- Black Hat debrief and detecting shadow AI
The Cloud Security Office Hours meeting began with Shawn greeting the group from his vacation at Disney World before handing over hosting duties to Dave.
Read recap →Cloud Security Office Hours

Topic-by-topic recaps from 107 weekly CSOH sessions. Search by topic or speaker, click any recap to read the full discussion. Want the synthesis instead of the chronology? What Practitioners Actually Think reads back across this archive one topic at a time.
Every recap below was written by a community member, not a marketer. - how this archive stays useful
107 meetings, newest first.
No meetings match your search.
The Cloud Security Office Hours meeting began with Shawn greeting the group from his vacation at Disney World before handing over hosting duties to Dave.
Read recap →The meeting was an open office hours session led by Neil, with Shawn and others joining for discussions on cloud security, AI, and related topics.
Read recap →Rohit Valia from Tumeryk presented on AI trust scoring and the Cloud Security Alliance's new risk rubric for AI. Rohit explained Tumeryk's platform for evaluating AI models across six pillars: security, privacy, reliability, excessive…
Read recap →The Cloud Security Office Hours session focused on open discussions about cloud security challenges, particularly around vulnerability management and the evolving landscape of prioritizing and remediating vulnerabilities.
Read recap →The session ranged across AI-assisted phishing, threat-intel attribution, and cloud cost control. It began with introductions for new attendees, including Kelsey from Minimus and Daniel, a recent Information Technology and Informatics…
Read recap →The session worked through a publicly reported industry controversy over a security company's alleged contact with a threat actor, using it to examine the ethics and real risks of researchers engaging threat actors and the field's…
Read recap →The conversation centered on governing AI in the enterprise - token limits, usage tracking, and the reality that these tools were not designed with enterprise security controls in mind - and widened into whether fines or personal…
Read recap →The 177th session opened on Fortinet's run of zero-days and why perimeter vendors keep drawing nation-state attention, then moved to practical AWS posture tooling.
Read recap →New members joined from Kansas City to Budapest, and the main thread was asset management in the cloud - specifically how organizations inventory and secure GitHub repositories at scale.
Read recap →The group worked through Anthropic's white paper on securing AI agents and applying zero-trust principles to non-deterministic agents, debating whether it offered practical guidance or mostly framing.
Read recap →The 175th session dug into how enterprises are actually governing AI use - MDM controls, proxies, and AI gateways to enforce acceptable-use policies - and the widening gap between promised and real token costs as newer models get less…
Read recap →The session dug into a hard, current problem: how to secure and scan the skills that power generative-AI agents. Neil laid out three code-scanning approaches - CI/CD integration, external secret scanners like GitGuardian, and secured…
Read recap →This session was a wide-ranging discussion of the human side of security: social engineering, user behavior, and why technical controls alone cannot carry the load.
Read recap →The Cloud Security Office Hours meeting focused primarily on discussions about data backup strategies and security implications of AI agents. The group extensively discussed recent security breaches, including the Instructure/Canvas…
Read recap →This meeting was Cloud Security Office Hours, where participants discussed recent website updates and shared insights on cloud security practices. Shawn presented new navigation and content sections on the website, including "What Is…
Read recap →The Cloud Security Office Hours meeting focused on discussions about AI token usage and supply chain security threats. Participants, including Tyler, Stryker, and Neil, debated the merits and challenges of "token maxing" in AI…
Read recap →The Cloud Security Office Hours meeting focused on discussing recent developments in AI's impact on cybersecurity, particularly around Microsoft's Mythos AI tool and its potential to accelerate vulnerability discovery and exploitation.…
Read recap →The meeting focused on discussing the current crisis in open source security, particularly regarding supply chain attacks and the impact of generative AI tools like Claude on vulnerability research. Participants, including Neil, Jay,…
Read recap →Cloud Security Office Hours featured discussions about conference experiences, particularly RSA and Black Hat, with participants sharing insights about networking, speaking opportunities, and career development in cybersecurity. The group…
Read recap →The meeting focused on discussing the recent Light LLM security compromise, where a Python package used by 97 million monthly users was compromised, leading to the theft of credentials and sensitive information from affected systems. The…
Read recap →Guest speaker Maria Thomas (digital investigator with the RISE Information Security Foundation, background in behavioral science) presented on the behavioral science behind online harassment - why people pile on, how anonymity shapes…
