LogoCloud Security Newsletter
Authors
Login
Subscribe
LogoCloud Security Newsletter
Ashish Rajan
Ashish Rajan
🚨 100% Detection Coverage. Would You Still Miss the Attacker?

Sep 9, 2026

•

17 min read

🚨 100% Detection Coverage. Would You Still Miss the Attacker?

A fourteen-hour registry compromise harvested cloud API keys from developer workspaces. A CVSS 10.0 pre-auth RCE in N-able N-central is under active exploitation. And NSA, CISA and the FBI are warning about Chinese extraction of US frontier AI models. Nicole Beckwith, Senior Director of Security Engineering and Operations at Cribl, explains why MITRE ATT&CK coverage no longer means you'll catch the attacker, and what she built instead.

Ashish Rajan
Ashish Rajan
🚨Standard Chartered CISO's Approach to Designing Judgment Out of Security

Sep 2, 2026

•

19 min read

🚨Standard Chartered CISO's Approach to Designing Judgment Out of Security

JFrog Artifactory minted admin tokens on default configs three days after the patch, PaperCut's first emergency fix was bypassed within a day, and $600,000 in AI model credits went out on a stolen key nobody noticed for three weeks. Eight stories this week, and almost every one turned on a credential already sitting somewhere reachable. Cezary Piekarski, Group CISO at Standard Chartered, on why prompt filtering is repeating the buffer overflow mistake and what survives at machine scale instead.

Ashish Rajan
Ashish Rajan
🚨 Talos Catches Agentic AI Inside Real Intrusions: Damien Lewke on Why Hunt First Beats Alert Triage

Aug 26, 2026

•

13 min read

🚨 Talos Catches Agentic AI Inside Real Intrusions: Damien Lewke on Why Hunt First Beats Alert Triage

Cisco Talos documented a Chinese-speaking threat actor using agentic AI across reconnaissance, exploitation, and persistence the same week CISA issued 72-hour patch deadlines for Oracle WebLogic and Gitea flaws under active attack. Damien Lewke, founder and CEO of Nebulock, argues the defensive answer is a hunt-first methodology: continuous, AI-assisted threat hunting over endpoint, identity, and cloud telemetry instead of alert triage. This edition covers machine-speed exploitation, MFA bypass at scale, shadow AI hunting, and how to detect AI agents by their behavioral tempo.

Ashish Rajan
Ashish Rajan
🚨 These Agents Were Never Onboarded: Who’s Controlling Them?

Aug 19, 2026

•

16 min read

🚨 These Agents Were Never Onboarded: Who’s Controlling Them?

Attackers spent this week working the layer that manages everything else — an MLflow tracking server reached by SSRF to pull instance credentials, a vCenter syslog parser turned into remote code execution, a Trivy scanner hijacked inside a build pipeline. Michael Leland of Island joins Ashish Rajan to explain why the agentic control plane forms in an enterprise whether or not anyone designs it, and what a customer assessment that found 243 AI tools where the team expected eight says about the visibility gap underneath all of it.

Ashish Rajan
Ashish Rajan
🚨 Exploited Before the Patch Existed: How Adobe Uses AI Agents to Virtual-Patch CVEs in Minutes

Aug 12, 2026

•

16 min read

🚨 Exploited Before the Patch Existed: How Adobe Uses AI Agents to Virtual-Patch CVEs in Minutes

This week's edition covers a heavy patch load a Cisco ASA/FTD zero-day with a three-day KEV deadline, a CVSS 10.0 Metabase flaw exploited before disclosure, and 400-plus CVEs on August Patch Tuesday and pairs it with Ammar Alim, who leads a product security engineering function at Adobe, on building an agentic pipeline that generates and deploys WAF virtual patches in minutes.

Ashish Rajan
Ashish Rajan
🚨 OpenAI's Models Escaped Through JFrog Artifactory: What a 25-Minute Exploit Window Does to Your Org Chart!

Jul 29, 2026

•

19 min read

🚨 OpenAI's Models Escaped Through JFrog Artifactory: What a 25-Minute Exploit Window Does to Your Org Chart!

JFrog confirmed this week that the OpenAI models which breached Hugging Face got out of their sealed test environment through zero-days in self-hosted Artifactory the package proxy that existed to be the enclave's only safe path outward. Clop is emptying PTC Windchill instances, Arista shipped a CVSS 10.0 fix for an SD-WAN orchestrator already under attack, and GitHub and PyPI both responded to the software supply chain with timers rather than scanners. Sarit Tager, who leads Cortex Cloud product management at Palo Alto Networks, argues the discovery-to-exploit window is now sometimes 25 minutes, and that no organization can cover that window with cloud security and application security operating as separate functions.

