Cloud and Cybersecurity News

eyalestrin

Stay sharp on cloud, cybersecurity, and AI - without the noise. Each week, this show breaks down the cloud, security, and AI/ML headlines that actually matter. No hype, no jargon. Just clear signal: • Concise summaries of major breaches, vulnerabilities, and threat trends, • Practical analysis of AI/ML security, misuse, and emerging risks, • Real-world implications for engineers, architects, and security leaders, • Takeaways you can apply immediately at work.

  1. Weekly news update - 15.5.2026

    May 15

    Weekly news update - 15.5.2026

    🌐 Cloud: The Offloading and Containerization Era Microsoft's General Availability of the Next Generation of Azure Boost marks a major leap in performance. By offloading foundational virtualization, networking, and storage processes from the host CPU onto purpose-built hardware, it achieves up to 800k IOPS and 12.5 GB/s in storage throughput. This hardware isolation drastically lowers latency for data-heavy workloads while shrinking the host attack surface. Concurrently, tools like AWS Transform are matching this push by letting enterprises completely skip simple "lift-and-shift" migrations, automatically replatforming legacy workloads straight into secure, production-ready container architectures. 🔒 Cybersecurity: The Expansion of "Agentic" and Identity Risk The State of AI Agent Security 2026 details a massive shift from simple data leakage chatbot risks to Agentic Risk. Attackers are now targeting the internal logic of autonomous agents using chain-of-thought prompt injection to force unauthorized administrative actions. This risk is amplified by a massive Identity Visibility Gap highlighted by Zoho, where 74% of organizations admit they cannot fully account for workforce identities or orphaned accounts, leaving automated business workflows to operate dangerously outside traditional Identity and Access Management (IAM) frameworks. 🤖 AI/ML: The Rise of Autonomous Control and Principled Alignment Microsoft Copilot Studio's General Availability of computer-using agents allows AI to navigate legacy software interfaces without APIs by mimicking human clicks, typing, and scrolling. As systems gain this physical agency, safety frameworks are scrambling to keep up. Anthropic's "Principled Alignment Training" research addresses this exact friction point. Their findings show that teaching models why an action is ethically right or wrong via step-by-step reasoning is significantly more effective at stopping autonomous tool misuse than simply training them on examples of good behavior. https://www.linkedin.com/pulse/weekly-news-update-1552026-eyal-estrin--mvvcf/

    22 min
  2. Weekly news update - 8.5.2026

    May 8

    Weekly news update - 8.5.2026

    Cloud: The "Data Plane" Audit Revolution AWS EventBridge has officially launched General Availability (GA) for Data Plane logging to CloudTrail. For the first time, organizations can move beyond basic management logging to record high-volume PutEvents activities. This is a massive win for governance, providing a verifiable audit trail to detect unauthorized event injections and solve the "black box" problem in complex, event-driven architectures. Cybersecurity: Surviving the "AI Vulnerability Storm" As AI collapses the time between vulnerability discovery and weaponization, the Cloud Security Alliance (CSA) has released its new framework for building "Mythos-ready" security programs. The focus is shifting from traditional patching to VulnOps and autonomous security agents. The key takeaway? Attacker asymmetry is real, and defenders must operationalize AI-driven transaction flow discovery and identity-centric Software-Defined Perimeters (SDP) to stay ahead of machine-speed threats.AI/ML: The Rise of the MCP StandardInfrastructure is finally learning to "talk" to AI. Both AWS and Azure have announced the General Availability of the Model Context Protocol (MCP) Server. This standardized protocol allows AI agents to natively discover, query, and reason about cloud resources (like S3, Lambda, and ARM) without custom glue code. It transforms the cloud from a collection of APIs into a "context-aware" playground for autonomous agents, governed by existing enterprise security boundaries. https://www.linkedin.com/pulse/weekly-news-update-852026-eyal-estrin--tatnf/

    23 min
  3. Weekly news update - 24.4.2026

    Apr 24

    Weekly news update - 24.4.2026

    Cloud: The Shift to Resilient, Scalable Data Fabrics Google has launched the Virgo network fabric, a "megascale" architecture designed specifically for the massive communication demands of modern AI. By utilizing Optical Circuit Switching (OCS), Virgo allows data centers to dynamically reconfigure network paths at the fiber level. This reduces power consumption and improves reliability by automatically bypassing faulty hardware. For architects, this represents a shift toward a unified AI interconnect where TPUs, GPUs, and storage share resources without the traditional bottlenecks of tiered networks. Cybersecurity: Identity as the New Perimeter The Cisco Talos 2025 Year in Review confirms that attackers have moved away from malware-heavy entries in favor of identity-centric tactics. Credential theft and session hijacking are now the primary drivers of breaches, effectively turning "living off the cloud" into a standard operating procedure for threat actors. To counter this, security teams must pivot from traditional endpoint defense to monitoring API activities and cloud-native service permissions, as automated ransomware now exfiltrates data faster than manual investigation can detect. AI/ML: The Rise of Autonomous Agentic Workflows The release of GPT-5.5 marks a transition from simple chatbots to autonomous agents capable of independent multi-step planning and self-correction. This "agentic" shift is mirrored in the infrastructure layer, with tools like Gemini Embedding 2 providing the semantic foundation for Retrieval-Augmented Generation (RAG). However, this autonomy brings risk; the Cloud Security Alliance reports that 65% of enterprises experienced an AI agent-related incident last year, with shadow AI agents frequently appearing in internal automation environments. https://www.linkedin.com/pulse/weekly-news-update-2442026-eyal-estrin--cb7df/

    21 min
  4. Weekly news update - 17.4.2026

    Apr 17

    Weekly news update - 17.4.2026

    Cloud: The Arrival of Native Multicloud Networking The headline in cloud infrastructure is the general availability of AWS Interconnect. This service marks a strategic shift by AWS to simplify "last-mile" connectivity to other providers. By leveraging the AWS global backbone, architects can now establish high-speed, direct links to rival clouds without managing complex third-party circuits or brittle VPN tunnels. This move effectively treats multicloud integration as a native networking feature rather than a logistical hurdle. Cybersecurity: The Race Against AI-Powered Exploits The central theme in security is the "Patch Sound Barrier." Research highlights that AI is now accelerating vulnerability discovery and exploit chaining to a speed that traditional human-led remediation cannot match. To counter this, industry leaders are advocating for a defensive shift toward autonomous "self-red-teaming." The strategy involves deploying frontier models to scan codebases and generate patches within 24-hour windows, essentially using the same AI tools as attackers to harden the perimeter before exploits can be realized. AI/ML: The Rise of Agentic Engineering The most significant trend in AI is the transition from simple chat interfaces to autonomous agentic workflows. With the launch of Claude Opus 4.7 and its "Advisor Strategy," models can now self-verify code and orchestrate multi-step engineering tasks with minimal human intervention. This is supported by new specialized tooling like GPT-5.4-Cyber and domain-specific models like GPT-Rosalind for life sciences. These developments signal a move toward "Expert AI" that doesn't just suggest content but actively executes complex research and development cycles. https://www.linkedin.com/pulse/weekly-news-update-1742026-eyal-estrin--peu8f/

    17 min

About

Stay sharp on cloud, cybersecurity, and AI - without the noise. Each week, this show breaks down the cloud, security, and AI/ML headlines that actually matter. No hype, no jargon. Just clear signal: • Concise summaries of major breaches, vulnerabilities, and threat trends, • Practical analysis of AI/ML security, misuse, and emerging risks, • Real-world implications for engineers, architects, and security leaders, • Takeaways you can apply immediately at work.