Read recap →The meeting focused on several key topics, including the recent acquisition of Wiz by Google and its implications for the company and its employees. Participants discussed the potential risks and benefits of this acquisition, with some…
Read recap →The meeting focused on discussing a critical Java authentication vulnerability and its implications for organizations. Participants shared their experiences with patching and vulnerability management, emphasizing the importance of…
Read recap →The Cloud Security Office Hours meeting focused on discussing password security practices and the importance of asking questions in technical environments. Tyler shared insights about using AI agents for software development and testing,…
Read recap →The meeting focused on reviewing and contributing to the Cloud Security Office Hours website, with participants discussing GitHub workflows, pull requests, and website improvements. New members introduced themselves, including Pavel from…
Read recap →The Cloud Security Office Hours community celebrated its 3-year anniversary, with Shawn highlighting the growth of the global participant base and introducing a new website built using AI that is now community-editable via GitHub. The…
Read recap →The Cloud Security Office Hours meeting began with introductions and casual conversation before transitioning into a discussion about AI's role in coding and development, including both its benefits and potential risks. The group explored…
Read recap →The meeting began with informal discussions before transitioning into Cloud Security Office Hours, where new participants introduced themselves and shared their backgrounds in cybersecurity and security architecture. The group engaged in…
Read recap →The meeting opened with informal greetings and casual conversation about weather conditions before transitioning to a discussion of Cloud Security Office Hours and its objectives for networking and knowledge sharing. The group reviewed…
Read recap →The meeting began with casual greetings and technical discussions about screen-sharing issues before transitioning into conversations about the upcoming RSA Conference 2024 and organizing a Cloud Security Office Hours breakfast meeting.…
Read recap →The Cloud Security Office Hours meeting focused on discussions about management styles and experiences, with participants sharing personal stories about their bosses and leadership challenges. The group discussed the importance of…
Read recap →The meeting began with informal discussions about attendance and personal updates before transitioning into conversations about LinkedIn networking strategies and social media engagement. The group explored cultural differences between…
Read recap →The meeting focused on discussing predictions for 2026 in cloud security, with participants sharing various forecasts about emerging threats, technology trends, and market developments. The group explored specific predictions including…
Read recap →The meeting focused on networking and career development in cloud security, featuring David Bradford, a former General Counsel at Novell, who shared his experiences and principles for building professional relationships. David emphasized…
Read recap →The meeting began with introductions and networking opportunities, welcoming Cole to the team and setting the stage for a collaborative session. The main focus was a GitHub and Mindset Dojo session aimed at demystifying open source…
Read recap →The meeting began with casual conversation about travel plans and experiences, including discussions about upcoming trips to Prague and European destinations. The Cloud Security Office Hours meeting welcomed new participants and addressed…
Read recap →The meeting began with casual conversation about Thanksgiving experiences and holiday attendance before transitioning into a discussion about cybersecurity challenges faced by seniors and various network security solutions. The group…
Read recap →The meeting began with discussions about building a religion and welcoming new participants, including a GitHub walkthrough session and potential new group member James Frasotti. The group explored leadership transitions and management…
Read recap →The meeting began with casual conversation and music sharing before transitioning to discussions about virtual meeting filters and a humorous charity rule about AI mentions. The main focus was on open source security challenges, including…
Read recap →The meeting began with introductions of new participants and discussions about cloud security and the importance of proactive cybersecurity approaches. The group then examined the Google Mandiant report on AI malware and discussed various…
Read recap →The meeting began with casual conversation about Halloween costumes and music before transitioning to introductions and updates from the Cloud Security Office Hours community. Community leaders shared their backgrounds and experiences,…
Read recap →The meeting began with casual discussions about cybersecurity awareness and included an introduction to Cloud Security Office Hours, welcoming new participants and encouraging networking. The group explored the importance of building and…
