Cloud Security Office Hours Banner

Friday, August 21, 2026 - Meeting Recap

Cloud Security Office Hours Update

- Cloud Security Office Hours Update

Quick recap. This was a Cloud Security Office Hours meeting where participants discussed various cybersecurity topics and shared updates. Shawn announced that the website had been updated with expanded kill chain content covering 45 different kill chains based on practitioner feedback. Stryker shared that he was recently let go from Fable Security and is looking for new opportunities, particularly in CTI (Cyber Threat Intelligence) roles. Jay presented research on AI models used in code generation, demonstrating how bias can be embedded in generated code, particularly showing problematic examples where models incorporated gender-based pay gaps and other discriminatory practices. The group also discussed the upcoming FlareOn CTF challenge, with Matt providing details about the reverse engineering competition. Stryker concluded by sharing findings from his report on AI-enabled employees, analyzing behavior patterns across 270,000 employees and 32 environments, which revealed interesting correlations between AI usage and risky behaviors like unsafe browsing and phishing clicks, particularly among legal professionals.

2026-08AIGuest Speaker
Show 5 discussion topics

Cloud Security Office Hours Update

Shawn led a Cloud Security Office Hours meeting, discussing recent updates to the website including expanded kill chains content and the deployment of automatic cloud hosting across three platforms. He announced that all previous hosting services had been canceled as the site is now fully deployed across AWS, Azure, and Google Cloud. The meeting served as an open networking session where participants could introduce themselves and ask questions, with several attendees including Marcello and Stryker sharing updates about their career moves and rejoining the community.

Security Vendor Growth Discussion

The meeting participants discussed the growth in the number of security vendors, with Marcello noting that 562 vendors were transacted in 2025 and expecting an increase to around 700 by 2026. Stryker shared his recent job change and search for new opportunities, particularly in cyber threat intelligence (CTI), and mentioned an upcoming report on AI-enabled employees' behaviors that the Wall Street Journal has shown interest in. The group also discussed a Signal chat group for cloud security support and shared information about accessing it.

AI Code Generation Bias Research

Jay presented research on AI models used in code generation that can embed bias, finding that even smaller models commonly used in autocomplete generators exhibit problematic behavior. The team tested multiple language models including GPT, Gemini, and Claude, discovering that while larger models show some improvement, cheaper models perform worse and all models contain bias that security tooling fails to detect. Jay noted that while the examples are concerning, the research shows progress as larger models are performing better, though the testing needs to be expanded to more models and languages.

Stryker's Severance and FlareOn CTF

Stryker discussed his severance package from a startup, explaining that he received 6 weeks total (2 weeks working, 4 weeks after) as part of a reputational strategy while the company is actively hiring. Matt announced the upcoming FlareOn CTF Challenge 13 starting in 35 days, describing it as a month-long reverse engineering competition involving assembly code and various binary formats, with no tool restrictions but requiring solo participation.

Reverse Engineering and AI Security

The group discussed reverse engineering and decompilation skills, with Rev expressing interest in learning more about reading assembly code after hearing about its practical applications. Matt and Shawn shared resources including Flare's Learning Hub malware analysis course and mentioned tools like IDA Pro and Binary Ninja for decompilation work. Stryker presented findings from an AI security report showing that only 34% of employees were detected using AI at work, compared to 50% in surveys, and highlighted how lawyers showed particularly high risky behavior rates due to their job requirements involving frequent email interactions and document handling.

↑ All meeting recaps