Cyber Decision LedgerTechnology

Cloud platform

5 public Decision Records in the whole ledger carry this label. Back to the full Ledger →

Decision Records

AI platform and agent exposure triageCRT-2026-00832026.07.14Afternoon roundtable6 references

Prioritize AI platform risks by exposure to secrets, execution, and automation

Inventory and block public access to MCP, local LLM, JSON-RPC, assistant configuration, and .env paths; validate vendor applicability before patching or isolating affected AI platform deployments; audit Langflow and similar tools for AWS metadata, secrets, CI/CD, and internal API access; rotate keys only if suspicious access appears.

Prioritize AI-platform and agent findings when they create a path to credentials, cloud metadata, code execution, repositories, or privileged automation. Block exposed MCP, local LLM, JSON-RPC, assistant-configuration, and .env paths; validate vendor applicability and local exposure before product-specific patch or isolation claims; rotate keys when suspicious access is indicated.

ActiveLast revised 2026-07-14
TechCloud platformAreaPatch prioritizationRisk acceptance
SeverityMedium
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Cloud credential incident responseCRT-2026-00542026.07.10Afternoon roundtable5 references

Handle reported cloud and source-control secret exposures as control-plane credential incidents

Treat reported AWS, GitHub, GovCloud, Azure, and Accenture-style secret exposures as cloud control-plane credential incidents: rotate AWS/Azure keys and tokens, invalidate sessions, contain high-risk CI/CD and automation paths, review IAM privilege chains across S3/ECS/SQS/source control, quarantine exposed repositories and forks, and validate whether claimed leaked secrets were usable.

Reported cloud, source-control, and CI/CD secret exposures should be handled first as control-plane credential incidents: rotate or revoke keys and tokens, invalidate sessions, contain high-risk automation, review IAM and source-control privilege paths, and quarantine exposed repositories where needed. Third-party leak claims, live usability, and downstream client impact should be validated before being stated as confirmed.

ActiveLast revised 2026-07-10
TechCloud platformAreaRisk acceptanceVulnerability
SeveritySeverity was not recorded when this record was first published.
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Amazon Q/AWS developer tooling malicious-repository exposureCRT-2026-00172026.06.28Afternoon roundtable6 references

Treat Amazon Q/AWS developer-tool malicious-repository exposure as a same-day affected-fleet action

For affected developer fleets, inventory Amazon Q Developer and AWS Language Server usage, apply available updates or disable affected tooling, review untrusted repositories for reported `.amazonq/mcp.json` or unexpected MCP/tool execution, check for exposed cloud or SSH credentials, and restrict AI coding agents from auto-loading untrusted workspace tool configuration.

Organizations using Amazon Q Developer or AWS Language Servers should treat reported malicious-repository/tool-configuration exposure as a same-day developer-fleet check: inventory the tooling, apply available updates or temporarily disable affected integrations, review untrusted repositories for `.amazonq/mcp.json` or unexpected MCP/tool execution, check for exposed developer cloud or SSH credentials, and prevent AI coding agents from auto-loading untrusted workspace tool configuration.

ActiveLast revised 2026-06-28
TechCloud platformAreaPatch prioritizationVulnerability
SeverityCritical
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Software supply-chain CI/CD containmentCRT-2026-00152026.06.28Morning roundtable8 references

Package Compromise Should Trigger CI/CD Secret Rotation and Build Containment

For suspected Miasma/Shai Hulud-style package compromise, freeze suspicious dependency changes, block affected package execution paths, audit npm/PyPI/Go lockfiles and GitHub Actions, rotate CI/CD, GitHub, package-manager, AWS and Redshift secrets, and inspect developer machines and runners for secret theft.

When package compromise is suspected in npm, PyPI, Go or CI/CD paths, freeze suspicious dependency changes, contain affected build paths, rotate workflow, package-manager and cloud secrets, and inspect runners and developer endpoints. Use known or suspected indicators pending local validation; do not imply this packet contains a complete IOC list.

ActiveLast revised 2026-06-28
TechCloud platformDevOps supply chainAreaSupply chainVulnerability
SeverityCritical
ConfidenceHigh confidence · 0/9 backed · 2 gaps
AWS AiTM IAM containmentCRT-2026-00132026.06.28Morning roundtable6 references

Suspected AWS AiTM Exposure Requires Same-Day IAM Containment

Treat suspected AWS AiTM credential/MFA capture as potential active session or token exposure: revoke sessions, invalidate tokens, rotate access keys and console credentials, inspect IAM persistence and console/API activity, and harden conditional-access and break-glass controls.

When AWS AiTM credential or MFA exposure is suspected, contain as if active sessions or tokens may be exposed: revoke sessions, rotate credentials and keys, inspect IAM changes and console/API activity, then harden access controls.

ActiveLast revised 2026-06-28
TechCloud platformAreaSOC escalationThreat actor
SeverityCritical
ConfidenceHigh confidence · 0/9 backed · 2 gaps

Unified Search

Search the public record.