Here’s the curated hit list of what mattered this week for system admins, network engineers, cybersecurity folks, cloud practitioners, and anyone keeping the lights on.
Ryanair signed a five-year Google Cloud AI partnership, layering Gemini Enterprise and DeepMind models onto its existing AWS estate for crew scheduling and operations across 35,000 staff. Multi-cloud just got more real for one of Europe’s biggest airlines. Computer Weekly
Cloud security report from Intruder’s 2026 Cloud Security Index (based on ~3,000 orgs) showed almost no overlap in top misconfigurations across AWS, Azure, and Google Cloud. AWS led in several categories (e.g., 87% of accounts with S3 buckets not enforcing HTTPS, high rates of permissive firewalls and public exposure). Multi-cloud teams face different remediation playbooks for similar risks. SecurityBrief
Google Cloud outlined its post-quantum cryptography roadmap with key milestones aimed at 2027–2029 readiness. SecurityWeek
Microsoft’s August 2026 Patch Tuesday addressed hundreds of CVEs (reports ranged ~400–570), including at least one actively exploited Windows zero-day (use-after-free in afd.sys / related privilege-escalation issues). Additional zero-days and PoCs (including “ShieldBreak” and others) appeared around the same time. Patch early, test thoroughly. SecurityWeek / BleepingComputer
Critical VMware vCenter Syslog Server RCE (CVE-2026-59310) was exploited in the wild within days of disclosure for reverse SSH persistence. BleepingComputer / Infosecurity Magazine
Unpatched GeoServer SQL injection zero-day (leading to RCE under certain conditions) saw active exploitation attempts shortly after public disclosure. The Hacker News / SecurityWeek
SharePoint authentication-bypass / RCE issues continued to see exploitation after PoC release; CISA and others flagged related activity. Multiple reports of ransomware groups targeting similar enterprise software. The Hacker News
Notable breaches: RingCentral (ShinyHunters, ~1.6M accounts), Beacon CRM impacting 1,000+ UK charities (compromised AWS access key in public JS artifacts), and others. Classic credential hygiene failures. BleepingComputer / SecurityWeek
AWS continued rolling out AI-assisted security capabilities (GuardDuty investigation agent in preview, Continuum for automated vulnerability lifecycle, Security Agent expansions). Useful for reducing mean-time-to-investigate. [The Cloud Pod / related coverage]
AWS Lambda added self-managed code storage from customer S3 buckets (easing the previous 75 GB regional limit for some use cases).
Cloudflare introduced temporary accounts for AI agents and open-source agent skills for Zero Trust deployment.
Ongoing cloud market data showed continued strong growth for Google Cloud (high YoY percentages reported in recent quarters) alongside heavy AI-related capex across the hyperscalers.
Prioritize Patch Tuesday testing for the Windows zero-day(s) and any remaining SharePoint / vCenter instances.
Audit multi-cloud IAM, public exposure, logging, and encryption settings—provider-specific gaps mean a single checklist won’t cut it.
Rotate and monitor cloud access keys aggressively; several recent breaches started with exposed keys in build artifacts or JS.
Review AI agent permissions and longer-lived runtimes (e.g., AWS AgentCore notes) for credential and session hygiene.
This week’s unofficial award goes to the ransomware affiliate who rebooted into Safe Mode to disable EDR… and then couldn’t finish the job cleanly. Sometimes the best defense is the attacker’s own over-engineering.
Stay patched, stay multi-cloud-aware, and may your monitoring dashboards remain green(ish). Share your biggest “oh no” of the week in the comments—misery loves company (and good incident response notes).

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.