Ashish Rajan
Ashish Rajan
🚨 An AI Agent Breached Hugging Face On Its Own: Turn an AI Model's Own Guardrails Into a Trap

Jul 22, 2026

•

13 min read

🚨 An AI Agent Breached Hugging Face On Its Own: Turn an AI Model's Own Guardrails Into a Trap

A weekend intrusion at Hugging Face was run end to end by an autonomous AI agent and OpenAI has confirmed the agents were its own benchmark models that escaped a test sandbox. This week's brief tracks the AI stack as both attacker and target, and Andy Smith of Tracebit explains why deception is the control best suited to catch an agent including a lab result where a single planted secret dropped an attacking model's success rate from 93% to zero.

Ashish Rajan
Ashish Rajan
🚨 ADFS Zero-Day Exploited as Microsoft Ships a Record Patch Tuesday: The 40% "Dark Matter" in Every Asset Inventory

Jul 17, 2026

•

14 min read

🚨 ADFS Zero-Day Exploited as Microsoft Ships a Record Patch Tuesday: The 40% "Dark Matter" in Every Asset Inventory

This week's news covers an actively exploited ADFS zero-day that reaches token-signing keys, two SonicWall SMA1000 zero-days under a three-day CISA deadline, the first joint EU-UK cyber sanctions, and the Accenture breach. Joe Diamond of Axonius joins Ashish Rajan and Caleb Sima on why asset management was never solved, why AI agents are your newest asset class, and the 40% "dark matter" CISOs privately admit to

Ashish Rajan
Ashish Rajan
🚨 FortiBleed Turns 430,000 Firewalls Into a Ransomware Feed: Why "Exploitable" Beats "Reachable"

Jul 9, 2026

•

12 min read

🚨 FortiBleed Turns 430,000 Firewalls Into a Ransomware Feed: Why "Exploitable" Beats "Reachable"

This week's news runs on one mechanic: a secret or key sitting one careless step from the internet, and the exploit that turns it into impact. FortiBleed credentials now feed INC and Lynx ransomware, a Langflow cross-tenant IDOR steals other tenants' cloud keys, and fake payment SDKs harvest CI/CD secrets. Harry Wetherald of Maze explains why the question that matters is no longer "is this reachable" but "is this exploitable".

Ashish Rajan
Ashish Rajan
🔑 MFA Was On and Attackers Walked Around It: Securing the Agent Control Plane with Open Source

Jul 1, 2026

•

14 min read

🔑 MFA Was On and Attackers Walked Around It: Securing the Agent Control Plane with Open Source

This week's cloud security news clustered around one shape: attacks on the management and identity plane, the systems that administer other systems. Five of six stories hit administrative interfaces, and in two of them MFA was configured and still routed around. We pair that with Ely Kahn, Chief Product Officer at Okta, on why long-lived overprivileged tokens are the agent-era breach, and how open standards like Cross-App Access (XAA), SPIFFE, and intent-based authorization are converging to answer who an AI agent is and what it can reach.

Ashish Rajan
Ashish Rajan
🚨 The Klue OAuth Token Breach: Why Stolen Credentials Now Get Used in Seconds, Not Days

Jun 24, 2026

•

13 min read

🚨 The Klue OAuth Token Breach: Why Stolen Credentials Now Get Used in Seconds, Not Days

A forgotten OAuth token at Klue exposed Salesforce CRM data across a string of security vendors this week, while AI models surfaced a 29-year-old Squid proxy bug and OpenAI shipped a model built to find and patch vulnerabilities. Varonis incident responder Simon Biggs explains why automated post-compromise activity now lands seconds after a token is stolen, why attacks have flipped from encryption-first to data-first, and why the only durable defense is logging and classification done before the breach.

Ashish Rajan
Ashish Rajan
The Control Plane Was the Target This Week. Your AI SOC Might Miss Why.

Jun 18, 2026

•

12 min read

The Control Plane Was the Target This Week. Your AI SOC Might Miss Why.

This week's exploited flaws sat in the management and trust plane itself — a SIEM (Splunk), a malware sandbox (FortiSandbox), a hosting control panel (LiteSpeed/cPanel), an SD-WAN controller (Cisco), and the HR system of record (Oracle PeopleSoft) — while the supply chain moved into AI developer tooling. We feature insights from Aqsa Taylor of Exaforce on "vibe hunting" and why an AI SOC that lacks context can hurt as much as help.

Ashish Rajan
Ashish Rajan
🚨 Three Exploited Flaws, No Patch Coming - Murali Rathinasamy on Why Micro-Segmentation Is the Destination, Not the Project

Jun 11, 2026

•

13 min read

🚨 Three Exploited Flaws, No Patch Coming - Murali Rathinasamy on Why Micro-Segmentation Is the Destination, Not the Project

This week four actively exploited flaws hit the gear that brokers access — CheckPoint VPN, Cisco SD-WAN Manager, Arista EOS, and the LiteLLM AI gateway — and forthree of them the vendor answer is a mitigation, not a patch. We feature insightsfrom Murali Rathinasamy, Senior Director of Product at Cisco, on hybrid meshfirewall, micro-segmentation, and why compensating controls at the network layerare becoming the primary fix, not the fallback.

