.<br>→ Enforce 48-hour npm version hold.<br>→ Audit AI agent permissions in CI/CD.</p></li></ul></li><li><p class="paragraph" style="text-align:left;"><b>Cisco&#39;s 2026 AI Security report</b>: </p><ul><li><p class="paragraph" style="text-align:left;">83% deploying agentic AI. Only 29% ready.<br>→ Treat the readiness gap as a funded backlog item.</p></li></ul></li><li><p class="paragraph" style="text-align:left;"><b>Microsoft&#39;s Security Dashboard for AI (public preview)</b> </p><ul><li><p class="paragraph" style="text-align:left;">First Unified AI asset inventory across Defender, Entra, Purview.<br>→ Enable this week and export your first AI asset register.</p></li></ul></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="this-weeks-security-news">📰 <b>THIS WEEK&#39;S TOP 4 SECURITY HEADLINES</b></h2><p class="paragraph" style="text-align:left;">Each story includes <b>why it matters</b> and <b>what to do next</b> — no vendor fluff.</p><h3 class="heading" style="text-align:left;" id="1-beyond-trust-cve-20261731-cvss-99"><b>1. </b><b>BeyondTrust CVE-2026-1731 (CVSS 9.9) </b></h3><p class="paragraph" style="text-align:left;"><b>What Happened: </b>What began as a critical disclosure on February 6 escalated this week into confirmed ransomware exploitation across multiple sectors. BeyondTrust&#39;s own telemetry indicates active exploitation started January 31 a full week before public disclosure   making CVE-2026-1731 a zero-day in retrospect. The flaw is an OS command injection vulnerability in the thin-scc-wrapper component of BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA), exposed via WebSocket and exploitable without authentication. A public PoC dropped February 10; GreyNoise observed mass scanning within 24 hours. CISA added it to the KEV catalog on February 13 with a 72-hour remediation mandate for federal agencies and updated the KEV entry on February 19 to activate the ransomware exploitation flag.</p><p class="paragraph" style="text-align:left;">Palo Alto Networks Unit 42 confirmed active exploitation this week across finance, legal, healthcare, higher education, and retail in the US, France, Germany, Australia, and Canada. Observed post-exploitation activity includes VShell and SparkRAT deployment, web shell installation, PostgreSQL database exfiltration, and lateral movement.</p><p class="paragraph" style="text-align:left;"><b>Why it matters to you:</b> BeyondTrust RS and PRA are privileged access tools by design they carry SYSTEM-level authority over every managed endpoint. An unauthenticated RCE on these appliances is effectively a master key to your entire managed estate. With 11,000+ internet-exposed instances confirmed and ransomware actors now actively pre-positioning, treat this as an active incident response situation, not a patch management queue item.</p><p class="paragraph" style="text-align:left;">👉 <a class="link" href="https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">Download Unit 42 IOCs and validate exposure this week.</a></p><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://thehackernews.com/2026/02/infostealer-steals-openclaw-ai-agent.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow"> </a><a class="link" href="https://www.bleepingcomputer.com/news/security/cisa-beyondtrust-rce-flaw-now-exploited-in-ransomware-attacks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">BleepingComputer</a> · <a class="link" href="https://www.securityweek.com/beyondtrust-vulnerability-exploited-in-ransomware-attacks/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">SecurityWeek</a> · <a class="link" href="https://www.scworld.com/news/cisa-update-beyondtrust-rce-exploited-in-ransomware-attacks?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">SC Media</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-cline-cli-npm-supply-chain-attack"><b>2. </b><b>Cline CLI npm Supply Chain Attack Prompt Injection Weaponised to Steal Publish Credentials and Deploy OpenClaw</b></h3><p class="paragraph" style="text-align:left;"><b>What happened:</b> On February 17, a threat actor used a stolen npm publish token to release cline@2.3.0   a poisoned update to Cline CLI, a popular AI-powered coding assistant with approximately 90,000 weekly npm downloads. A single postinstall script silently ran npm install -g openclaw@latest on any machine installing the package. The malicious version was live for approximately eight hours. StepSecurity estimated roughly 4,000 downloads of the compromised version.