Cloud Security Office Hours Banner

Friday, August 7, 2026 - Meeting Recap

AI's impact on cybersecurity, Microsoft Red Sun zero-day, HSBC password controversy

- Cloud Security Office Hours Meeting

Quick recap. The Cloud Security Office Hours meeting began with Shawn greeting the group from his vacation at Disney World before handing over hosting duties to Dave. The discussion covered recent experiences at Black Hat, where attendees like Neil and Juninho reported a slower show floor and noted the trend of companies coming out of stealth with expensive booths. The group discussed OpenAI's Black Hat session on their security incident, with Juninho sharing his take that it felt more like marketing than a technical deep dive. The conversation then shifted to detecting shadow AI usage, with Artist seeking advice on using Microsoft Sentinel; the group suggested focusing on device inventory, browser behavior, and network egress controls. Other topics included the choice of GitHub over GitLab for open source projects, the challenges of AI models escaping sandboxes, and the difficulties in recruitment and hiring diverse candidates. The conversation ended with participants wishing each other a good weekend.

2026-08AISupply ChainVulnerabilitiesConferences
Show 4 discussion topics

Cloud Security Office Hours Meeting

Shawn opened the Cloud Security Office Hours meeting while on vacation at Disney World, noting the rainy weather affected their plans. Dave mentioned he has a week left before his upcoming vacation to Scotland and Centre Parks. The meeting began with casual greetings and discussions about vacation plans, with Shawn requesting that hosts remove meeting notes from future sessions.

Black Hat Conference Review Discussion

The team discussed their experiences at Black Hat, with Juninho and Neil attending and reporting that the show floor was slower than previous years. They noted that several companies that came out of stealth with expensive booths may not survive next year. The group also reviewed OpenAI's presentation at Black Hat, which detailed their response to model containment breaches, though Juninho expressed some skepticism about the presentation's marketing tone and lack of recommendations for preventing future breaches.

Supply Chain and AI Security

The team discussed recent supply chain attacks, noting a potential trend of attacks occurring during major security conferences when personnel are away. Artist asked about implementing Microsoft Sentinel for detecting shadow AI usage, leading to a discussion about different AI security tools and detection methods. The group explored various approaches including device inventory management, browser behavior monitoring, and network controls, with Neil suggesting that Microsoft Premier customers could leverage their support for guidance on implementing these solutions.

Shadow AI Monitoring Discussion

The group discussed monitoring and managing shadow AI usage in enterprise environments. Alex advised Artist to verify the correct Microsoft logs are being captured, particularly non-interactive sign-in logs and managed identity sign-in logs, and suggested creating specific alerts to detect shadow AI activity. The discussion also covered GitHub as a platform for hosting open source projects, with participants agreeing that while GitHub has experienced outages, it remains the de facto platform for community engagement due to its widespread adoption and available resources. The conversation concluded with a debate about recruitment challenges, particularly around finding diverse candidates and overcoming resume filtering systems that may discriminate against candidates without traditional credentials.

↑ All meeting recaps