The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment.
Cloud Security Alliance The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment.
- AI Controls Matrix v1.1: Strengthening the Foundation for Trustworthy AIon July 14, 2026 at 4:33 pm
The Cloud Security Alliance (CSA) recently announced the release of the AI Controls Matrix (AICM) v1.1, a significant update to our comprehensive framework for secure and trustworthy AI systems. Building on the strong foundation established with the original AICM release in 2025, this update expands our control coverage, includes a dedicated Model Security domain, AI-specific security controls, and delivers complete mappings to the world’s major AI governance frameworks, inclu…
- When “Who Are You?’ Is No Longer Enough: The Case for Intent-Based Access Control in the Age of AI Agentson July 9, 2026 at 4:46 pm
It keeps coming back to a conversation I had about six months ago. I sat with the CISO of a fortune 50 retail organization to review an incident that had kept the security team up for two straight nights. No credentials were stolen. No malware was deployed. No firewall rule was broken. Yet the critical reconciliation process had gone seriously wrong, wrong enough to draw regulatory scrutiny. The culprit? An AI-powered automation agent that had been granted, quite legitimately, acce…
- CMMC Certification Deadlines are Coming Soon. Here’s What That Means for Youon July 6, 2026 at 10:50 pm
Organizations can no longer treat CMMC compliance as something to address later. In November 2025, the U.S. Department of War (DoW) began incorporating CMMC assessment requirements into applicable defense procurements. While the first phase of implementation focuses primarily on Level 1 and Level 2 self-assessments, organizations should not mistake this for a grace period. For contractors that handle Controlled Unclassified Information (CUI), CMMC readiness is quickly becoming a business…
- AI-Speed Risk Requires Identity-Defined Reachabilityon July 2, 2026 at 5:22 am
Why Zero Trust Steps 3, 4, and 5 must evolve beyond patching, topology, and ticket-driven connectivity Written by Philip Griffiths, Head of Strategic Sales, NetFoundry. Executive Summary AI is compressing the time between vulnerability discovery, exploitation, and impact. Patching, secure engineering, and vulnerability management remain essential, but “find and fix faster” is no longer enough. CISA’s risk-based remediation model reinforces the architectural point that expo…
- Cloud Security Alliance Extends AI Assurance Leadership Into Agentic AI With Addition of AIUC-1 Certification to STAR Registryon June 29, 2026 at 1:00 pm
New designation allows enterprises to identify providers that have demonstrated safe, secure, and reliable AI agents SEATTLE – June 30, 2026 – The Cloud Security Alliance (CSA), the world’s leading not-for-profit organization committed to AI, cloud, and Zero Trust cybersecurity education, today announced a collaboration with AIUC-1 that addresses the growing demand for verifiable assurance of AI agents and autonomous AI systems. This collaboration marks another important milestone in CSA…
- SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weaponon June 24, 2026 at 9:30 pm
Varonis Threat Labs discovered SearchLeak, a critical vulnerability chain in Microsoft 365 Copilot Enterprise that allows an attacker to steal sensitive data — MFA codes, email messages, meeting details, and private organizational files — with a single click. Varonis Threat Labs has uncovered a new three-stage vulnerability chain that turns Microsoft 365 Copilot Enterprise Search into a silent data exfiltration weapon. Dubbed SearchLeak, the chain combines a relatively new class …
- The SaaS Security Problem Most Organizations Still Treat Like an IT Issueon June 24, 2026 at 4:14 pm
For years, organizations approached SaaS security as an access management problem. Enable SSO. Turn on MFA. Provision users correctly. Deprovision them quickly. Audit permissions periodically. That model no longer reflects how modern SaaS breaches actually happen. The recent ADT breach attributed to the ShinyHunters extortion group demonstrates why. According to reports, attackers allegedly compromised an employee’s Okta account through a voice phishing attack and used that foothold to…
- AI Regulation Keeps Evolving: How to Develop an AI Governance Framework That Adaptson June 24, 2026 at 4:12 pm
The regulatory landscape for AI is shifting rapidly between evolving federal policies, an explosion of state-level legislation, and the emergence of industry-specific compliance requirements. Many organizations know they need AI governance but may face uncertainty about how to navigate the evolving landscape. The most forward-thinking companies aren’t waiting for regulatory clarity, they’re building governance frameworks now that will position themselves to adapt and comply with whatev…
- Top 6 Claude Cowork Security Risks to Watchon June 24, 2026 at 4:12 pm
Most security teams evaluate Claude Cowork as if it were a chatbot with extra buttons. It isn’t. Cowork is a local agent that runs on the employee’s machine, reads their files, runs shell commands, browses the web with their logged-in cookies, and connects to the enterprise systems they can reach. As Anthropic frames it, when something goes wrong, the impact depends on what Claude can read and what Claude is allowed to do. That changes the threat model. A prompt injection against a ch…
- The Role of CSA STAR in Vendor Security Assessmentson June 24, 2026 at 4:12 pm
Most organizations operate across complex digital ecosystems that include cloud providers, SaaS platforms, API integrations, and outsourced infrastructure. While these technologies enable scalability and operational efficiency, they also introduce additional security considerations. As vendor networks expand, security and procurement teams often encounter lengthy due diligence processes, repetitive security questionnaires, and limited visibility into third-party risks. Managing tra…