</p><p class="paragraph" style="text-align:left;">What makes this attack structurally significant is the initial access vector: security researcher Adnan Khan had disclosed on February 9 that Cline&#39;s Claude-powered GitHub issue-triage workflow was vulnerable to prompt injection. A crafted GitHub issue could cause the AI agent to execute a malicious payload, poison the GitHub Actions cache, and pivot to steal the npm publish token. Cline patched the triage workflow within 30 minutes   but rotated the wrong token. Eight days later, the still-valid token was used to publish the malicious package. The payload, OpenClaw, is a legitimate open-source AI agent with broad system access (full disk, terminal, persistent WebSocket daemon) and a known critical CVE (CVE-2026-25253, CVSS 8.8) in versions prior to 2026.1.29 allowing unauthenticated operator access.</p><p class="paragraph" style="text-align:left;"><b>Why it matters to you:</b> This attack introduces a materially new threat model: prompt injection against AI agents in CI/CD pipelines as an initial access technique for credential theft. The entry point was not a phishing email or a code vulnerability, it was a GitHub issue. Any organisation using LLM-powered bots to automate repository triage, PR review, or release workflows with access to production secrets is now a viable target for this attack pattern. This connects directly to Shannon Murphy&#39;s warning that agentic AI is creating new blind spots that existing DLP and AppSec tooling cannot cover.</p><p class="paragraph" style="text-align:left;">👉 If your AI agent can push code, it must be governed like a privileged identity.</p><p class="paragraph" style="text-align:left;"><b>Sources:</b> <a class="link" href="https://thehackernews.com/2026/02/cline-cli-230-supply-chain-attack.html?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">The Hacker News</a> · <a class="link" href="https://www.darkreading.com/application-security/supply-chain-attack-openclaw-cline-users?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">Dark Reading</a> · <a class="link" href="https://snyk.io/blog/cline-supply-chain-attack-prompt-injection-github-actions/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">Snyk Deep-Dive</a> · <a class="link" href="https://www.stepsecurity.io/blog/cline-supply-chain-attack-detected-cline-2-3-0-silently-installs-openclaw?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">StepSecurity Detection Report</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-cisco-state-of-ai-security-2026-7"><b>3. </b><b>Cisco &quot;State of AI Security 2026&quot;- 71% of Enterprises Are Deploying Agentic AI They Cannot Secure</b></h3><p class="paragraph" style="text-align:left;"><b>What happened:</b> Cisco&#39;s AI Threat Intelligence & Security Research team released its flagship annual report on February 19, with Help Net Security publishing a practitioner-focused analysis on February 23. The report documents three compounding risks: rapid agentic AI deployment outpacing security readiness; a fragile AI supply chain with documented tool poisoning and MCP ecosystem vulnerabilities; and adversarial techniques   particularly prompt injection and jailbreaks   maturing from research concepts into documented real-world exploits. Key statistic: 83% of surveyed organisations plan to deploy agentic AI into business functions; only 29% feel ready to secure those deployments.</p><p class="paragraph" style="text-align:left;">Documented incidents include a GitHub MCP server compromise in which a malicious issue injected hidden instructions that hijacked an agent and exfiltrated private repository data. The report also covers a fake npm package mimicking an email integration that silently forwarded outbound messages to attacker infrastructure   a pattern strikingly consistent with the Cline incident reported in the same week. Cisco&#39;s researchers demonstrated that open-weight models remain susceptible to multi-turn jailbreaks at significantly higher success rates than single-turn attacks.</p><p class="paragraph" style="text-align:left;"><b>Why it matters to you:</b> The report crystallises what security leaders are observing operationally: AI agents are being granted authority to execute tasks, query databases, modify code, and interact with external services   often without the controls that would be non-negotiable for a human performing the same actions. The agent-to-agent trust problem is particularly acute. For cloud security teams, the MCP attack surface deserves immediate attention; Cisco has released open-source scanners for MCP, A2A, and agentic skill files as companion tooling. The 71% readiness gap is not a statistic to present to leadership   it is a project backlog. This data is the empirical foundation for every strategic recommendation Shannon Murphy makes in this week&#39;s feature.</p><p class="paragraph" style="text-align:left;">👉 Use this data in your next board update and tie it to funded remediation.