Curated by Marco Lancini Delivered Sundays
◇ The cloud security newsletter

The signal in cloud security,
delivered once a week.

Hand-curated research, tooling, and incidents from across the cloud security landscape. Distilled by a practitioner, read by twelve thousand engineers, CISOs, and founders.

Free · 1× weekly · Unsubscribe in one click
12,000+
Subscribers
7 yrs
Curating weekly
300+
Issues delivered
Email per week
§ Why subscribers stay

7 years of curation.
Zero noise.

01

Hand-picked, never aggregated

Every link gets read by me before it makes the issue. No RSS firehose, no AI summary slop. Just a practitioner choosing what's worth your time.

02

Laser-focused on Cloud Security

You'll get comprehensive coverage, including the latest cloud security research, technical deep dives, tools, major updates from cloud providers, and service updates/releases.

03

Global Reach

Our readers come from different backgrounds and are distributed across the globe. They vary from hands-on security professionals working as security engineers or SOC analysts, to security managers, heads of security, CISOs, CSOs, security founders, senior leaders, and VCs.

Coverage AI Attacks AWS Azure CI/CD Cloudflare Containers Defend Design Detection eBPF GCP GSuite IAC IAM Kubernetes Monitoring OIDC Processes Runtime SAAS Strategy Supply chain Terraform Workload identity Zero Trust
◊ New · AI-powered archive

Ask 7 years of cloud security a question.

Every CloudSecList issue and every CloudSecDocs page is searchable in plain English. Find that runtime detection paper from two years ago, the OIDC misconfiguration write-up, the right open-source scanner. Without scrolling.

Try Ask AI →

Read by the room you want to be in.

§ Testimonials
For those wanting a summary of cloud security news, I strongly recommend CloudSecList by @lancinimarco. He surfaces lots of links I had not seen, all high quality, and does a great job summarizing them.
SP
Scott Piper

“If you're not getting the CloudSecList email digest every Sunday, you're missing out.”

Anthony Randazzo

“After reading for several weeks: CloudSecList by @lancinimarco is an *excellent* source for Cloud Security News!”

Matthias Luft

“If you are in InfoSec and you deal with cloud or k8s, and you're not subscribed to CloudSecList you are doing yourself a disservice.”

Nick Frichette

“If you're into cloud security, this is easily the best newsletter.”

John Grange

“I joined the weekly CloudSecList newsletter in early 2021, and I love it! If you're into cloud security, you want to take advantage of it.”

Adan Álvarez

“CloudSecList is a pretty nice read on Sundays / Monday mornings. Good summaries, links to tools — reminds me of the old SummitRoute emails.”

Pete Markowsky

“Have you checked out the latest CloudSecList newsletter by @lancinimarco? I totally recommend a subscription - todays news collection is again an absolute blast!”

jan harrie

“Most newsletters sit unread in your inbox; some you look forward to reading. CloudSecList, thoughtfully curated by Marco, is top notch — always relevant and high quality.”

IAM Pulse

“CloudSecList's latest newsletter is 🔥. Marco curates the most cloud security relevant stuff in this newsletter.”

InfosecGandalf
§ FAQ

Everything you'd ask before subscribing.

01

What is CloudSecList?

CloudSecList is a newsletter that keeps thousands of security professionals informed about current happenings and news related to the security of cloud-native technologies.
02

How often will I receive emails?

You will receive the newsletter once a week. I value your time and aim to provide a concise summary of the most important updates in cloud security.
03

How do I unsubscribe from the newsletter?

Unsubscribing is easy. At the bottom of every newsletter, you will find an unsubscribe link. Simply click on it and follow the instructions to remove yourself from the mailing list.
04

How is my privacy protected?

CloudSecList takes the privacy of readers very seriously. There is a conscious effort NOT to collect additional information about the CloudSecList readership outside of an email address (which, of course, will NOT be shared with advertisers, ever). In addition, CloudSecList does not track individual open and click rates, but only the global (and anonymized) ones.

For more information, you can refer to CloudSecList's Privacy Policy.

05

How can I contribute or suggest content for the newsletter?

We welcome contributions and suggestions! You can submit your content or suggestions by emailing [email protected]
06

How can I advertise in the newsletter?

Please take a look at the Sponsor page for more information.
07

I have more questions, how can I get in touch?

I'd love to hear from you! Feel free to reach out via email at [email protected]
◇ Sundays · Inbox

Start the week
already informed.