7 Aug 2026, 04:20 UTC122 views3 reactionsread 7 August 2026 Photo
🤖 AI Worming through Word
A coordinated disclosure with MSRC demonstrating a document-borne AI worm in Microsoft Copilot for Word: hidden XPIA prompts in source documents cause Copilot to alter generated content and self-propagate the malicious instructions into downstream documents.
https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word
#AI
❤1👍1🔥1
Signed Артем Марков
6 Aug 2026, 04:39 UTC163 views3 reactionsread 7 August 2026 Photo
🤖 A Security Analysis of Amazon S3 Vectors and Its Use in LLM Retrieval Pipelines
An analysis of the security model of Amazon S3 Vectors and of the considerations that arise when it is used as the retrieval layer for LLM applications: access control scope, input validation, metadata integrity, and audit coverage.
https://www.offensai.com/blog/amazon-s3-vectors-security-llm-rag-poisoning
#AI
❤1👍1🔥1
Signed Артем Марков
5 Aug 2026, 04:56 UTC191 views4 reactionsread 7 August 2026 Photo
🤖 Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
A companion technical writeup to HunggingFace's incident disclosure from last week. This post walks through how the intrusion actually worked: the two initial-access vectors, how the agent pivoted and moved laterally, representative examples of the commands that were run and how they investigated with GLM 5.2.
https://huggin…
🔥2❤1👍1
Signed Артем Марков
4 Aug 2026, 06:00 UTC210 views3 reactionsread 7 August 2026 Photo
🤖 Least privilege for AI agents: Identity, access, and tool binding
AI agents acting as autonomous multi-system actors require dedicated managed identities, least-privilege task-scoped RBAC, explicit tool allowlists, JIT time-limited entitlements, downstream re-authorization per call, and end-to-end audit logs capturing identity, role, scope, and correlation IDs.
https://www.microsoft.com/en-us/security/blog/2026/0…
❤1👍1🔥1
Signed Артем Марков
3 Aug 2026, 04:39 UTC215 views4 reactionsread 7 August 2026 Photo
🤖 Inside the OpenClaw Ecosystem: What Happens When AI Agents Get Credentials to Everything
Permiso researchers deployed an AI agent (Rufio) into the OpenClaw ecosystem and found active malware campaigns in its unvetted skill marketplace (ClawHub), credential-harvesting skills with 377+ downloads, C2 infrastructure, and prompt injection attacks targeting agents holding plaintext credentials to email, Slack, and file …
🔥2❤1👍1
Signed Артем Марков
31 Jul 2026, 09:58 UTC278 views3 reactionsread 7 August 2026 Photo
🤖 New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs
A study of ~200,000 LLM responses found 5 frontier models (Claude, GPT, Gemini, DeepSeek) hallucinate nonexistent package names at 4.62-6.10%, with 53 shared fictitious names on PyPI/npm still registrable and exploitable via slopsquatting attacks.
https://socket.dev/blog/slopsquatting-targets-across-frontier-llms
#AI
❤1👍1🔥1
Signed Артем Марков
30 Jul 2026, 06:03 UTC294 views3 reactionsread 7 August 2026 Photo
🔶 Introducing the Amazon GuardDuty investigation agent: on-demand AI-powered threat assessment
Amazon GuardDuty investigation agent (public preview) uses AI to auto-investigate GuardDuty security findings, reducing investigation time from hours to minutes. It returns risk levels, confidence scores, MITRE ATT&CK mappings, and remediation steps via console, CLI, API, or AWS MCP server.
https://aws.amazon.com/ru/blogs…
❤1👍1🔥1
Signed Артем Марков
29 Jul 2026, 07:59 UTC251 views4 reactionsread 7 August 2026 Photo
🤖 Delegated authority, running locally: Give an agent on your machine an identity you can trust
A reference architecture for giving a locally-running AI agent a trustworthy, auditable identity, without long-lived credentials on disk, including a structural defense against prompt injection built into the protocol layer.
https://1password.com/blog/ai-agent-identity-delegated-local
#AI
🔥2❤1👍1
Signed Артем Марков
28 Jul 2026, 04:10 UTC298 views3 reactionsread 7 August 2026 Photo
🤖 CISO's guide to agentic AI
Anthropic's Deputy CISO shares a four-question framework for assessing agentic AI risk, and walks through controls that keep agent deployments bounded and auditable.
https://claude.com/blog/ciso-guide-to-agentic-ai
#AI
❤1👍1🔥1
Signed Артем Марков
27 Jul 2026, 04:03 UTC331 views3 reactionsread 7 August 2026 Photo
🔶 Introducing Claude apps gateway for AWS
Amazon announced the Claude apps gateway for AWS, a self-hosted control plane that gives organizations a single point of control over access, cost, and policy for Claude Code and Claude Desktop.
https://aws.amazon.com/ru/blogs/machine-learning/introducing-claude-apps-gateway-for-aws
#aws
❤1👍1🔥1
Signed Артем Марков
24 Jul 2026, 08:48 UTC352 views3 reactionsread 7 August 2026 Photo
🔶🔷🔴 The Two Mitigations for the Service-Account Confused Deputy in the Cloud
Two mitigations exist for cloud service-account confused deputy attacks: for customer-managed identities, an attachment gate (GCP actAs, AWS iam:PassRole, Azure assign/action) controls bind-time authorization; for provider-managed identities, the CSP enforces internal checks, with AWS uniquely exposing this via Forward Access Sessions and c…
❤1👍1🔥1
Signed Артем Марков
23 Jul 2026, 05:11 UTC310 views4 reactionsread 7 August 2026 Photo
🔶 OIDC tokens can now restrict which AWS roles they assume
AWS STS now supports a new OIDC claim that restricts which role ARNs a token can assume. Enforced before trust policy evaluation. The boolean condition key sts:RoleAuthorizedByIdp enables mandatory enforcement via trust policies or RCPs.
https://awsteele.com/blog/2026/07/13/oidc-tokens-can-restrict-which-aws-roles-they-assume.html
#aws
❤2👍1🔥1
Signed Артем Марков
Showing the 12 most recent of 15 posts we hold for @cloud_sec. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.