</p><p class="paragraph" style="text-align:left;"><b>Sources:</b> <a class="link" href="https://blogs.cisco.com/ai/cisco-state-of-ai-security-2026-report?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">Cisco AI Security Blog (Primary)</a> · <a class="link" href="https://www.helpnetsecurity.com/2026/02/23/ai-agent-security-risks-enterprise/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">Help Net Security</a> · <a class="link" href="https://learn-cloudsecurity.cisco.com/2026-state-of-ai-security-report?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">Cisco Report</a></p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-microsoft-launches-security-dashb"><b>4. </b><b>Microsoft Launches Security Dashboard for AI in Public Preview - Unified CISO Visibility Across the Enterprise AI Estate</b></h3><p class="paragraph" style="text-align:left;"><b>What happened:</b><b> </b>Microsoft released the Security Dashboard for AI into public preview on February 16, available across enterprise tenants with eligible Defender, Entra, and Purview subscriptions at no additional cost. Accessible at ai. security. microsoft. com, the dashboard aggregates real-time risk signals from all three platforms into a single governance interface designed for CISOs and AI risk leaders. Core capabilities include: a comprehensive AI asset inventory spanning Microsoft 365 Copilot agents, Copilot Studio agents, Azure AI Foundry deployments, MCP servers, and third-party AI applications including OpenAI, Google Gemini, and ChatGPT tenant integrations; an AI risk scorecard with posture drift tracking; correlated risk views linking Purview data sensitivity signals with Entra identity context and Defender threat alerts; and delegated remediation actions. Security Copilot is embedded for natural-language investigation.</p><p class="paragraph" style="text-align:left;"><b>Why it matters to you:</b> This announcement directly addresses the shadow AI problem Shannon Murphy identifies as the critical first milestone in any AI security programme: you cannot govern what you cannot see. The dashboard&#39;s AI inventory discovery function is the operationalisation of that principle   and for organisations already invested in the Microsoft security stack, it is immediately actionable. The dashboard also directly addresses the data leakage risk Cisco independently flags in this week&#39;s AI Security report: oversharing detection in Purview integration targets agents with overly broad data permissions, one of the most prevalent enterprise AI exposure patterns observed in 2025. For organisations not on the Microsoft stack, this announcement raises the competitive bar for what a mature CNAPP or CSPM vendor must now offer in AI security posture management.</p><p class="paragraph" style="text-align:left;">Enable it. Export inventory. Start governance.</p><p class="paragraph" style="text-align:left;"><b>Sources:</b><a class="link" href="https://www.bleepingcomputer.com/news/microsoft/microsoft-says-bug-causes-copilot-to-summarize-confidential-emails/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow"> </a><a class="link" href="https://techcommunity.microsoft.com/blog/microsoft-security-blog/introducing-security-dashboard-for-ai-now-in-public-preview/4494637?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">Microsoft TechCommunity (Primary)</a> · <a class="link" href="https://www.helpnetsecurity.com/2026/02/16/microsoft-security-dashboard-for-ai-tool/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">Help Net Security</a> · <a class="link" href="https://learn.microsoft.com/en-us/security/security-for-ai/security-dashboard-for-ai?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">Microsoft Learn Docs</a></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="cloud-security-topic-of-the-week">🎯 Cloud Security Topic of the Week: </h2><h3 class="heading" style="text-align:left;" id="the-ai-security-blueprint-a-maturit"><b>The AI Security Blueprint: A Maturity-Staged Framework for Enterprise AI Governance</b></h3><p class="paragraph" style="text-align:left;">One of the clearest themes emerging from Shannon Murphy&#39;s conversation is that most organisations are attempting to govern AI deployments using frameworks and tool stacks designed for a deterministic, pre-AI world   and that gap is not theoretical. It is showing up in the Cisco report&#39;s 71% readiness gap, in the Cline supply chain attack, and in the data leakage scenarios Shannon describes from real enterprise field engagements.