Read recap →The meeting began with introductions and discussions about cloud security tools, including experiences with Wiz's incident response capabilities and challenges in securing AI agents. The group explored issues around security reporting and…
Read recap →The meeting began with casual discussions about music and song genres before transitioning to a conversation about polymorphic malware and cybersecurity, featuring an introduction of Andrea Pullman and her work with Cyberjutsu. The group…
Read recap →The meeting began with casual conversation and introductions before transitioning into a discussion about cloud security and job searching strategies, including advice on networking at security conferences and using technology like QR…
Read recap →The meeting began with Shawn Nunley sharing audio clips with abstract lyrics before transitioning into personal and professional updates from various team members, including discussions about business planning and website development. The…
Read recap →The meeting began with a monologue by Shawn Nunley discussing technical topics related to cryptocurrency and hacking, followed by a discussion about an upcoming event and its promotion plans. The group then covered various professional…
Read recap →The Cloud Security Office Hours meeting welcomed new participants and focused on networking opportunities while discussing various technical topics including threat modeling, AI security frameworks, and cloud security tools. The group…
Read recap →The meeting began with casual conversation and introductions before transitioning into discussions about cloud security and vendor-neutral approaches to cybersecurity. The group explored challenges and implementations related to AI in…
Read recap →The meeting began with a technical discussion focused on security measures and threat detection protocols, including discussions about logging, access controls, and incident response. Alhaji Bah shared his personal journey from HR to…
Read recap →In this Cloud Security office hours meeting, Shawn welcomed participants to a safe discussion space before Stryker presented her DEF CON session on building a DIY threat intelligence platform, explaining that commercial platforms can cost…
Read recap →In this Cloud Security Office Hours meeting, Shawn and Dave discussed their upcoming presentation for a megaport event, debating whether to focus on cloud architecture or security challenges, while also welcoming Alex who shared news…
Read recap →The meeting began with a discussion about the origins of the Russia investigation into Donald Trump, including media coverage and potential influences from intelligence officials and the Obama administration. Personal experiences with…
Read recap →Patrick Burke (Chainguard, Solutions Engineer) presented on minimal container images - what they are, why vulnerability trends are driving adoption, and how they compare to traditional patching, golden-image programs, and debloated…
Read recap →The meeting began with introductions for new participants in the Cloud Security Office Hours, where participants shared their backgrounds and interests in cloud security. Technical difficulties with audio and screen sharing were…
Read recap →The meeting covered a wide range of topics, including cybersecurity challenges, AI developments, and personal experiences in the tech industry. Participants discussed the complexities of hiring individuals with criminal backgrounds in…
Read recap →The meeting began with introductions and discussions about rotational programs in cybersecurity, followed by an in-depth exploration of Geico's Cyber Defense Practitioner program and its onboarding process. The group then delved into…
Read recap →The meeting covered a range of topics including attendance patterns, weather conditions, cloud security, and data governance. Discussions focused on AWS's annual cloud security conference, sovereign cloud approaches in Europe, and…
Read recap →The meeting covered a range of topics related to cloud security, AI adoption, and cybersecurity challenges. Discussions included the evolution of ransomware, the implications of AI in security and education, and the limitations of Large…
Read recap →The meeting began with birthday celebrations and introductions of new participants, followed by discussions about potential future presentations and networking opportunities within the cloud security community. The group then addressed…
Read recap →The Cloud Security Office Hours meeting welcomed new participant Aimee and focused on community building through networking and learning initiatives, including plans for a Capture the Flag event. The group discussed various technical and…
Read recap →The meeting began with informal introductions and discussions about transitioning into cloud security roles, followed by Matt Chiodi sharing his career journey from CISO to COO and the importance of mentorship in professional development.…
Read recap →The meeting began with introductions from the Cloud Security Office Hours hosts and participants, who shared their backgrounds and experiences in cloud security. The group engaged in discussions about career development, emphasizing the…
Read recap →The meeting began with casual conversation between attendees before transitioning to a formal presentation by Jay Seirmarco, a lawyer with expertise in technology and AI. Jay presented on the intersection of cybersecurity, contracts, and…
