LogoCloud Security Newsletter
Authors
Login
Subscribe
LogoCloud Security Newsletter

Archive

🚨 Three Exploited Flaws, No Patch Coming - Murali Rathinasamy on Why Micro-Segmentation Is the Destination, Not the Project

Jun 11, 2026

•

13 min read

🚨 Three Exploited Flaws, No Patch Coming - Murali Rathinasamy on Why Micro-Segmentation Is the Destination, Not the Project

This week four actively exploited flaws hit the gear that brokers access — CheckPoint VPN, Cisco SD-WAN Manager, Arista EOS, and the LiteLLM AI gateway — and forthree of them the vendor answer is a mitigation, not a patch. We feature insightsfrom Murali Rathinasamy, Senior Director of Product at Cisco, on hybrid meshfirewall, micro-segmentation, and why compensating controls at the network layerare becoming the primary fix, not the fallback.

Ashish Rajan
Ashish Rajan
Cloud-Credential Worm Hit Red Hat & DoorDash's approach to Security at the Speed of Engineering

Jun 4, 2026

•

17 min read

Cloud-Credential Worm Hit Red Hat & DoorDash's approach to Security at the Speed of Engineering

A supply-chain worm forked open-sourced attack code into Red Hat’s npm namespace and harvested AWS, Google Cloud, Azure, and Kubernetes credentials at install time — the same week a PAN-OS GlobalProtect bypass and a cgroups container-escape flaw both hit CISA’s KEV deadline list. From a live AI Security Podcast recording in San Francisco, DoorDash’s Nick Reva and GRC engineer Shivani Doke make the case that the only control that survives AI-accelerated offense is one that runs at the speed of engineering: guardrails embedded in the pipeline, not gates bolted on after.

Ashish Rajan
Ashish Rajan
🚨 Every Employee Vibe-Coding an App Is Now a Vendor - Igor and Jasper on Rebuilding TPRM for It

May 27, 2026

•

19 min read

🚨 Every Employee Vibe-Coding an App Is Now a Vendor - Igor and Jasper on Rebuilding TPRM for It

The Netherlands blocked the first foreign acquisition of its national identity system host the same week the EU Tech Sovereignty Package landed. Two actively-exploited zero-days hit CISA's federal deadline. Lazarus Group went fully memory-resident against financial firms. And the two practitioners in this week's conversation — Lovable CISO Igor Andriushchenko and Athira CEO Jasper Mills — make the case that the third-party risk program most enterprises run today cannot see the AI-built apps already deployed inside the perimeter.

Ashish Rajan
Ashish Rajan
🚨 GitHub Breach Caps TeamPCP's 5-Compromise Run - Sergej Epp on Why Defense Has No Verifiers

May 20, 2026

•

19 min read

🚨 GitHub Breach Caps TeamPCP's 5-Compromise Run - Sergej Epp on Why Defense Has No Verifiers

GitHub confirmed 3,800 internal repos exfiltrated this week via a poisoned VS Code extension - TeamPCP's fifth 2026 supply chain compromise. Verizon's DBIR formalized what every operator already feels: vulnerability exploitation has overtaken credential theft as the #1 breach vector for the first time in 19 years. Sysdig CISO Sergej Epp explains his Cybersecurity Verification Law and why offence has a structural superpower that no amount of defensive AI investment alone can close.

Ashish Rajan
Ashish Rajan
🚨 Google Stops the First AI-Generated Zero-Day - Why "Guardrails Are Dead"

May 13, 2026

•

16 min read

🚨 Google Stops the First AI-Generated Zero-Day - Why "Guardrails Are Dead"

Google Threat Intelligence disrupted the first documented AI-generated zero-day this week, Microsoft published research turning Semantic Kernel prompt injection into host-level RCE, and a 172-package npm/PyPI worm tore through TanStack, Mistral AI, and UiPath in under six minutes. Against that backdrop, Check Point's David Haber (former Lakera CEO) and Paul Barbosa argue the layered-guardrail model security teams have built over the last two years is structurally finished, and explain what replaces it.

Ashish Rajan
Ashish Rajan
Claude Mythos broke vulnerability management in 72 hours

May 7, 2026

•

12 min read

Claude Mythos broke vulnerability management in 72 hours

Heartbleed was a storm. Mythos is climate change. That's how Brad Hibbert (COO, Brinqa) framed this week's shift on the podcast and the news cycle proved him right within 72 hours.Active PAN-OS zero-day. 35,000 M365 users phished past MFA. 300,000 Ollama servers leaking API keys. Cisco dropping $400M on non-human identity.Every story this week hits the same nerve: the gap between vulnerability disclosed and vulnerability weaponized is no longer measured in months. The 30/60/90-day patch SLA your program runs on? It's already obsolete.