</p><p class="paragraph" style="text-align:left;">The AI security blueprint she outlines is structured around three maturity stages   adopter, builder, and scaler   each with distinct risk profiles and corresponding security requirements. What makes this framework practically valuable is that Shannon explicitly states the underlying philosophy remains consistent across all three stages: discover, assess, prioritise, mitigate. The level of security capability scales with the attack surface; the methodology does not change.</p><p class="paragraph" style="text-align:left;"><b>Stage-1 - Adopter:</b> Organisations in productivity-gain mode face their highest risk from data governance failures and over-permissioned AI access. </p><p class="paragraph" style="text-align:left;">Primary Risk: Shadow AI & Data Exposure<br>Objective: Real-time AI asset visibility</p><p class="paragraph" style="text-align:left;">Deliverable:<br>Continuously updated AI inventory not a spreadsheet.</p><p class="paragraph" style="text-align:left;"><b>Stage-2 - Builder:</b> Development teams building internal AI tools or going to market with AI-powered products face all of the adopter risks plus the application security and supply chain risks illustrated by the Cline attack this week. </p><p class="paragraph" style="text-align:left;">Primary Risk: Supply chain & application security<br>Add:</p><ul><li><p class="paragraph" style="text-align:left;">AI-specific vulnerability scanning</p></li><li><p class="paragraph" style="text-align:left;">Container security</p></li><li><p class="paragraph" style="text-align:left;">Runtime monitoring</p></li><li><p class="paragraph" style="text-align:left;">Agent identity governance</p></li></ul><p class="paragraph" style="text-align:left;">Shift-left is necessary.<br>Runtime monitoring is mandatory.</p><p class="paragraph" style="text-align:left;"><b>Stage-3-  Scaler</b>: Organisations investing in AI factories and enterprise-wide automation are operating in what Shannon describes as an inferencing security paradigm: continuous monitoring of live AI systems for behavioural drift, adversarial manipulation, and agent-to-agent trust failures. </p><p class="paragraph" style="text-align:left;">Primary Risk: Inferencing Security & Agent-to-Agent Trust<br>Objective:Treat agents as identities:</p><ul><li><p class="paragraph" style="text-align:left;">Scoped permissions</p></li><li><p class="paragraph" style="text-align:left;">Short-lived credentials</p></li><li><p class="paragraph" style="text-align:left;">Access governance</p></li><li><p class="paragraph" style="text-align:left;">Continuous behavioural monitoring</p></li></ul><p class="paragraph" style="text-align:left;">DSPM becomes foundational here.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="featured-experts-this-week"><b>Featured Experts This Week </b>🎤</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/greatgtm/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow"><b>Shannon Murphy</b></a><b>- </b> Senior Researcher & AI Security Strategist | TrendAI</p></li><li><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/in/ashishrajan/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">Ashish Rajan</a></b> - CISO | Co-Host <a class="link" href="https://open.spotify.com/show/3nV4eijfzdHKIvDOaycVII?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a> , Host of <a class="link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Podcast</a></p></li></ul><h2 class="heading" style="text-align:left;" id="definitions-and-core-concepts"><b>Definitions and Core Concepts 📚</b></h2><p class="paragraph" style="text-align:left;">Before diving into our insights, let&#39;s clarify some key terms:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Agentic AI</b><br>Autonomous systems executing multi-step tasks via tool calls.</p></li><li><p class="paragraph" style="text-align:left;"><b>Prompt Injection</b><br>Malicious instructions embedded in data processed by AI agents.</p></li><li><p class="paragraph" style="text-align:left;"><b>Model Context Protocol (MCP)</b><br>Standard defining how agents discover and call tools.</p><p class="paragraph" style="text-align:left;"></p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:center;">This week&#39;s issue is sponsored by <a class="link" href="https://www.aisecuritypodcast.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow"><b>AI Security Podcast</b></a></p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="our-insights-from-this-practitioner">💡<b>Our Insights from this Practitioner 🔍</b></h2><h3 class="heading" style="text-align:left;" id="how-to-build-an-ai-security-program"><b>How to Build an AI Security Program from Scratch.</b><b> (</b><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/how-to-build-an-ai-security-program-from-scratch?