Read recap →The meeting began with personal updates and introductions, including a recruiter offering job opportunities in cybersecurity. The group then discussed cloud governance strategies, focusing on Azure infrastructure, security measures, and…
Read recap →The team discussed the upcoming Cloud Security Office Hours and welcomed new attendees, with Stryker sharing his personal project of using AI to create song lyrics. Neil Carpenter shared his experiences in the vulnerability management…
Read recap →The meeting focused on various topics including cybersecurity, AI, and coding, with participants sharing their experiences and insights on these subjects. The group discussed the challenges of implementing effective cybersecurity measures…
Read recap →The Cloud Security Office Hours meeting covered a range of topics in cybersecurity, including networking opportunities, sales challenges in the industry, and technical discussions on Kubernetes security. Participants shared insights on…
Read recap →The meeting covered a wide range of topics, including discussions on security vulnerabilities, AI and machine learning applications, and developer access to security tools. Special guests shared their experiences with finding and…
Read recap →The security officers' meeting covered a range of topics including cloud infrastructure challenges, learning strategies for AWS and cloud technologies, and implementing data loss prevention in Azure. Participants discussed the importance…
Read recap →The team discussed the recent Oracle security breach and its potential impact on Oracle's customers, emphasizing the importance of having a well-prepared incident response plan. They also explored various approaches to improve…
Read recap →The meeting covered various cybersecurity topics, including identity and access management challenges, cloud security issues, and recent vulnerabilities. Discussions also focused on the evolution of cybercriminal enterprises, particularly…
Read recap →The team discussed the potential acquisition of Wiz by Google, with Shawn expressing optimism about the impact on employees and Neil sharing his concerns about past acquisitions. They also discussed the increasing risks of supply chain…
Read recap →The meeting covered a wide range of topics, including group activities, cloud platform challenges, and the intersection of politics and corporate security. Discussions also focused on Apple's encryption decisions, quantum security, and…
Read recap →The Cloud Security Office Hours meeting welcomed participants from diverse backgrounds and discussed various aspects of cloud security. The group explored topics such as transitioning into cloud security careers, the importance of…
Read recap →The team discussed various topics including the transition from on-prem to cloud security, the importance of understanding business acronyms, and the potential for AI breakthroughs and its implications on security. They also explored the…
Read recap →Mario discussed the timeline for making a request and the transition of PM duties, while also recommending additional test data for edge cases. Justin and Ben presented on discovery enablement to a group of employees, focusing on new…
Read recap →The meeting covered a range of topics including introductions of new members, discussions on resume writing and formatting, and career advice for professionals in the cloud security field. The team shared insights on maintaining…
Read recap →The team discussed the challenges and opportunities of making career pivots, particularly in fields like cloud computing and cybersecurity, and the importance of networking and knowledge sharing. They also explored the challenges of…
Read recap →The meeting involved a diverse group of professionals discussing their experiences and interests in cloud security, with a focus on the potential impact of AI on their work and the future of technology. They discussed the potential…
Read recap →Shawn led a series of seemingly unrelated discussions covering various topics, including academic world, fashion, family, dreams, industry, and more. The team also discussed the potential implications of the current administration's…
Read recap →The meeting involved discussions on the use of AI models, with a focus on the risks associated with them and the importance of protecting enterprise data privacy. The team also explored the potential risks and benefits of using private…
Read recap →Shawn and Ian discussed the importance of networking and making connections, with Ian presenting on his role as the Azure Cloud Community Leader at Cis and the development process of the CIS benchmarks. The team also discussed the CIS…
Read recap →The meeting began with a recitation of song lyrics and casual conversation before transitioning to a presentation by Etay Haral on cloud detection engineering, focusing on role unchaining in AWS and the challenges of tracing activities…
Read recap →The team discussed their personal experiences and preferences for different operating systems, with a focus on Windows and Mac. They also explored the challenges and benefits of using these systems in a corporate environment, with a…