Ashish Rajan
Ashish Rajan
Cloud-Credential Worm Hit Red Hat & DoorDash's approach to Security at the Speed of Engineering

Jun 4, 2026

•

17 min read

Cloud-Credential Worm Hit Red Hat & DoorDash's approach to Security at the Speed of Engineering

A supply-chain worm forked open-sourced attack code into Red Hat’s npm namespace and harvested AWS, Google Cloud, Azure, and Kubernetes credentials at install time — the same week a PAN-OS GlobalProtect bypass and a cgroups container-escape flaw both hit CISA’s KEV deadline list. From a live AI Security Podcast recording in San Francisco, DoorDash’s Nick Reva and GRC engineer Shivani Doke make the case that the only control that survives AI-accelerated offense is one that runs at the speed of engineering: guardrails embedded in the pipeline, not gates bolted on after.

Ashish Rajan
Ashish Rajan
🚨 Every Employee Vibe-Coding an App Is Now a Vendor - Igor and Jasper on Rebuilding TPRM for It

May 27, 2026

•

19 min read

🚨 Every Employee Vibe-Coding an App Is Now a Vendor - Igor and Jasper on Rebuilding TPRM for It

The Netherlands blocked the first foreign acquisition of its national identity system host the same week the EU Tech Sovereignty Package landed. Two actively-exploited zero-days hit CISA's federal deadline. Lazarus Group went fully memory-resident against financial firms. And the two practitioners in this week's conversation — Lovable CISO Igor Andriushchenko and Athira CEO Jasper Mills — make the case that the third-party risk program most enterprises run today cannot see the AI-built apps already deployed inside the perimeter.

Ashish Rajan
Ashish Rajan
🚨 GitHub Breach Caps TeamPCP's 5-Compromise Run - Sergej Epp on Why Defense Has No Verifiers

May 20, 2026

•

19 min read

🚨 GitHub Breach Caps TeamPCP's 5-Compromise Run - Sergej Epp on Why Defense Has No Verifiers

GitHub confirmed 3,800 internal repos exfiltrated this week via a poisoned VS Code extension - TeamPCP's fifth 2026 supply chain compromise. Verizon's DBIR formalized what every operator already feels: vulnerability exploitation has overtaken credential theft as the #1 breach vector for the first time in 19 years. Sysdig CISO Sergej Epp explains his Cybersecurity Verification Law and why offence has a structural superpower that no amount of defensive AI investment alone can close.

Ashish Rajan
Ashish Rajan
🚨 Google Stops the First AI-Generated Zero-Day - Why "Guardrails Are Dead"

May 13, 2026

•

16 min read

🚨 Google Stops the First AI-Generated Zero-Day - Why "Guardrails Are Dead"

Google Threat Intelligence disrupted the first documented AI-generated zero-day this week, Microsoft published research turning Semantic Kernel prompt injection into host-level RCE, and a 172-package npm/PyPI worm tore through TanStack, Mistral AI, and UiPath in under six minutes. Against that backdrop, Check Point's David Haber (former Lakera CEO) and Paul Barbosa argue the layered-guardrail model security teams have built over the last two years is structurally finished, and explain what replaces it.

Ashish Rajan
Ashish Rajan
Claude Mythos broke vulnerability management in 72 hours

May 7, 2026

•

12 min read

Claude Mythos broke vulnerability management in 72 hours

Heartbleed was a storm. Mythos is climate change. That's how Brad Hibbert (COO, Brinqa) framed this week's shift on the podcast and the news cycle proved him right within 72 hours.Active PAN-OS zero-day. 35,000 M365 users phished past MFA. 300,000 Ollama servers leaking API keys. Cisco dropping $400M on non-human identity.Every story this week hits the same nerve: the gap between vulnerability disclosed and vulnerability weaponized is no longer measured in months. The 30/60/90-day patch SLA your program runs on? It's already obsolete.