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow"><b>Full Episode here</b></a><b>)</b></h3><hr class="content_break"><h3 class="heading" style="text-align:left;" id="1-why-95-of-ai-projects-fail-and-wh"><span style="color:rgb(67, 67, 67);"><b>1. Why 95% of AI Projects Fail   and What Security Owns in the Answer</b></span></h3><p class="paragraph" style="text-align:left;">Shannon opens with a striking data point from an MIT study that circulated widely in the security community: 95% of AI projects are failing. Her diagnosis is direct:</p><p class="paragraph" style="text-align:left;">&quot;Any security leader who attempts to drive an AI governance strategy in a silo will fail. 95% of AI projects are failing because we&#39;re not having all the stakeholders at the table.&quot;   Shannon Murphy, TrendAI</p><p class="paragraph" style="text-align:left;">The failure pattern she describes is recognisable to anyone who has watched a well-intentioned AI governance initiative stall: business units move fast under top-down pressure to adopt AI, security is brought in late or not at all, and the resulting programme has policy gaps that surface as incidents. The structural fix she advocates is a cross-functional governance committee   legal, compliance, engineering, and security   with board-level sponsorship that distributes risk ownership rather than concentrating it in the security team alone.</p><p class="paragraph" style="text-align:left;">For cloud security leaders, this is both a risk management and a career positioning insight. Shannon notes that AI is creating the conditions for security to have a genuine seat at strategic decision-making tables for the first time   because business leaders now understand they have knowledge gaps that require security intelligence to navigate. The opportunity to shift from reactive incident responder to proactive governance partner is real, but it requires showing up with scenario-based risk framing (&quot;here is what a data exfiltration incident looks like in our AI environment and here is what it costs&quot;) rather than technical jargon.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="2-your-existing-stack-has-a-blind-s"><span style="color:rgb(67, 67, 67);"><b>2. Your Existing Stack Has a Blind Spot the Size of Your AI Deployment</b></span></h3><p class="paragraph" style="text-align:left;">One of the most practically important points Shannon makes concerns the false sense of coverage that a mature security stack can create when AI enters the picture:</p><p class="paragraph" style="text-align:left;">&quot;AI is embedded in every single SaaS application and every single tool that your team is using. You need to know what people are using, you need to know what content is going into that experience and what content is going out.&quot;   Shannon Murphy, TrendAI</p><p class="paragraph" style="text-align:left;">She illustrates the blind spot with a deceptively simple example: an employee asks their corporate AI copilot for a colleague&#39;s salary. Traditional DLP, tuned to flag sensitive data leaving via email or file transfer, has no visibility into this interaction. The data exposure happens entirely within what the organisation considers a sanctioned, secured application   and no alert is generated. Scale this to thousands of employees across dozens of AI-enabled SaaS tools, and the aggregate data risk is substantial.</p><p class="paragraph" style="text-align:left;">Her prescription is not to abandon the existing stack but to recognise it as table stakes that now requires an AI-specific visibility layer on top. The key principle: context is everything. Risk that exists in isolation   an AI query here, a model access there   becomes actionable and prioritisable only when it can be seen in relation to the identity making the request, the data being accessed, and the threat signals already in your environment. This is precisely what Microsoft&#39;s Security Dashboard for AI announced this week attempts to operationalise.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="3-the-three-milestone-ai-security-r"><span style="color:rgb(67, 67, 67);"><b>3. The Three-Milestone AI Security Roadma</b></span><span style="color:rgb(67, 67, 67);">p</span></h3><p class="paragraph" style="text-align:left;">Shannon provides the clearest practical roadmap in the conversation for how a security leader should sequence their AI security programme. It maps directly to the three building blocks her blueprint prioritises:</p><p class="paragraph" style="text-align:left;">Milestone 1   Real-Time AI Asset Visibility: &quot;Shadow AI is absolutely massive and you need to be able to wrap your arms around it.&quot; This is the non-negotiable foundation. Shannon is explicit that a static inventory is insufficient: &quot;What we have today in place is not what we have tomorrow   literally tomorrow.