The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment.
Cloud Security Alliance The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment.
- Shadow AI Does Not Read Your Org Chart: Rethinking Identity Governance for Autonomous Agentson September 3, 2026 at 5:21 pm
RBAC is solving yesterday’s identity problem while autonomous systems are making decisions with access they already have. At RSA Conference 2026, Adi Shamir, the “S” in RSA, warned the security professionals that he is “totally terrified” of AI agents, because they need access to everything to be useful, and he does not extend that kind of access even to his own wife [1]. Most CISOs are living a quieter version of that fear. Enterprise AI agent deployments are growing tenfold in months r…
- 2026 Cloud Security Index: How Risk Differs Across AWS, Azure, and Google Cloudon September 2, 2026 at 10:49 pm
Originally published by Intruder. Juggling multiple cloud providers is complicated enough without each one failing in different places. But that’s what Intruder’s 2026 Cloud Security Index found: the issues that dominate on AWS barely overlap with those on Google Cloud, and Azure looks different again. For security teams, this doesn’t just create more work: it fragments teams’ understanding of risk, makes prioritization harder, and can slow down remediation. That matters beca…
- What Zero Trust Can Teach Us About AI Watermarkson August 28, 2026 at 6:31 am
I recently wrote about the mess that is watermarking AI-generated text and how Anthropic’s move to add watermarks (in response to the EU AI Act’s transparency rules) raises more questions than it answers. If you haven’t read that blog, the short version is this: telling AI content apart from human content is getting harder every day – AI is a tool that should be used much in the same way that you use a calculator to do long division, and slapping a watermark on it doesn’t change that. B…
- State of AI Cybersecurity 2026: 87% of Security Professionals are Seeing More AI-Driven Threats, But Few Feel Ready to Stop Themon August 26, 2026 at 10:25 pm
Originally published by Darktrace. Findings from our annual survey of 1,500+ cyber professionals reveal that security leaders are confronting a surge in AI-driven attacks, which are faster, more personalized, and harder to detect than anything they’ve seen before. As these threats scale, the challenge for defenders is in evolving their security programs in tandem to defend with confidence. The findings in this blog are taken from Darktrace’s annual State of AI Cybersecurity Report 202…
- Top 6 Claude in Chrome Security Risks to Model Before You Roll It Outon August 26, 2026 at 10:09 pm
Most teams evaluate a browser agent like a browser extension. Check the permissions, check the vendor, check for open CVEs, approve or deny. That framing produced two clean patch cycles in 2026 and no reduction in exposure. Two problems are being treated as one. Implementation bugs, which vendors fix. And the authority the agent carries while it works, which no patch touches. Every hard question in agentic AI security lives in the gap between them. Six categories worth modeling separate…
- Beyond Deepfakes: Zero Trust Security for the AI Economyon August 19, 2026 at 5:27 pm
TL;DR: Deepfakes are not merely a detection challenge. They expose fundamental weaknesses in how organizations establish identity, grant authority, and protect data. Appearances alone can no longer serve as proof. CSA research shows how Zero Trust, IAM, and AI data security can provide the trust infrastructure organizations need. A familiar face appears on a video call. A known voice delivers an urgent instruction. A senior executive requests an unusual payment, data transfer, or passwor…
- State of AI Cybersecurity 2026: 77% of Security Stacks Include AI, But Trust is Laggingon August 18, 2026 at 9:40 pm
Originally published by Darktrace. AI is now embedded throughout the cybersecurity stack, but findings from the State of AI Cybersecurity 2026 show that adoption is growing much faster than trust or understanding. As vendors strive to capture market share, security leaders must learn how to distinguish the most valuable solutions from the hype. Findings in this blog are taken from Darktrace’s annual State of AI Cybersecurity Report 2026. AI is a contributing member of nearly …
- MITRE’s New Framework: Securing the eBPF Layer Your AI Depends Onon August 18, 2026 at 9:15 pm
AI systems are increasingly making automated decisions on telemetry drawn from the kernel. MITRE’s new Framework for Continuous Remote Attestation names the layer where that telemetry can be quietly corrupted, and it is the layer the industry has spent the least time defending. In cloud-native infrastructure, eBPF (extended Berkeley Packet Filter) has become indispensable. It delivers deep visibility and fine-grained control by running programs directly in kernel space. Security platform…
- MITRE’s New Continuous Remote Attestation Framework for the AI Eraon August 18, 2026 at 9:13 pm
As AI makes decisions on infrastructure that changes by the minute, MITRE is formalizing how to verify those systems stay trustworthy while they run, not just when they boot. Why MITRE built a new framework For most of computing history, we verified a system once and trusted it from there. A machine was provisioned, checked at startup, and assumed good until something obvious went wrong. The AI era has broken that assumption. Systems now make decisions and take actions faster …
- EU AI Act Compliance for High-Risk AI Systems: What Your Organization Needs to Knowon August 18, 2026 at 9:13 pm
A Q&A about the EU AI Act with Schellman CEO Avani Desai on risk classification, AI literacy, and the August 2 deadline Schellman CEO, Avani Desai, recently joined a DataCamp panel webinar, “Deadline Approaching: EU AI Act Compliance for High-Risk AI Systems”, alongside Jessica Eaves Mathews (Managing Attorney at Leverage Legal Group) and Jason M. Loring (Partner at Jones Walker, co-chair of its Privacy, Data Strategy and AI team). The panel broke down what the EU AI Act requires, h…
