// field notes

Insights

A weekly, opinionated digest of what actually mattered in cloud, security, AI, and automation — with a practitioner's read on each.

Field Notes — Week of August 2, 2026

A public PoC turns an AD CS enrollment quirk into full domain takeover, JetBrains ships an emergency fix for an unauthenticated RCE in TeamCity's CI/CD server, Google Cloud flips Looker MFA on by default, and Cognizant stands up an EMEA unit aimed squarely at the 88% agent-pilot failure rate.

securityautomationcloudai

Field Notes — Week of July 26, 2026

A fourth SharePoint RCE (CVE-2026-50522) goes from public PoC to machine-key theft in hours, AWS quietly removes two long-standing migration frictions in S3 and Cognito, OpenAI's GPT-5.6 family lands GA on Bedrock behind the Responses API, and AWS starts shipping agent-native tooling straight into the build-and-deploy loop.

securitycloudaiautomation

Field Notes — Week of July 20, 2026

Microsoft ships a record 569-CVE Patch Tuesday with SharePoint and AD FS zero-days under active attack, AWS Summit NYC turns cross-cloud management into a first-party feature by folding Azure into Security Hub and Systems Manager, GitHub enforces immutable OIDC subject claims while backporting a secure-by-default fix for pwn requests, and the 2026 State of AI Agents numbers land hard — 96% running agents, 12% able to govern them.

securitycloudautomationai

Field Notes — Week of July 12, 2026

Adobe ColdFusion's CVSS 10.0 RCE (CVE-2026-48282) hits the wild two hours post-disclosure, Microsoft's Defender flaw grants SYSTEM privileges via RoguePlanet, Patch Tuesday swells to 220+ critical flaws across Windows, AWS hardens security automation with AI-native vulnerability discovery and OAuth-gated MCP access, and enterprise AI agents hit the governance wall with 88% of orgs reporting incidents despite production adoption at 72%.

securitycloudaiautomation

Field Notes — Week of July 5, 2026

CISA puts SharePoint and Splunk on emergency-patch clocks while a CVSS 10.0 SimpleHelp auth bypass gets exploited in the wild, AWS goes all-in on public-sector AI at its D.C. Summit, Gartner sizes agent software at $206.5B against an 88% incident rate, and the npm worm era keeps validating GitHub's pipeline-hardening roadmap.

cloudsecurityaiautomation

Field Notes — Week of June 28, 2026

A Check Point VPN zero-day that ransomware crews were riding a month before the patch, Google making cross-cloud location data a first-class API, the agentic-AI buying cycle hitting its governance wall, and Terraform and OpenTofu both shipping point releases in the same week. The week's signal, with a practitioner's read on each.

cloudsecurityaiautomation

Field Notes — Week of June 22, 2026

A PeopleSoft zero-day that gutted higher ed before Oracle even shipped an advisory, AWS turning incident response into an autonomous agent, Pulumi planting a flag on Terraform's own turf, and JPMorgan moving AI spend into the same budget line as data centers. The week's signal, with a practitioner's read on each.

cloudsecurityaiautomation

Field Notes — Week of June 17, 2026

A Check Point VPN zero-day already in ransomware hands, the cloud providers quietly attacking egress fees, KPMG putting agents into production with guardrails, and OpenTofu dropping the DynamoDB lock table. The week's signal, with a practitioner's read on each.

cloudsecurityaiautomation