- Quantum Computing & AI: When AI Starts Writing Quantum Codeon June 24, 2026 at 4:12 pm
We often discuss quantum computing and artificial intelligence as separate revolutions. One promises to change what is computationally possible. The other is already changing how organizations build software, analyze data, and automate decisions. But the more interesting question may be what happens when these two emerging technologies start helping each other advance. CSA’s recent Quantum Computing & Artificial Intelligence publication describes this future as Quantum Artificial Int…
- Validating LLM-Generated Control Mappings Beyond Aggregate Accuracyon June 24, 2026 at 4:11 pm
Security control frameworks continue to grow in scope and complexity. The CSA AI Controls Matrix (AICM) alone has 243 control objectives. NIST CSF has hundreds of subcategories. Organizations operating under multiple frameworks need to map between them for compliance cross-referencing, gap analysis, risk aggregation, and audit preparation. LLMs have become a practical necessity for this work. An LLM can produce a complete mapping in minutes, with structured output, valid schema, and a …
- AI Security Asymmetry: Why Speed Alone Won’t Save Defenderson June 24, 2026 at 4:10 pm
AI has made something painfully clear: finding vulnerabilities faster does not automatically make an organization safer. That may sound odd, since vulnerability discovery has long been one of the hardest parts of cybersecurity. If a tool can identify more flaws, analyze more logs, and prioritize more signals, shouldn’t that reduce risk? Sometimes, yes, but only when defenders can convert discovery into remediation. CSA’s recent research publication, Core Collapse, argues that the asym…
- How AI Governance and Data Governance Are Converging in the Cloudon June 16, 2026 at 9:04 pm
Businesses of all sizes are dabbling in data and AI. And as they scale, they’re becoming increasingly aware of the need to develop strict data and AI governance oversight and protocols. However, they’re not always interested in purchasing the equipment and software needed to keep their data protected and available onsite. Instead, many are turning to cloud-based ecosystems. In this way, data and AI governance are converging in the cloud. For the most part, this is working to more tightl…
- Agentic AI Red Teaming: Tool Misuse is the Test That Matterson June 9, 2026 at 12:30 am
Agentic AI changes the red teaming conversation. Traditional generative AI testing often focuses on whether a model will produce harmful text. Agentic AI raises the question of what happens when an AI system can plan, reason, and interact with tools, workflows, and downstream systems. That is where agentic AI red teaming becomes essential. In CSA’s recent research publication, Evaluating PyRIT for Agentic AI Red Teaming, Microsoft’s Python Risk Identification Toolkit is evaluated as a wa…
- Proof is the Application Security Bottleneckon June 9, 2026 at 12:30 am
For years, application security programs have focused on a single goal: finding vulnerabilities earlier in the software lifecycle. We’ve invested heavily in shift-left security, app security testing, CI/CD scanning, and dev-focused remediation workflows. But according to CSA and Miggo Security’s new survey report, security teams are still losing the production battle. The problem is no longer visibility alone. Security teams are overwhelmed with threat intelligence findings, alerts, a…
- Securing the Swarm: Governance, Attack Surfaces, and Zero-Trust Architectures in Multi-Agent AI Environmentson June 9, 2026 at 12:27 am
EXECUTIVE SUMMARY Enterprise artificial intelligence has transitioned from isolated, static Large Language Model (LLM) prompts to dynamic, multi-agent systems (MAS) operating at high levels of operational autonomy. While these systems dramatically accelerate software development, supply chain orchestration, and threat response, they introduce unprecedented security blind spots that render legacy identity, data protection, and boundary defense mechanisms obsolete. This bl…
- Dangling CNAMEs: The Critical DNS Misconfiguration Most Organizations Still Misson June 9, 2026 at 12:27 am
In cybersecurity, the most damaging attacks are not always the most sophisticated. Sometimes, they begin with something as mundane as a forgotten DNS record. That reality came into sharp focus when researchers uncovered a large-scale campaign involving hijacked university subdomains across institutions including UC Berkeley, Columbia University, and Washington University in St. Louis. Attackers exploited abandoned CNAME records to take control of trusted .edu subdomains and use them to h…
- Is Financial Services Ready for Agentic Payments?on June 9, 2026 at 12:26 am
Imagine telling an AI assistant: “Find me the best flight to Chicago next Thursday. Book a hotel within walking distance of the conference center, stay under my travel budget, and use my rewards points if it makes sense.” Now imagine that assistant not only making recommendations, but actually completing the purchases on your behalf. No extra approvals, switching between apps, or manually entering payment information. That is the emerging reality of agentic payments. AI agents are quic…
- 5 Claude Agent Skills Risks Every CISO Should Knowon June 9, 2026 at 12:26 am
The SKILL .md file is the new package.json. And it’s already compromised. Developers and business users trust Claude Skills the way engineers once trusted npm packages. Install a skill on Claude Code, claude.ai, or via the API. Extend the agent’s capabilities. Ship faster. But the parallels don’t stop at convenience. They extend to the attack surface. Over the past six months, security researchers have converged on the same finding: the Claude agent skills ecosystem carries systemic s…







