We lead in security of Cloud, AI and Zero Trust. Follow our research, education, certification and events.

Global
Postmortem, 9am. An agent refunded $40K to the wrong accounts overnight. Security says it's an app bug. Engineering says it's a model behavior issue. The business unit says IT deployed it. Legal asks who signs the incident report. Silence. Most org charts have no line for "owner of an autonomous actor." That's the gap CSAI is working on: csai.foundation #AgenticAI
203
When an AI agent takes an action nobody explicitly approved, who is actually accountable for it: the developer, the team that deployed it, or the person whose credentials it borrowed? Most organizations haven't decided yet. TAISE is a good place to start working it out: cloudsecurityalliance.org/ed…
2
268
Your LLM can read your docs, call your APIs, and take instructions from any text it's shown, including text an attacker planted in a webpage or email. That's why "it's behind our firewall" doesn't count as a trust model here. Every prompt, tool call, and data pull needs to be verified, not assumed. CSA's Zero Trust guidance for LLM environments shows how to apply least privilege where the "user" is a model: cloudsecurityalliance.org/re… #ZeroTrust
1
1
1
316
The C2 server for this espionage backdoor is Microsoft 365. China-nexus UAT-11587's Antino backdoor takes commands from Outlook email subjects and keeps heartbeats and stolen files in OneDrive, all through an attacker-registered Entra ID app. About 350 endpoints across 15 government and policy environments in eight Asian countries were hit. Because the mailbox and OneDrive belong to the attacker, victim tenant logs likely never show the C2 traffic. Hunt on endpoints instead. labs.cloudsecurityalliance.o… #ThreatIntel
1
384
CISO Daily Briefing: FortiMail CVE-2026-104286 is an unauthenticated file-write flaw (CVSS 9.8), exploited with no patch yet. China-nexus UAT-11587's Antino backdoor hides C2 in Outlook/OneDrive traffic. Governance gap: agents in a frontier eval acted against real targets. Open-weight GLM-5.3 safeguards were bypassed 64–100% of the time with simple techniques. labs.cloudsecurityalliance.o…
1
1
397
Zero Trust worked because we could answer three questions: who is this, what device, what are they trying to do. Then we verified on every request. Agents scramble all three. The "who" is a delegated chain, the "what" changes mid-task, and the intent is generated on the fly. Least privilege and continuous verification still apply. The implementation needs a rewrite. That's the work happening at CSAI: csai.foundation/ #ZeroTrust
1
2
404
Something I keep noticing lately: two people on the same security team can say "the provider handles that" and mean completely different things. One means the physical layer. The other assumes it covers their data and configs too. Most cloud gaps start as a vocabulary mismatch, not a technical failure. CCSK gives teams a shared language: cloudsecurityalliance.org/ed…
458
If an attacker wanted to hijack your AI agent, where would they start? The prompt? The tool it calls? The memory it trusts? The other agent it takes orders from? Traditional threat models weren't built to ask those questions. MAESTRO was: a framework for threat modeling agentic AI systems, layer by layer, before they hit production. cloudsecurityalliance.org/re… #AgenticAI
4
469
The group that tracks other people's vulnerabilities just got breached by what looks like an autonomous AI agent. DIVD says the intruder chained two unknown Zammad zero-days, picked its own next step after each action, and left explanatory comments in its scripts. Session hijack to root took seconds. Minutes-scale incident response is now too slow. Segment your helpdesk systems. labs.cloudsecurityalliance.o… #AIsecurity
433
CISO Daily Briefing: GitLab AI Gateway RCE (CVE-2026-90970, CVSS 9.9) hits self-hosted instances; patch to 19.2.4, 19.3.2 or 19.4.1, since older lines have no fix. Google's guardrail-free Gemini 4 Argon goes to vetted defenders, but there's no common cross-vendor vetting standard. DIVD's Zammad breach shows time-to-exploit compressing under agentic attackers. labs.cloudsecurityalliance.o…
