Watch hub·gcc-high · aws-govcloud · azure-government · ms-cloud-us-gov

Cloud & Platforms

GCC High, AWS GovCloud, Azure Government, and the cloud choices that shape compliance scope.

Updated ·RSS ↗

Cloud-platform selection shapes a contractor's CMMC scope, FedRAMP authorization path, and audit cost. This hub tracks platform compliance announcements, FedRAMP authorizations relevant to CUI workloads, and the harmonization between FedRAMP, GovRAMP, and CMMC across GCC High, AWS GovCloud, Azure Government, and Microsoft Cloud for US Government.

What changed in the last 30 days

  • ai-cybersecurity/vendor

    AWS benchmark shows AI code review is a coin flip

    AWS released Deception Benchmark, a dataset of 14,822 code samples across 16 languages and more than 70 CWE categories, designed to test whether AI models can tell real vulnerabilities from code that looks risky but is actually safe. Twelve models from five providers were evaluated. Under standard prompting, precision landed in the mid-50s, no better than guessing. The benchmark deliberately includes only samples that successfully deceived at least one frontier model during construction, so the difficulty is calibrated to the state of the art.

  • incident-response/vendor

    Social engineering lures pivot from MFA fatigue to passkey pretexts

    Microsoft Security Research reports active cloud intrusions since May 2026 that open with social engineering calls and SMS messages themed around passkey, MFA, or SSO enrollment. Attackers direct targets to adversary-in-the-middle phishing pages or device-code authentication flows, capturing credentials and session tokens. Once inside, they add their own authentication methods, enumerate SharePoint and OneDrive via Microsoft Graph, and collect mail through REST APIs. The initial compromise often leaves little endpoint telemetry because victims open links on personal mobile devices not onboarded to Defender for Endpoint.

  • ai-cybersecurity/trade-press

    Microsoft puts MDASH vulnerability-hunting AI into Azure Government

    Microsoft placed MDASH, an AI vulnerability-hunting system that deploys more than 100 AI agents to find exploitable software flaws, into limited preview on Azure Government. Both defense and civilian agencies are testing it, though Microsoft named none. The company's CTO said the tool is "uncovering previously unknown vulnerabilities and significantly improving the quality of the underlying code", then provided zero examples and zero counts to back the claim.

  • supply-chain/vendor

    Counterfeit software installers hit China-based operations across seven sectors

    Microsoft is tracking an active campaign using counterfeit software-download sites that impersonate trusted vendors to distribute malicious installers. Victims span healthcare, manufacturing, gaming, technology, logistics, government, and education, concentrated among China-based operations and Chinese-speaking users. The campaign, consistent with Silver Fox (Yinhu) activity, regenerates installer payloads server-side per download: same filename, different hash, defeating conventional hash-based detection. Microsoft has not attributed it to a nation-state actor.

  • ai-cybersecurity/vendor

    Microsoft lays out attestation-first model for edge AI security

    Microsoft published guidance on securing edge AI deployments where customers own the infrastructure. The core shift: in cloud AI, the provider attests the hardware, platform, and model weights; in edge AI, the customer operates more of the stack and must verify it before sensitive assets are released. The post argues for runtime attestation, artifact provenance verification, and deterministic mediation to constrain model actions. It's a positioning document for Azure IoT Edge's security framework, not a standard.

  • ai-cybersecurity/vendor

    Unicode tag smuggling jumps from AI prompt injection to phishing

    Microsoft researchers have documented a phishing campaign that repurposes "ASCII smuggling" (invisible Unicode tag characters from the U+E0000) U+E007F range, to split financial-lure words like "funding" so email filters can't parse them. The technique was popularized in AI prompt-injection research, where attackers hide instructions from humans while exposing them to language models. Microsoft Defender for Office 365 telemetry shows hits on a hunting signature for this pattern jumped sharply on February 9, 2026, and stayed elevated on weekdays for roughly three months. Most flagged messages were caught by layered defenses, not a single Unicode-specific signal.

  • incident-response/vendor

    DeadLock ransomware layers decentralized recovery onto extortion

    Microsoft Threat Intelligence published a technical breakdown of DeadLock ransomware August 10. The Rust-based encryptor, active since July 2025, has hit more than 80 organizations across IT, mining, transportation, manufacturing, hospitality, and consumer goods, more than half in Europe. What distinguishes DeadLock is its recovery infrastructure: it combines the Session messaging network with blockchain-backed services to store and deliver resources used throughout extortion, likely hardening portions of its leak and negotiation infrastructure against disruption. The encryptor also throttles to preserve system responsiveness and geofences against systems in former Soviet, CIS, and select Middle Eastern countries.

  • fedramp/vendor

    AWS Transform lands FedRAMP Class C in Ohio

    AWS Transform, the company's agentic migration and modernization service, is now in scope for FedRAMP Class C (formerly Moderate baseline) in the US East (Ohio) Region. Federal agencies and contractors can now use Transform for workloads subject to Class C compliance requirements. The authorization covers one region (Ohio only) which means multi-region moderate architectures will need to wait for additional regions to enter scope. No Class D (High) authorization for GovCloud was announced.

  • ai-cybersecurity/vendor

    Attackers breach LiteLLM, RAGFlow, Kestra gateways for credential theft

    Microsoft's threat research team observed three distinct compromise campaigns targeting AI infrastructure, a LiteLLM gateway, a RAGFlow deployment, and a Kestra orchestration environment. In each case, attackers harvested API keys, database connection strings, and virtual-key records, then established persistence and deployed cryptocurrency miners. The common thread: AI middleware concentrates credentials at a level most organizations haven't secured, and attackers have noticed. None of the intrusions involved prompt injection or model poisoning, these were straightforward infrastructure compromises aimed at the control plane where trust aggregates.

