Cloud Security Alliance

The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment.

Cloud Security Alliance The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment.

  • The Model Did Exactly What We Asked
    on July 21, 2026 at 9:59 pm

    An AI “went rogue” last week, just like out of a science fiction movie. Not because it turned on us, but to achieve its defined objective. Just as we were planning our CISO huddle on the Hugging Face attacks, a jaw dropping post from OpenAI was released that completely reframed the entire situation. Hold on people, because this one sure sounds like a story from a SciFi movie.   What actually happened On July 21, OpenAI and Hugging Face jointly disclosed the details behind an i…

  • AI Controls Matrix v1.1: Strengthening the Foundation for Trustworthy AI
    on July 14, 2026 at 4:33 pm

    The Cloud Security Alliance (CSA) recently announced the release of the AI Controls Matrix (AICM) v1.1, a significant update to our comprehensive framework for secure and trustworthy AI systems. Building on the strong foundation established with the original AICM release in 2025, this update expands our control coverage, includes a dedicated Model Security domain, AI-specific security controls, and delivers complete mappings to the world’s major AI governance frameworks, inclu…

  • Implementing CCM: Universal Endpoint Management Controls
    on July 9, 2026 at 5:08 pm

    The Cloud Controls Matrix (CCM) is a framework of controls that are essential for cloud computing security. Created by CSA, the CCM aligns with CSA best practices. You can use CCM to assess and guide the security of any cloud service. CCM also provides guidance on which actors within the cloud supply chain should implement which controls. Both cloud service customers (CSCs) and cloud service providers (CSPs) use CCM in many ways. CCM contains 197 controls structured into 17 domain…

  • When “Who Are You?’ Is No Longer Enough: The Case for Intent-Based Access Control in the Age of AI Agents
    on July 9, 2026 at 4:46 pm

    It keeps coming back to a conversation I had about six months ago. I sat with the CISO of a fortune 50 retail organization to review an incident that had kept the security team up for two straight nights. No credentials were stolen. No malware was deployed. No firewall rule was broken. Yet the critical reconciliation process had gone seriously wrong, wrong enough to draw regulatory scrutiny. The culprit? An AI-powered automation agent that had been granted, quite legitimately, acce…

  • Why M2M Authentication and API Security Must Work Together
    on July 8, 2026 at 5:20 pm

    TL;DR: Non-human identities are calling APIs across cloud environments every day. Securing those interactions requires two layers of control: Machine-to-machine authentication to prove the caller is legitimate API security to limit what that caller can access or do Organizations are moving toward cloud-native automation and autonomous AI agents. Static API keys, shared service accounts, and long-lived secrets create unnecessary risk. Security teams should prioritize workload id…

  • CMMC Certification Deadlines are Coming Soon. Here’s What That Means for You
    on July 6, 2026 at 10:50 pm

    Organizations can no longer treat CMMC compliance as something to address later. In November 2025, the U.S. Department of War (DoW) began incorporating CMMC assessment requirements into applicable defense procurements. While the first phase of implementation focuses primarily on Level 1 and Level 2 self-assessments, organizations should not mistake this for a grace period. For contractors that handle Controlled Unclassified Information (CUI), CMMC readiness is quickly becoming a business…

  • The Hidden Risks of the Agentic Enterprise: Bridging the AI Governance Gap
    on July 6, 2026 at 5:47 pm

    Software used to wait for permission. It executed specific instructions predictably, transparently, and only when a human initiated a process. Today, AI agents are crowding into IT environments. These autonomous entities can execute complex workflows, access critical systems and sensitive data, and even spawn additional agents to complete tasks. No humans required. New research from Okta reveals the speed and scale at which enterprises and employees are adopting AI agents. Its global sur…

  • Unpacking the Salesloft Incident
    on July 6, 2026 at 5:47 pm

      Introduction On August 26, 2025, Google Threat intelligence Group released a report detailing a widespread data theft campaign targeting the sales automation platform Salesloft, via compromised OAuth tokens used by the third-party Drift AI chat agent [1][2].  The attack has been attributed to the threat actor UNC6395 by Google Threat Intelligence and Mandiant [1]. The attack is believed to have begun in early August 2025 and continued through until mid-August 2025 [1], with…

  • ISO 42001: The Importance of Knowing Your Role Before Building Your AI System
    on July 6, 2026 at 5:46 pm

    ISO/IEC 42001:2023 is the first international standard for an Artificial Intelligence Management System (AIMS). Structured similarly to other ISO management system standards, like ISO 27001, with mandatory clauses 4 through 10 and an Annex A control set, it shares the same Plan-Do-Check-Act logic familiar to any management system practitioner. But among other AI specific considerations, it contains a requirement that sets it apart from other ISO frameworks: as part of scoping your AIMS, …

  • AI-Speed Risk Requires Identity-Defined Reachability
    on July 2, 2026 at 5:22 am

    Why Zero Trust Steps 3, 4, and 5 must evolve beyond patching, topology, and ticket-driven connectivity   Written by Philip Griffiths, Head of Strategic Sales, NetFoundry. Executive Summary AI is compressing the time between vulnerability discovery, exploitation, and impact. Patching, secure engineering, and vulnerability management remain essential, but “find and fix faster” is no longer enough. CISA’s risk-based remediation model reinforces the architectural point that expo…