&quot; The first deliverable is a continuously updated, real-time inventory of every AI application, agent, model, and integration in your environment. Tools exist today to make this tractable   the question is whether the programme has been prioritised.</p><p class="paragraph" style="text-align:left;">Milestone 2   Identity and Access Governance for AI: Once you have inventory, the next question is access. Who   and what   gets access to which data and tools? Shannon&#39;s recommendation to treat agents as identities is strategically important: &quot;Maybe we wanna start treating them a little bit like identities. Taking an identity risk management approach to those agents.&quot; The tooling for identity governance is mature; applying it systematically to AI agents requires discipline and the right agent inventory to work from.</p><p class="paragraph" style="text-align:left;">Milestone 3   Data Governance and Provenance: Shannon identifies this as &quot;your biggest project&quot; and the one most security teams are furthest behind on. DSPM   understanding where your data lives, who has access to it in AI contexts, and what happens to it during model fine-tuning or inference   is the pillar she describes as &quot;the central bingo card conversation in every CISO engagement over the last two years.&quot; For organisations fine-tuning open-weight models on proprietary data, this is particularly acute: the data used for fine-tuning must be governed with the same rigour as production data.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="4-shift-left-for-ai-more-critical-t"><span style="color:rgb(67, 67, 67);"><b>4. Shift Left for AI - More Critical Than Ever, and More Incomplete</b></span></h3><p class="paragraph" style="text-align:left;">Ashish Rajan asks Shannon directly whether shift-left DevSecOps is still relevant in an AI-first world. Her answer is nuanced and worth the full framing:</p><p class="paragraph" style="text-align:left;">&quot;Shift left is more needed than ever before. But it is what is going to keep you out of trouble from a quality perspective   and when we layer in things like an AI scanner for vulnerability, that&#39;s what&#39;s going to keep you out of trouble even when we&#39;re live in runtime.&quot;   Shannon Murphy, TrendAI</p><p class="paragraph" style="text-align:left;">The key addition she makes is that shift-left for AI does not end at the pipeline gate. Unlike traditional deterministic software, AI applications continue to change after deployment through model drift, fine-tuning updates, and the inherent non-determinism of LLM outputs. This means that runtime monitoring   for hallucination, for adversarial prompt injection, for novel zero-day vulnerabilities in live inference stacks   is a distinct and mandatory complement to pre-deployment scanning. The Cline attack this week is a live demonstration: a supply chain compromise in the pre-deployment phase that delivered a runtime-persistent agent with ongoing system access. Both vectors required coverage; neither alone was sufficient.</p><hr class="content_break"><h3 class="heading" style="text-align:left;" id="5-the-model-card-as-enterprise-trus"><span style="color:rgb(67, 67, 67);"><b>5. The Model Card as Enterprise Trust Infrastructure</b></span></h3><p class="paragraph" style="text-align:left;">Shannon surfaces an emerging practice that deserves broader adoption among organisations building AI-powered products: the model card used as customer-facing transparency documentation.</p><p class="paragraph" style="text-align:left;">&quot;Some organizations are doing something really great using a model card that I call a license to thrive   where they show here are the models we use, here are the safety precautions we take, this is how we use a Zero Trust approach to protect your data.&quot; She expects standardisation of this practice to accelerate through 2026 as regulated industries (healthcare, financial services) begin demanding it from AI-powered vendors as a due diligence requirement.</p><p class="paragraph" style="text-align:left;">For security leaders at organisations building or evaluating AI-powered products, the model card framework serves a dual purpose: externally, it builds customer trust without disclosing IP; internally, it creates the documentation discipline that forces clarity about which models are in production, what data they have been trained on, and what controls are in place. That internal clarity is also the foundation of a defensible DSPM programme.</p><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>RELATED RESOURCES 🎧</b></h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.nist.gov/artificial-intelligence/ai-risk-management-framework?