LogoCloud Security Newsletter
Authors
Login
Subscribe
LogoCloud Security Newsletter
Gallery

Cloud Security Newsletter

Byte-sized security wisdom from the best Leaders and Practitioners in Cybersecurity to power up ☕️ your security skills in Cloud and Emerging Tech!

Written by

Ashish Rajan

Connect

Archive

🚨 100% Detection Coverage. Would You Still Miss the Attacker?

Sep 9, 2026

•

17 min read

🚨 100% Detection Coverage. Would You Still Miss the Attacker?

A fourteen-hour registry compromise harvested cloud API keys from developer workspaces. A CVSS 10.0 pre-auth RCE in N-able N-central is under active exploitation. And NSA, CISA and the FBI are warning about Chinese extraction of US frontier AI models. Nicole Beckwith, Senior Director of Security Engineering and Operations at Cribl, explains why MITRE ATT&CK coverage no longer means you'll catch the attacker, and what she built instead.

Ashish Rajan
Ashish Rajan
🚨Standard Chartered CISO's Approach to Designing Judgment Out of Security

Sep 2, 2026

•

19 min read

🚨Standard Chartered CISO's Approach to Designing Judgment Out of Security

JFrog Artifactory minted admin tokens on default configs three days after the patch, PaperCut's first emergency fix was bypassed within a day, and $600,000 in AI model credits went out on a stolen key nobody noticed for three weeks. Eight stories this week, and almost every one turned on a credential already sitting somewhere reachable. Cezary Piekarski, Group CISO at Standard Chartered, on why prompt filtering is repeating the buffer overflow mistake and what survives at machine scale instead.

Ashish Rajan
Ashish Rajan
🚨 Talos Catches Agentic AI Inside Real Intrusions: Damien Lewke on Why Hunt First Beats Alert Triage

Aug 26, 2026

•

13 min read

🚨 Talos Catches Agentic AI Inside Real Intrusions: Damien Lewke on Why Hunt First Beats Alert Triage

Cisco Talos documented a Chinese-speaking threat actor using agentic AI across reconnaissance, exploitation, and persistence the same week CISA issued 72-hour patch deadlines for Oracle WebLogic and Gitea flaws under active attack. Damien Lewke, founder and CEO of Nebulock, argues the defensive answer is a hunt-first methodology: continuous, AI-assisted threat hunting over endpoint, identity, and cloud telemetry instead of alert triage. This edition covers machine-speed exploitation, MFA bypass at scale, shadow AI hunting, and how to detect AI agents by their behavioral tempo.

Ashish Rajan
Ashish Rajan
🚨 These Agents Were Never Onboarded: Who’s Controlling Them?

Aug 19, 2026

•

16 min read

🚨 These Agents Were Never Onboarded: Who’s Controlling Them?

Attackers spent this week working the layer that manages everything else — an MLflow tracking server reached by SSRF to pull instance credentials, a vCenter syslog parser turned into remote code execution, a Trivy scanner hijacked inside a build pipeline. Michael Leland of Island joins Ashish Rajan to explain why the agentic control plane forms in an enterprise whether or not anyone designs it, and what a customer assessment that found 243 AI tools where the team expected eight says about the visibility gap underneath all of it.

Ashish Rajan
Ashish Rajan
🚨 Exploited Before the Patch Existed: How Adobe Uses AI Agents to Virtual-Patch CVEs in Minutes

Aug 12, 2026

•

16 min read

🚨 Exploited Before the Patch Existed: How Adobe Uses AI Agents to Virtual-Patch CVEs in Minutes

This week's edition covers a heavy patch load a Cisco ASA/FTD zero-day with a three-day KEV deadline, a CVSS 10.0 Metabase flaw exploited before disclosure, and 400-plus CVEs on August Patch Tuesday and pairs it with Ammar Alim, who leads a product security engineering function at Adobe, on building an agentic pipeline that generates and deploys WAF virtual patches in minutes.

Ashish Rajan
Ashish Rajan
🚨 OpenAI's Models Escaped Through JFrog Artifactory: What a 25-Minute Exploit Window Does to Your Org Chart!

Jul 29, 2026

•

19 min read

🚨 OpenAI's Models Escaped Through JFrog Artifactory: What a 25-Minute Exploit Window Does to Your Org Chart!

JFrog confirmed this week that the OpenAI models which breached Hugging Face got out of their sealed test environment through zero-days in self-hosted Artifactory the package proxy that existed to be the enclave's only safe path outward. Clop is emptying PTC Windchill instances, Arista shipped a CVSS 10.0 fix for an SD-WAN orchestrator already under attack, and GitHub and PyPI both responded to the software supply chain with timers rather than scanners. Sarit Tager, who leads Cortex Cloud product management at Palo Alto Networks, argues the discovery-to-exploit window is now sometimes 25 minutes, and that no organization can cover that window with cloud security and application security operating as separate functions.

Ashish Rajan
Ashish Rajan
🚨 An AI Agent Breached Hugging Face On Its Own: Turn an AI Model's Own Guardrails Into a Trap

Jul 22, 2026

•

13 min read

🚨 An AI Agent Breached Hugging Face On Its Own: Turn an AI Model's Own Guardrails Into a Trap

A weekend intrusion at Hugging Face was run end to end by an autonomous AI agent and OpenAI has confirmed the agents were its own benchmark models that escaped a test sandbox. This week's brief tracks the AI stack as both attacker and target, and Andy Smith of Tracebit explains why deception is the control best suited to catch an agent including a lab result where a single planted secret dropped an attacking model's success rate from 93% to zero.

Ashish Rajan
Ashish Rajan
🚨 ADFS Zero-Day Exploited as Microsoft Ships a Record Patch Tuesday: The 40% "Dark Matter" in Every Asset Inventory

Jul 17, 2026

•

14 min read

🚨 ADFS Zero-Day Exploited as Microsoft Ships a Record Patch Tuesday: The 40% "Dark Matter" in Every Asset Inventory

This week's news covers an actively exploited ADFS zero-day that reaches token-signing keys, two SonicWall SMA1000 zero-days under a three-day CISA deadline, the first joint EU-UK cyber sanctions, and the Accenture breach. Joe Diamond of Axonius joins Ashish Rajan and Caleb Sima on why asset management was never solved, why AI agents are your newest asset class, and the 40% "dark matter" CISOs privately admit to

Ashish Rajan
Ashish Rajan
🚨 FortiBleed Turns 430,000 Firewalls Into a Ransomware Feed: Why "Exploitable" Beats "Reachable"

Jul 9, 2026

•

12 min read

🚨 FortiBleed Turns 430,000 Firewalls Into a Ransomware Feed: Why "Exploitable" Beats "Reachable"

This week's news runs on one mechanic: a secret or key sitting one careless step from the internet, and the exploit that turns it into impact. FortiBleed credentials now feed INC and Lynx ransomware, a Langflow cross-tenant IDOR steals other tenants' cloud keys, and fake payment SDKs harvest CI/CD secrets. Harry Wetherald of Maze explains why the question that matters is no longer "is this reachable" but "is this exploitable".

Ashish Rajan
Ashish Rajan
...
Cloud Security Newsletter

Cloud Security Newsletter

Bringing you relevant Cloud Security News, Interviews & Expert Knowledge so you don’t have to spend hours looking for it.


Home

Posts

Authors

© 2026 Cloud Security Newsletter.
beehiivPowered by beehiiv