- Why Cloud Security Requires More Than Point-in-Time Auditson August 18, 2026 at 9:12 pm
An organization may pass its annual cloud security audit with every control in place. Yet days later, a misconfigured storage bucket, an overly permissive IAM policy, or an insecure firewall rule can alter its security posture. The audit report remains unchanged, but the environment no longer reflects what was assessed. This is the challenge with point-in-time audits. They verify security at a single point in time, while dynamic cloud environments require continuous validation. The focu…
- The New Face of Identity Attacks: Why Phishing No Longer Needs Your Passwordon August 18, 2026 at 9:12 pm
For years, cybersecurity awareness has revolved around a familiar set of best practices: create strong passwords, enable multi-factor authentication (MFA), and think twice before clicking on suspicious emails. Those recommendations remain important, but they were designed for a threat landscape where attackers primarily wanted your credentials. That landscape is changing. The FBI’s recent warning about Kali365, an emerging Phishing-as-a-Service (PhaaS) platform targeting Microsoft 365 u…
- AI Governance Programs: What CISOs Say vs. What They Actually Doon August 18, 2026 at 9:11 pm
Security leaders have heard the phrase “AI has expanded the attack surface” enough times. The more interesting story is the widening gap between what CISOs say they’re doing about it and what’s actually happening inside their organizations. I got to test this disconnect at a recent private CISO summit in Chicago as the closing keynote alongside Dr. Fred Kwong, VP and CISO for DeVry University. 5 Key AI Governance Program Takeaways AI deployment has far outpaced AI governance …
- We Asked an AI Agent to Close a Linear Ticket. It Dropped a Production Table.on August 18, 2026 at 9:11 pm
Originally published by Eve Security. A developer opens Cursor, points it at a Linear ticket, and asks it to implement the fix. Cursor loads ticket-work, a small skill that standardizes how the agent pulls context from Linear and closes tickets. It’s the kind of utility a team writes once and then forgets about. The agent reads the ticket and loads the skill. A few tool calls later, the insurance_claims table is gone. Unconfined agent drop — after “Implement RND-1277,” t…
- Legacy Operating Models Can’t Keep Pace With IT Complexity, Cloud Security Alliance Survey Findson August 18, 2026 at 10:35 am
Study reveals that fragmented ownership and limited visibility have made manual policy management a production risk SEATTLE – Aug. 18, 2026 — Fragmented operating models spanning teams, tools, and environments and which are still heavily reliant on manual processes are taking a measurable toll on production uptime, deployment velocity, and compliance readiness, according to a new survey from the Cloud Security Alliance (CSA), the world’s leading not-for-profit organization committed to A…
- Downwind of the Labson August 18, 2026 at 6:53 am
One of the first things they teach you in hazmat response is to stage uphill and upwind. (And the rule of thumb: if you can’t cover the scene with your thumb, you’re too close). Before you treat a single patient, before you even get out of the truck, you figure out where the plume is going. While most industrial accidents are self-contained, it’s the ones that spread into the surrounding community that make the news. This is how I’m now thinking about the Hugging Face and related AI “esc…
- When the Playbook Breaks: AI Incident Response for Systems That Don’t Behave Like Anything Elseon August 17, 2026 at 4:40 pm
Three years after the explosion of GenAI in the enterprise, most organizations now have an inventory of their AI systems, an acceptable use policy, and — at best — a process for approving AI use cases. Far fewer, however, have answered a seemingly simple question about AI Incident Response: what exactly do we do on the day one of these tools is compromised? Most security organizations have mature playbooks for ransomware, business email compromise, and cloud account takeover. Yet very fe…
- When Tokenmaxxing Leads to Riskmaxxingon August 12, 2026 at 5:03 pm
AI fluency and tokenmaxxing are the new corporate obsessions. But where leadership sees opportunity, security sees friction. It’s no longer enough just to do your job well. Across industries, employees are expected to weave AI into every workflow so they can 10x productivity and innovation. And when it comes to AI, today’s workforce is single-minded. They’re rising to the occasion to “use AI more” by seemingly any means necessary. They are seeking out new tools, signing up,…
- SOC 2 vs. HITRUST: Which Framework is Right for Healthcare Organizations?on August 12, 2026 at 5:00 pm
Healthcare organizations face growing pressure to protect sensitive patient data while meeting strict regulatory requirements. Two of the most recognized cybersecurity and compliance frameworks in the healthcare space are SOC 2 and HITRUST. While both frameworks strengthen security posture and build trust with stakeholders, choosing which one is the best next step for your organization depends on your goals, customer expectations, and compliance needs. In this blog, you will learn: SOC…
- Artificial Intelligence (AI) Emerges as an Attack Enabler and Target in Cloud Security Alliance’s 2026 Top Threats Reporton August 12, 2026 at 11:33 am
Identity, AI, software supply chains, and interconnected cloud ecosystems displace traditional infrastructure as top security concerns SEATTLE – Aug. 13, 2026 – Security practitioners are increasingly concerned about the impact of AI on cloud security, according to the findings of the Top Threats to Cloud Computing Survey Report 2026. The latest installation in the Top Threats to Cloud Computing series from the Cloud Security Alliance (CSA), the world’s leading not-for-profit organiza…