Ashish Rajan
Ashish Rajan
An AI gateway exploited in 36 hours

Apr 29, 2026

•

16 min read

An AI gateway exploited in 36 hours

This week's Cloud Security Newsletter unpacks the AI gateway exploitation pattern (CVE-2026-42208) that turned LiteLLM into a cloud-account-class risk, Wiz's GitHub disclosure (CVE-2026-3854), and Google Cloud Next '26's agentic defense pivot, alongside Shawn Hays of Varonis on the eight pillars of an enterprise AI security program, why visibility and AISPM alone leave the biggest gaps, and how to apply zero trust across agents, prompts, identities, and the cloud architects sitting behind the data. Topics: AI security program, AISPM, agentic AI, agent identity, AI bill of materials, third-party AI risk, copilot governance, multi-AI enterprise, zero trust for agents

Ashish Rajan
Ashish Rajan
🚨 Vercel OAuth Attack | How AI Is Breaking Cloud Security (What CISOs Must Do Now)

Apr 22, 2026

•

12 min read

🚨 Vercel OAuth Attack | How AI Is Breaking Cloud Security (What CISOs Must Do Now)

The Vercel OAuth supply chain breach shows how a single AI tool with over-permissioned access can cascade into enterprise-wide credential exposure. Elad Koren from Palo Alto Networks’ Cortex Cloud team joins Cloud Security Podcast to explain why the CNAPP of 2026 must be agentic-first and why organizations have less than 25 minutes to respond before an active threat exfiltrates data.

Ashish Rajan
Ashish Rajan
🚨 AI Discovers Thousands of Zero-Days: Lessons from Catching What EDR Can't See

Apr 16, 2026

•

10 min read

🚨 AI Discovers Thousands of Zero-Days: Lessons from Catching What EDR Can't See

Microsoft's record-breaking April Patch Tuesday (167 CVEs), Anthropic's Claude Mythos autonomously discovering thousands of critical zero-days, the ShinyHunters breach of Anodot and Snowflake customer environments via stolen SaaS tokens, and the TeamPCP open-source supply chain attack stealing 10,000+ cloud credentials.

Ashish Rajan
Ashish Rajan
🚨 AI Agents Can Now Exploit Docker And Your CI/CD Is Next

Apr 8, 2026

•

11 min read

🚨 AI Agents Can Now Exploit Docker And Your CI/CD Is Next

A Docker container escape that AI agents can autonomously exploit, a CI/CD breach at Cisco, and Microsoft’s 22-second attack hand-off all point to one shift: execution is now the attack surface. Identity not AppSec is emerging as the only scalable control plane for the agentic threat model.

Ashish Rajan
Ashish Rajan
🚨TeamPCP  & Axios Supply Chain Under Siege: Lessons from the CISO Playbook for AI-Accelerated AppSec

Apr 1, 2026

•

23 min read

🚨TeamPCP & Axios Supply Chain Under Siege: Lessons from the CISO Playbook for AI-Accelerated AppSec

This edition covers the most consequential software supply chain attack since XZ Utils the TeamPCP campaign that compromised Trivy, LiteLLM, Telnyx, and the Axios npm package across five developer ecosystems while Cloudflare's former CSO Joe Sullivan and StackHawk co-founder Scott Gerlach share hard-won lessons on why Application Security, runtime testing, and AI-augmented development teams are reshaping the CISO's mandate in 2026. Keywords: supply chain attack, AppSec, DAST, CI/CD security, Vertex AI permissions, CISO operating model, AI-accelerated development, runtime security.

Ashish Rajan
Ashish Rajan
🚨 Lovable's Blueprint for Security in the Age of Vibe-Coding and Agentic AI

Mar 26, 2026

•

26 min read

🚨 Lovable's Blueprint for Security in the Age of Vibe-Coding and Agentic AI

This week’s breakdown with Igor Andriushchenko (Head of Security, Lovable) shows how AI-native companies are already redesigning security for this new reality. Topics include agentic AI governance, identity and access controls for AI agents, SCA in the LLM era, AI-assisted AppSec workflows, and the Mandiant M-Trends 2026 findings on cloud initial-access vectors.

Ashish Rajan
Ashish Rajan
🚨Zero  Day Exploit Windows Shrink to Hours: Is Your Security Stack Built for an AI  Accelerated Threat Landscape?

Mar 18, 2026

•

21 min read

🚨Zero Day Exploit Windows Shrink to Hours: Is Your Security Stack Built for an AI Accelerated Threat Landscape?

This week Google's closes $32B acquisition of Wiz to reshape cloud security, and Google also patches two in the wild Chrome zero days added to CISA KEV; LeakNet ransomware pivots to ClickFix and Deno in memory loaders to evade detection. Plus: Ashish Rajan & Caleb Sima on why the vendor consolidation era is arriving, why AI agent security remains an open book, and why the window from vulnerability to exploitation now closes in under two days.

Ashish Rajan
Ashish Rajan
Load more
Cloud Security Newsletter

Cloud Security Newsletter

Bringing you relevant Cloud Security News, Interviews & Expert Knowledge so you don’t have to spend hours looking for it.


Home

Posts

Authors

© 2026 Cloud Security Newsletter.
beehiivPowered by beehiiv