Skip to content

Posts tagged

#cloud

17posts

August 2026
  1. 27Aug
    Ground TruthEssay
    CSA's 2026 Top Threats: Identity Beats Infrastructure, AI Shows Up Twice
    Cloud Security Alliance ranks inadequate IAM — driven by non-human identity sprawl — as the #1 cloud threat for 2026, with two AI-related risks debuting on the list. What actually changed, and what it means for cloud teams.
    5 min read
July 2026
  1. 27Jul
    Ground TruthCase Study
    Malaysia's Military AI Push: Sovereign Ambition, Cloud-Security Blind Spots
    TactiDrone's offline AI is a quiet admission about cloud-dependent C2 risk. The same gaps that plague government cloud security — talent shortage, silos, corruption risk — also bottleneck Malaysia's military AI.
    9 min read
  2. 15Jul
    Cloud SecField Note
    Shift-Left → Auto-Remediation → Agentic Remediation: The 2026 Vendor Landscape and a Palo Alto Cortex Cloud Deep Dive
    From Checkov blocking PRs in CI to AI agents executing one-click fixes across code, cloud, and SOC — a vendor-by-vendor map of how cloud security moved from finding issues to fixing them, and where Palo Alto's Cortex Cloud platform sits in the race.
    9 min read
  3. 13Jul
    Ground TruthCase Study
    Malaysia's Military AI Infrastructure 2026 — Case Study and Threat Scenarios
    PSPN 2026-2030, PSEP Cyber Command, STRIDE drone framework, CL-STA-1062 attacks on ASEAN critical infrastructure, TNB AI grid, and NACSA's Cryptology Centre — a case study on how Malaysia is building and defending military AI infrastructure amid real 2026 threats.
    7 min read
  4. 12Jul
    Ground TruthEssay
    The World Is Writing AI Law — What Engineers Actually Need to Know
    EU AI Act enforcement began Feb 2025. Malaysia is finalising an AI Governance Bill. ASEAN has its own frameworks. Regulation is shaping how we build AI — whether we are paying attention or not. A guide for engineers.
    6 min read
  5. 11Jul
    Ground TruthEssay
    Guardrail Vendors vs Production Reality — What AWS, Azure and Google Don't Tell You
    AWS Bedrock Guardrails, Azure AI Content Safety, Google Vertex AI Safety — all look solid in documentation. But in production, there are real gaps between vendor promises and actual protection. Data from Palo Alto Unit42, AML bypass research, and production latency benchmarks.
    7 min read
  6. 10Jul
    Ground Truth
    Ground Truth
    Essays and case studies on the global cloud security and AI guardrail engineering landscape — perspective, analysis, and real threat scenarios from a Malaysian and ASEAN context.
    1 min read
  7. 10Jul
    Ground TruthEssay
    Identity Is the New Perimeter — Lessons from Snowflake, MGM and Scattered Spider
    In 2024, UNC5537 stole data from 165 Snowflake customers without exploiting a single vulnerability. In 2023, Scattered Spider paralysed MGM in a 10-minute phone call. This is not a technical attack story — it is the new era where identity is the only perimeter left.
    5 min read
  8. 08Jul
    Military AIField Note
    Malaysia & Defence AI: Left Behind or Being Careful?
    Singapore has deployed autonomous drones, DSTA runs AI detection systems — and Malaysia? We need to ask this question honestly: where do we stand, and where should we go?
    7 min read
  9. 07Jul
    Military AIField Note
    AI on the Battlefield: Project Maven, Drone Swarms & JADC2
    From thousand-unit drone swarms to AI targeting systems making decisions in milliseconds — AI has transformed warfare. This isn't science fiction. It's happening now.
    5 min read
  10. 07Jul
    Military AI
    Military AI & Defence
    Field notes on AI in defence — from autonomous battlefield systems and drone swarms, to the hard question: where does Malaysia stand in this landscape?
    1 min read
  11. 06Jul
    AI GuardrailField Note
    open source AI agent OS — Goose and the 2026 agentic ecosystem
    Goose by Block (now under Linux Foundation), Alibaba's Anolis AgenticOS, and the open source agentic AI stack shaping how agents run, deploy, and get secured.
    6 min read
  12. 06Jul
    Cloud Sec
    Cloud Security Engineering 2026
    Field note series on Cloud Security Engineering — shifting skills, modern tooling, and how engineers navigate a landscape that has converged with AI and agentic systems.
    1 min read
  13. 03Jul
    AI GuardrailField Note
    cloud, AI, agentic OS — 2026 trends for Gen Z
    Cloud security has shifted to intent filtering. AI has become an agent. Agents have become an OS. Four trends Gen Z needs to understand now.
    12 min read
  14. 02Jul
    Cloud SecField Note
    cloud security baseline — the foundation that needs to be right from day one
    Cloud Security Baseline (CSB) is the minimum set of controls that must exist before the first workload deploys. Here's the practical breakdown — from CIS Benchmarks, drift detection, to automatically enforcing baseline.
    5 min read
  15. 01Jul
    Cloud SecField Note
    becoming a cloud security engineer in 2026 — skills that have shifted
    The role of cloud security engineer has changed more in 2 years than in the 5 years before. Here's an honest breakdown: what's stayed the same, what's changed, and what new skills you need now.
    7 min read
June 2026
  1. 30Jun
    Field Note
    young Malaysian talent on the cloud & AI stage
    Gen Z Malaysia is building, not just using. Cloud, AI, open source — talent is there, it's just quiet.
    3 min read