0
Deep & Emerging Tech·July 30, 2026·1 min read

What is the Shared Responsibility Model in cloud security?

Share

The fact that the shared responsibility model still needs explaining tells you how many teams implicitly assume ‘cloud = secure by default.’ This week, document—on one page—what your cloud provider covers and what you own for each major service; most surprises in incidents start there.

Deep & Emerging Tech

Amazon researchers link the compromises of four npm packages, including axios, over the past 18 months to the North Korea-linked group tracked as Sapphire Sleet

Four compromised npm packages over 18 months—via social engineering of maintainers—reinforces that your software supply chain risk now includes upstream humans, not just code. Lock down dependency policies, pin and mirror critical packages, and assume popular OSS components are active targets for state-linked actors.