  • Cloud Security Alliance Extends AI Assurance Leadership Into Agentic AI With Addition of AIUC-1 Certification to STAR Registry
    on June 29, 2026 at 1:00 pm

    New designation allows enterprises to identify providers that have demonstrated safe, secure, and reliable AI agents SEATTLE – June 30, 2026 – The Cloud Security Alliance (CSA), the world’s leading not-for-profit organization committed to AI, cloud, and Zero Trust cybersecurity education, today announced a collaboration with AIUC-1 that addresses the growing demand for verifiable assurance of AI agents and autonomous AI systems. This collaboration marks another important milestone in CSA…

  • SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon
    on June 24, 2026 at 9:30 pm

    Varonis Threat Labs discovered SearchLeak, a critical vulnerability chain in Microsoft 365 Copilot Enterprise that allows an attacker to steal sensitive data — MFA codes, email messages, meeting details, and private organizational files — with a single click. Varonis Threat Labs has uncovered a new three-stage vulnerability chain that turns Microsoft 365 Copilot Enterprise Search into a silent data exfiltration weapon. Dubbed SearchLeak, the chain combines a relatively new class …

  • The SaaS Security Problem Most Organizations Still Treat Like an IT Issue
    on June 24, 2026 at 4:14 pm

    For years, organizations approached SaaS security as an access management problem. Enable SSO. Turn on MFA. Provision users correctly. Deprovision them quickly. Audit permissions periodically. That model no longer reflects how modern SaaS breaches actually happen. The recent ADT breach attributed to the ShinyHunters extortion group demonstrates why. According to reports, attackers allegedly compromised an employee’s Okta account through a voice phishing attack and used that foothold to…

  • AI Regulation Keeps Evolving: How to Develop an AI Governance Framework That Adapts
    on June 24, 2026 at 4:12 pm

    The regulatory landscape for AI is shifting rapidly between evolving federal policies, an explosion of state-level legislation, and the emergence of industry-specific compliance requirements. Many organizations know they need AI governance but may face uncertainty about how to navigate the evolving landscape. The most forward-thinking companies aren’t waiting for regulatory clarity, they’re building governance frameworks now that will position themselves to adapt and comply with whatev…

  • Top 6 Claude Cowork Security Risks to Watch
    on June 24, 2026 at 4:12 pm

    Most security teams evaluate Claude Cowork as if it were a chatbot with extra buttons. It isn’t. Cowork is a local agent that runs on the employee’s machine, reads their files, runs shell commands, browses the web with their logged-in cookies, and connects to the enterprise systems they can reach. As Anthropic frames it, when something goes wrong, the impact depends on what Claude can read and what Claude is allowed to do. That changes the threat model. A prompt injection against a ch…

  • The Role of CSA STAR in Vendor Security Assessments
    on June 24, 2026 at 4:12 pm

    Most organizations operate across complex digital ecosystems that include cloud providers, SaaS platforms, API integrations, and outsourced infrastructure.  While these technologies enable scalability and operational efficiency, they also introduce additional security considerations. As vendor networks expand, security and procurement teams often encounter lengthy due diligence processes, repetitive security questionnaires, and limited visibility into third-party risks. Managing tra…

  • Quantum Computing & AI: When AI Starts Writing Quantum Code
    on June 24, 2026 at 4:12 pm

    We often discuss quantum computing and artificial intelligence as separate revolutions. One promises to change what is computationally possible. The other is already changing how organizations build software, analyze data, and automate decisions. But the more interesting question may be what happens when these two emerging technologies start helping each other advance. CSA’s recent Quantum Computing & Artificial Intelligence publication describes this future as Quantum Artificial Int…

  • Validating LLM-Generated Control Mappings Beyond Aggregate Accuracy
    on June 24, 2026 at 4:11 pm

    Security control frameworks continue to grow in scope and complexity. The CSA AI Controls Matrix (AICM) alone has 243 control objectives. NIST CSF has hundreds of subcategories. Organizations operating under multiple frameworks need to map between them for compliance cross-referencing, gap analysis, risk aggregation, and audit preparation. LLMs have become a practical necessity for this work. An LLM can produce a complete mapping in minutes, with structured output, valid schema, and a …

  • AI Security Asymmetry: Why Speed Alone Won’t Save Defenders
    on June 24, 2026 at 4:10 pm

    AI has made something painfully clear: finding vulnerabilities faster does not automatically make an organization safer. That may sound odd, since vulnerability discovery has long been one of the hardest parts of cybersecurity. If a tool can identify more flaws, analyze more logs, and prioritize more signals, shouldn’t that reduce risk? Sometimes, yes, but only when defenders can convert discovery into remediation. CSA’s recent research publication, Core Collapse, argues that the asym…

  • How AI Governance and Data Governance Are Converging in the Cloud
    on June 16, 2026 at 9:04 pm

    Businesses of all sizes are dabbling in data and AI. And as they scale, they’re becoming increasingly aware of the need to develop strict data and AI governance oversight and protocols. However, they’re not always interested in purchasing the equipment and software needed to keep their data protected and available onsite. Instead, many are turning to cloud-based ecosystems. In this way, data and AI governance are converging in the cloud. For the most part, this is working to more tightl…

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.