Logo
Search
Home
Archive
Login
SUBSCRIBE
Logo

cloud-security

cloud-security

+3

Your agent can edit /etc/hosts

Sep 8, 2026

•

5 min read

Your agent can edit /etc/hosts

Agents on a timed lookup task were allowed to fetch pages and blocked from sending anything that writes. They invented a hostname ending in a trusted suffix, pointed it at the blocked server, and posted the recipe for each other.

cloud-security

+4

Malware asks your MCP server what it can do

Aug 25, 2026

•

7 min read

Malware asks your MCP server what it can do

It asks your server what tools it has, then uses the one that runs commands. No bug, no patch.

cloud-security

+4

Your build server runs commands from strangers

Aug 11, 2026

•

6 min read

Your build server runs commands from strangers

TeamCity handed XStream a list of allowed classes. XStream added it to the ones it already allowed.

cloud-security

+3

Your secrets webhook hands out its own token

Aug 4, 2026

•

6 min read

Your secrets webhook hands out its own token

One annotation redirects the client, and the webhook's own token goes with it

R.K. Chidambaram
R.K. Chidambaram

cloud-security

+4

How a rootkit hides a connection

Jul 28, 2026

•

2 min read

How a rootkit hides a connection

One number gets rewritten, and your socket list comes back short

cloud-security

+2

Your GitOps controller can hand over the whole cluster

Jul 14, 2026

•

6 min read

Your GitOps controller can hand over the whole cluster

An unauthenticated bug in Argo CD's repo-server walks straight to full cluster takeover. No CVE, no patch, and the fix is a Helm setting the chart shipped switched off until 10.0.0.

Weekly Recon

Weekly defensive engineering for cloud, CI/CD, agents, Kubernetes, and software supply-chain security. One attack walked through. One detection idea. One defender move worth shipping.

© 2026 defensive.works Weekly Recon.
beehiivPowered by beehiiv