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">NIST AI Risk Management Framework (AI RMF)</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://owasp.org/www-project-top-10-for-large-language-model-applications/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">OWASP Top 10 for LLM Applications</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://atlas.mitre.org/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">MITRE ATLAS   Adversarial Threat Landscape for AI Systems</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.trendmicro.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">TrendAI Security Blueprint Whitepaper</a>   Framework for adopters, builders, and scalers</p></li></ul><h3 class="heading" style="text-align:left;" id="cloud-security-podcast"><b>Cloud Security Podcast</b></h3><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.cloudsecuritypodcast.tv/videos/how-to-build-an-ai-security-program-from-scratch?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow"><b>Cloud Security Podcast Episode with Shannon Murphy</b></a></p></li></ul><hr class="content_break"><h2 class="heading" style="text-align:left;" id="related-podcast-episodes"><b>Related Podcast Episodes 🎧</b></h2><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/videos/how-to-build-an-ai-security-program-from-scratch?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8eef9378-33a0-4881-b30a-4b54b726e9c7/S07EP00_Shannon_Murphy_.jpg?t=1772057210"/></a></div><h3 class="heading" style="text-align:left;" id="question-for-you-reply-to-this-emai">Question for you? (Reply to this email)</h3><p class="paragraph" style="text-align:left;">🤔<b> </b>If your AI agent can read GitHub issues and push production code… Does it have more access than your junior engineer?</p><p class="paragraph" style="text-align:left;">Because in many enterprises — it does.<br></p><p class="paragraph" style="text-align:left;">Next week, we&#39;ll explore another critical aspect of cloud security. Stay tuned!</p><hr class="content_break"><p class="paragraph" style="text-align:left;">📬 Want weekly expert takes on AI & Cloud Security? [<a class="link" href="https://www.cloudsecuritynewsletter.com/subscribe?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">Subscribe here</a>]”</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><span style="color:rgb(238, 40, 60);"><b><a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">We would love to hear from you</a></b></span>📢 for a feature or topic request or if you would like to sponsor an edition of Cloud Security Newsletter. </p><p class="paragraph" style="text-align:left;">Thank you for continuing to subscribe and Welcome to the new members in tis newsletter community💙</p><p class="paragraph" style="text-align:start;">Peace!</p><p class="paragraph" style="text-align:start;"><a class="link" href="https://www.linkedin.com/in/shilpi-bhattacharjee/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">Shilpi Bhattacharjee</a></p><div class="image"><a class="image__link" href="https://www.cloudsecuritypodcast.tv/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dc094a1c-678a-43e0-adc9-1bee6c3499e2/CSP_Logo_Blue_ScreenRes_3000x3000_v2.jpg"/></a></div><div class="button" style="text-align:left;"><a target="_blank" rel="noopener nofollow noreferrer" class="button__link" style="" href="{{rp_referral_hub_url}}"><span class="button__text" style=""> Share the newsletter </span></a></div><p class="paragraph" style="text-align:left;">Was this forwarded to you? You can <a class="link" href="https://www.cloudsecuritynewsletter.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">Sign up here</a>, to join our growing readership.</p><p class="paragraph" style="text-align:left;">Want to <b>sponsor</b> the next newsletter edition! <a class="link" href="mailto:info@cloudsecuritypodcast.tv" target="_blank" rel="noopener noreferrer nofollow">Lets make it happen </a></p><p class="paragraph" style="text-align:left;">Have you joined our FREE <b>Monthly</b> <a class="link" href="https://www.cloudsecuritybootcamp.com/?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">Cloud Security Bootcamp</a> yet?</p><p class="paragraph" style="text-align:left;">checkout our <b>sister podcast</b> <a class="link" href="https://www.youtube.com/@AISecurityPodcast?utm_source=www.cloudsecuritynewsletter.com&utm_medium=newsletter&utm_campaign=ai-agents-are-now-the-attack-surface-building-an-ai-security-blueprint-before-it-s-too-late" target="_blank" rel="noopener noreferrer nofollow">AI Security Podcast</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=50be88b7-44ea-43c7-a0b4-048b4df0b860&utm_medium=post_rss&utm_source=cloud_security_newsletter">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

  </channel>
</rss>
