<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CloudSecOps Labs</title>
    <link>https://cloudsecops.com/labs</link>
    <description>Cloud and AI security research, tooling, and field guides from CloudSecOps.</description>
    <language>en</language>
    <atom:link href="https://cloudsecops.com/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>What we actually check in an AWS assessment</title>
      <link>https://cloudsecops.com/labs/what-we-actually-check-in-an-aws-assessment</link>
      <guid>https://cloudsecops.com/labs/what-we-actually-check-in-an-aws-assessment</guid>
      <description>The working method behind a CloudSecOps AWS security assessment: 69 checks organised by attack path rather than by service, the evidence request, read-only collection, a severity rubric, and why a benchmark-compliant account can still be three hops from account-wide admin.</description>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Prompt-injection testing methodology</title>
      <link>https://cloudsecops.com/labs/prompt-injection-testing-methodology</link>
      <guid>https://cloudsecops.com/labs/prompt-injection-testing-methodology</guid>
      <description>A repeatable methodology for testing prompt injection in LLM, RAG and agent systems: rules of engagement, test matrix, trial protocols under non-determinism, severity, evidence capture and retest.</description>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>MCP security threat model</title>
      <link>https://cloudsecops.com/labs/mcp-security-threat-model</link>
      <guid>https://cloudsecops.com/labs/mcp-security-threat-model</guid>
      <description>A threat model for Model Context Protocol deployments pinned to specification revision 2026-07-28: trust boundaries, a 41-row threat register with attacker capability and impact per row, three attack trees, and an account of what MCP declines to defend.</description>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Kubernetes guardrails with OPA Gatekeeper</title>
      <link>https://cloudsecops.com/labs/kubernetes-guardrails-with-opa-gatekeeper</link>
      <guid>https://cloudsecops.com/labs/kubernetes-guardrails-with-opa-gatekeeper</guid>
      <description>Writing the constraint is the easy part. An operational guide to running Gatekeeper as admission control you can afford to have fail: fail-open defaults, cold caches, audit blind spots, staged rollout, and the silent-drop bugs that make a green CI run mean nothing.</description>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>DevSecOps practice notes</title>
      <link>https://cloudsecops.com/labs/devsecops-practice-notes</link>
      <guid>https://cloudsecops.com/labs/devsecops-practice-notes</guid>
      <description>Thirty-six field notes on DevSecOps practice: pipeline identity, build provenance, secret blast radius, and vulnerability triage after NVD stopped enriching a third of new CVEs. Each note states the condition under which it stops being true.</description>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Detection engineering in AI-era clouds</title>
      <link>https://cloudsecops.com/labs/detection-engineering-in-ai-era-clouds</link>
      <guid>https://cloudsecops.com/labs/detection-engineering-in-ai-era-clouds</guid>
      <description>Most evidence you need to detect attacks on AI workloads is off by default, billable, capped or sampled. A field guide to the telemetry that exists today.</description>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Automated remediation on AWS</title>
      <link>https://cloudsecops.com/labs/automated-remediation-on-aws</link>
      <guid>https://cloudsecops.com/labs/automated-remediation-on-aws</guid>
      <description>An engineering guide to automated security remediation on AWS: when to automate, why an organization trail plus a service control policy removes most of the CloudTrail-disruption problem before any code runs, and how to build a loop that is idempotent, bounded, reversible and switchable-off.</description>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>AI governance for engineers, not lawyers</title>
      <link>https://cloudsecops.com/labs/ai-governance-for-engineers-not-lawyers</link>
      <guid>https://cloudsecops.com/labs/ai-governance-for-engineers-not-lawyers</guid>
      <description>Translate AI governance into systems you can build: inventory reconciled against runtime telemetry, deployment gates that block, human oversight you can measure, and evidence that survives review. With EU AI Act dates as amended in July 2026.</description>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>