  • aws-govcloud/vendor

    SageMaker MLflow adds customer-managed KMS keys

    AWS SageMaker MLflow now supports customer-managed KMS keys for encryption, giving customers control over key management and independent CloudTrail audit trails. Previously, MLflow used AWS-managed keys: encryption existed but key-access logging was invisible to the customer. For defense contractors and organizations operating under CMMC or FedRAMP, the shift turns a black-box encryption posture into something an assessor can independently verify. Constraints are standard KMS fare: symmetric keys only, same account and region as the MLflow app.

  • nist/trade-press

    NIST IR 8613 maps multi-cloud security seams

    NIST published draft IR 8613 on August 21, cataloguing security and authorization-to-operate challenges unique to multi-cloud environments. The report, produced by NIST's Multi-Cloud Security Public Working Group, identifies five structural gaps where alignment is most urgent: identity and access management, telemetry and logging, configuration and change management, data protection, and compliance and authorization. Comments close October 5. The publication validates what practitioners have long known (that ATO processes built for a single provider don't survive contact with a second one) and tees up potential guidance or standards work to follow.

  • cmmc/trade-press

    ITI pushes DOD to accept FedRAMP controls under CMMC

    ITI urged DOD to establish formal FedRAMP-CMMC reciprocity in comments filed during the Phase Two pause, arguing that re-auditing controls already validated under FedRAMP produces "duplicative cost without a proportionate increase in security." The filing proposes a "commercial solutions equivalency" pathway where contractors inherit platform-level FedRAMP assurances rather than re-certifying per project. DOD already recognized FedRAMP Moderate equivalency for cloud providers handling CUI in a January 2024 memo, ITI wants that extended to commercial software platforms broadly and codified in a common control matrix.

  • fedramp/trade-press

    FedRAMP 20x ends compliance theater with 2, 4 day vuln deadlines

    FedRAMP Director Pete Waterman told vendors at Carahsoft's FedRAMP Summit that those who can't fix critical, internet-facing vulnerabilities within days don't belong in the federal marketplace. FedRAMP 20x codifies that expectation: risk reduction must begin within two to four days, and system security state must be verified at least every three days. The implication is structural, vendors whose compliance staff sit apart from engineering cannot sustain that pace. Continuous authorization requires continuous delivery, and the deployment pipeline itself becomes the control.

  • aws-govcloud/vendor

    AWS Storage Gateway adds FIPS 140-3 PrivateLink endpoints

    AWS Storage Gateway now supports FIPS 140-3 validated endpoints over AWS PrivateLink for Tape and Volume Gateway. Previously, FIPS endpoints were only reachable over the public internet, forcing regulated-workload operators to choose between FIPS-compliant encryption and private network architecture. The feature is available in eight regions including both GovCloud endpoints, with gateway software version 3.2.7 or later required. The fix closes a long-standing gap that competing cloud storage services addressed earlier, but for GovCloud tenants already running Storage Gateway, it removes a genuine operational constraint.

  • ai-cybersecurity/vendor

    Microsoft diagnoses shrinking patch windows, prescribes its platform

    Microsoft argues that the gap between vulnerability disclosure and exploitation has collapsed, and AI-assisted attacker workflows are making it worse. The diagnosis is real: CISA's KEV catalog and joint advisories show attackers routinely exploit vulnerabilities within hours of disclosure. But the proposed fix, what Microsoft calls a new control plane for the pre-patch period, is its unified security operations platform. The compensating controls it describes (interim mitigations, risk-based triage) are already recommended under NIST SP 800-53 and CISA BOD 26-04. Practitioners who've been running patch orchestration for years will recognize the playbook.

  • procurement/trade-press

    DISA pegs Aug. 24 release for JWCC Unified Cloud Marketplace

    DISA's August acquisition schedule sets an expected Aug. 24 final solicitation release for JWCC Unified Cloud Marketplace, the follow-on to the $9 billion Joint Warfighting Cloud Capability contract. The new vehicle splits into three tiers: hyperscalers (AWS, Microsoft, Google, Oracle) at Tier 1, everything-as-a-service at Tier 2, and emerging companies and small businesses at Tier 3. DISA hasn't posted an estimated ceiling value. Task-order data from Deltek shows the current JWCC is heavily lopsided: AWS holds $526.5 million in obligations against a $9 billion ceiling, followed by Microsoft at $221 million, Oracle at $76.9 million, and Google at $35.9 million.

  • aws-govcloud/vendor

    Amazon Quick brings autonomous agents to FedRAMP Class D

    Amazon Quick's agentic AI capabilities are now live in AWS GovCloud (US-West), putting autonomous agents inside the FedRAMP Class D boundary for the first time. Federal teams can build custom agents for procurement, grants management, and ATO compliance while data stays in the GovCloud region. GCC High connectors for Microsoft 365 and SharePoint are included. The service didn't appear on the FedRAMP services-in-scope roster as of August 7, and any agency deploying Quick agents for production ATO workflows will still need its own authorization under the shared responsibility model.

Open questions

  • 01When will additional CUI-capable cloud platforms enter the market?
  • 02How does FedRAMP 20x affect contractors using Moderate platforms?
  • 03Which platforms have publicly attested to NIST 800-171 r3 readiness?

Sources we watch

Related from Deep Fathom

Earlier coverage