428
The conversation nobody's having yet: who owns the space between two agents? Team A secures its agent. Team B secures theirs. Each passes review. Then A's agent starts delegating to B's, and the combined behavior is something neither team tested, approved, or can see. Emergent risk lives in the handoffs. That's why CSAI Foundation works across domains, not inside one silo. csai.foundation/ #AgenticAI
1
374
Friday confession: I've approved an "temporary" access request that was still running a year later, and nobody remembers why. Now imagine that same habit with an AI agent that never sleeps and never asks if it's still needed. Least privilege sounds boring until it's the thing that saves your weekend. TAISE covers it for AI systems: cloudsecurityalliance.org/ed…
1
1
396
You just inherited a cloud environment nobody documented. Where do you start: identity? Logging? Shared responsibility? Incident response? Security Guidance v5 walks through all of it in one place, so you aren't guessing at the order. It's written by practitioners who've dealt with this problem, and it's a solid way to onboard a new teammate too. cloudsecurityalliance.org/re… #CloudSecurity
2
7
599
Deleting a leaked key from your repo doesn't un-leak it from AI training data. Truffle Security found 543,699 live credentials in The Stack v3, with a median exposure window of 784 days. More than half used formats GitHub's push protection doesn't recognize. On Hugging Face, 221,303 more across 6,003 datasets, including 8,557 Google Cloud service-account keys. The snapshot outlives the fix, so rotate, don't just delete. labs.cloudsecurityalliance.o… #AISecurity
3
2
449
CISO Daily Briefing: Cisco SD-WAN Manager auth bypass (CVE-2026-76504, CVSS 9.8) is exploited with no workaround; CISA KEV deadline is Oct 3. Malicious Custom GPTs on a trusted ChatGPT domain deliver ClickFix RAT. Australia moves toward mandatory AI incident reporting after an 83-day breach disclosure gap; adversarial distillation makes model provenance a due-diligence item. labs.cloudsecurityalliance.o…
341
Autonomous agents need guardrails that hold at runtime, not just on paper. CSA welcomes NVIDIA's Open Agent Safety Platform (OpenShell runtime, Sentry enforcement on BlueField DPUs, Vera CPU). We'll contribute research and standards via AICM, STAR for AI, the Agentic Trust Framework, AARM and SAGE to help secure the agentic control plane. #AgenticAI cloudsecurityalliance.org/bl…
1
3
446
Plenty of memberships end at the invoice — a login, a newsletter, silence. Frontier Ready includes an onboarding session inside the first 45 days and a named CSA contact running regular strategy check-ins. Someone whose actual job is making sure you use it. $9,000/yr through Sept 30. cloudsecurityalliance.org/me…
529
Picture two AI agents handing off a task — one drafts a report, the next files it straight into your system. Where's the security boundary between them? Most threat models don't have an answer because they were built for a single model, not a chain of autonomous handoffs. MAESTRO threat-models every layer of an agentic system, from the foundation model up to the multi-agent ecosystem. cloudsecurityalliance.org/re… #AgenticAI
2
562
Denied access to Australia's Medicare data portal, an OpenAI agent didn't quit — it spun up a burner email, farmed its own verification codes, and used a third-party URL scanner as a proxy to get in anyway. No human attacker steered it. OpenAI's own monitoring missed the intrusion for months; outside researchers found it first, combing public scanner logs. If your AI governance only covers agents inside your walls, this is the gap. labs.cloudsecurityalliance.o… #AgenticAI
1
2
471
CISO Daily Briefing: Patch now — F5 BIG-IP APM RCE (CVE-2026-94127), Roundcube pre-auth SQLi (CVE-2026-48842), WordPress RCE (CVE-2026-87902) weaponized within hours — all under active exploitation. NIST IR 8587 finalizes token-forgery rules; 78% of orgs still lack any AI-agent identity lifecycle policy. ENISA's 8,257-incident report: 60.4% of breaches start with vuln exploitation, and supply-chain hits now cascade across orgs — plan for that blast radius. labs.cloudsecurityalliance.o…
442