Read recap →The team discussed their personal experiences and emotions, with Shawn expressing his love and longing for someone. They also explored the potential and challenges of AI, with discussions on its use in INFOSEC, network fault detection,…
Read recap →The team discussed various topics including the use of AI recording, security updates, the value of certifications in cybersecurity, and the potential of home labs for learning. They also emphasized the importance of networking, building…
Read recap →The team discussed the importance of considering the self-selected nature of data in security reports, particularly in relation to AI models and cloud security solutions. They also explored the vulnerabilities in AI packages and…
Read recap →The team discussed various topics including acquisitions and mergers in the cybersecurity sector, the challenges of integrating new technologies into existing systems, and the potential impact of acquisitions on customers. They also…
Read recap →Shawn initiated the meeting, encouraging new members to introduce themselves and discussed the potential of a new website for learning and sharing. Brandon presented on the workings of the scan engine, his role in the underwriting…
Read recap →The meeting began with introductions and discussions about the revamped website and the importance of networking within the group. The team also shared their experiences and challenges in the field of cloud security, with a focus on the…
Read recap →The team discussed various security issues, including Chinese groups targeting firewalls, the high number of known exploited vulnerabilities in Microsoft, and the use of remote desktop protocol for spear phishing campaigns. They also…
Read recap →The team discussed the challenges and differences between on-premises and cloud-based systems, with a focus on security and infrastructure, and the importance of building resilient architectures. They also shared their personal…
Read recap →The team discussed the evolution of application development, the benefits and challenges of using containers, and the differences between running containers on AWS using ECS and EKS. They also explored the concept of abstraction in…
Read recap →The team discussed personal experiences, technological challenges, and industry trends, including climate change's impact on the tech sector and the use of containers in enterprise environments. They explored auto remediation, its…
Read recap →The team discussed the transition to cloud security, with Saubhagya expressing interest in learning more about securing their cloud infrastructure. They also discussed recent fines imposed on T-Mobile by the FCC and the potential for…
Read recap →The team discussed the potential of AI to enhance work capabilities and the risks associated with it, including the potential for AI to replace certain jobs. They also discussed a recent vulnerability and the development of a new…
Read recap →The team discussed the challenges and potential solutions in managing Multi-Factor Authentication (MFA) for shared accounts, with a focus on the use of FIDO keys and the protection of SIM cards. They also explored the evolving roles in…
Read recap →The team discussed the challenges and benefits of their children's schooling in Singapore, sales kickoff events, and issues with neighborly dumpster use. They also shared personal experiences and insights on the impact of extensive…
Read recap →The team discussed recent vulnerabilities in AWS, the need for improved security policies, and strategies to limit cloud storage sprawl. They also explored the challenges and evolving strategies in cloud detection and response, the…
Read recap →The team discussed the ongoing issues with the Crowdstrike incident, the impact of outdated systems on ATM performance, and the challenges of dealing with nation state actors' malware. They also explored potential solutions, including the…
Read recap →The team from Equinix discussed recent infrastructure outages, the potential impact on the company's reputation, and the trend of customers preferring to rent server space. They also explored the potential of AI in container…
Read recap →The team introduced themselves, discussed their backgrounds in cloud security, and shared their experiences in physical security assessments using social engineering tactics. Lastly, they explored the responsible use of hardware exploits,…
Read recap →The team discussed their dissatisfaction with the lack of originality and reliance on gimmicks at trade shows, emphasizing the need for vendors to showcase their actual offerings. They also explored the challenges of conveying technical…
Read recap →The team discussed strategies for managing and safeguarding secrets, with a focus on the risks of malicious insiders and the misuse of tools like AWS and Google CLI. Lastly, they explored the implications of the acquisition of HashiCorp…
Read recap →The team discussed issues related to heavy rainfall, cloud security, and supply chain concerns, with a focus on the XZ backdoor and the Microsoft SSH login issue. They also delved into the job interview process, with Josef drawing…
Read recap →The group discussed Steven's transition into a senior security engineer role, emphasizing the need for guidance and mentorship. They also highlighted the importance of networking and keeping up with technological advancements. Jay…
Read recap →