Ashish Rajan
Ashish Rajan
An AI gateway exploited in 36 hours

Apr 29, 2026

•

16 min read

An AI gateway exploited in 36 hours

This week's Cloud Security Newsletter unpacks the AI gateway exploitation pattern (CVE-2026-42208) that turned LiteLLM into a cloud-account-class risk, Wiz's GitHub disclosure (CVE-2026-3854), and Google Cloud Next '26's agentic defense pivot, alongside Shawn Hays of Varonis on the eight pillars of an enterprise AI security program, why visibility and AISPM alone leave the biggest gaps, and how to apply zero trust across agents, prompts, identities, and the cloud architects sitting behind the data. Topics: AI security program, AISPM, agentic AI, agent identity, AI bill of materials, third-party AI risk, copilot governance, multi-AI enterprise, zero trust for agents

Ashish Rajan
Ashish Rajan
🚨 Vercel OAuth Attack | How AI Is Breaking Cloud Security (What CISOs Must Do Now)

Apr 22, 2026

•

12 min read

🚨 Vercel OAuth Attack | How AI Is Breaking Cloud Security (What CISOs Must Do Now)

The Vercel OAuth supply chain breach shows how a single AI tool with over-permissioned access can cascade into enterprise-wide credential exposure. Elad Koren from Palo Alto Networks’ Cortex Cloud team joins Cloud Security Podcast to explain why the CNAPP of 2026 must be agentic-first and why organizations have less than 25 minutes to respond before an active threat exfiltrates data.

Ashish Rajan
Ashish Rajan
🚨 AI Discovers Thousands of Zero-Days: Lessons from Catching What EDR Can't See

Apr 16, 2026

•

10 min read

🚨 AI Discovers Thousands of Zero-Days: Lessons from Catching What EDR Can't See

Microsoft's record-breaking April Patch Tuesday (167 CVEs), Anthropic's Claude Mythos autonomously discovering thousands of critical zero-days, the ShinyHunters breach of Anodot and Snowflake customer environments via stolen SaaS tokens, and the TeamPCP open-source supply chain attack stealing 10,000+ cloud credentials.

Ashish Rajan
Ashish Rajan
🚨 AI Agents Can Now Exploit Docker And Your CI/CD Is Next

Apr 8, 2026

•

11 min read

🚨 AI Agents Can Now Exploit Docker And Your CI/CD Is Next

A Docker container escape that AI agents can autonomously exploit, a CI/CD breach at Cisco, and Microsoft’s 22-second attack hand-off all point to one shift: execution is now the attack surface. Identity not AppSec is emerging as the only scalable control plane for the agentic threat model.

Ashish Rajan
Ashish Rajan
🚨TeamPCP  & Axios Supply Chain Under Siege: Lessons from the CISO Playbook for AI-Accelerated AppSec

Apr 1, 2026

•

23 min read

🚨TeamPCP & Axios Supply Chain Under Siege: Lessons from the CISO Playbook for AI-Accelerated AppSec

This edition covers the most consequential software supply chain attack since XZ Utils the TeamPCP campaign that compromised Trivy, LiteLLM, Telnyx, and the Axios npm package across five developer ecosystems while Cloudflare's former CSO Joe Sullivan and StackHawk co-founder Scott Gerlach share hard-won lessons on why Application Security, runtime testing, and AI-augmented development teams are reshaping the CISO's mandate in 2026. Keywords: supply chain attack, AppSec, DAST, CI/CD security, Vertex AI permissions, CISO operating model, AI-accelerated development, runtime security.

Ashish Rajan
Ashish Rajan
🚨 Lovable's Blueprint for Security in the Age of Vibe-Coding and Agentic AI

Mar 26, 2026

•

26 min read

🚨 Lovable's Blueprint for Security in the Age of Vibe-Coding and Agentic AI

This week’s breakdown with Igor Andriushchenko (Head of Security, Lovable) shows how AI-native companies are already redesigning security for this new reality. Topics include agentic AI governance, identity and access controls for AI agents, SCA in the LLM era, AI-assisted AppSec workflows, and the Mandiant M-Trends 2026 findings on cloud initial-access vectors.

Ashish Rajan
Ashish Rajan
1234...10
Cloud Security Newsletter

Cloud Security Newsletter

Bringing you relevant Cloud Security News, Interviews & Expert Knowledge so you don’t have to spend hours looking for it.


Home

Posts

Authors

© 2026 Cloud Security Newsletter.
beehiivPowered by beehiiv