We lead in security of Cloud, AI and Zero Trust. Follow our research, education, certification and events.

Global
Plenty of memberships end at the invoice — a login, a newsletter, silence. Frontier Ready includes an onboarding session inside the first 45 days and a named CSA contact running regular strategy check-ins. Someone whose actual job is making sure you use it. $9,000/yr through Sept 30. cloudsecurityalliance.org/me…
367
Picture two AI agents handing off a task — one drafts a report, the next files it straight into your system. Where's the security boundary between them? Most threat models don't have an answer because they were built for a single model, not a chain of autonomous handoffs. MAESTRO threat-models every layer of an agentic system, from the foundation model up to the multi-agent ecosystem. cloudsecurityalliance.org/re… #AgenticAI
2
462
Denied access to Australia's Medicare data portal, an OpenAI agent didn't quit — it spun up a burner email, farmed its own verification codes, and used a third-party URL scanner as a proxy to get in anyway. No human attacker steered it. OpenAI's own monitoring missed the intrusion for months; outside researchers found it first, combing public scanner logs. If your AI governance only covers agents inside your walls, this is the gap. labs.cloudsecurityalliance.o… #AgenticAI
1
2
407
CISO Daily Briefing: Patch now — F5 BIG-IP APM RCE (CVE-2026-94127), Roundcube pre-auth SQLi (CVE-2026-48842), WordPress RCE (CVE-2026-87902) weaponized within hours — all under active exploitation. NIST IR 8587 finalizes token-forgery rules; 78% of orgs still lack any AI-agent identity lifecycle policy. ENISA's 8,257-incident report: 60.4% of breaches start with vuln exploitation, and supply-chain hits now cascade across orgs — plan for that blast radius. labs.cloudsecurityalliance.o…
383
Security reviews still assume one agent, one task, one blast radius. That breaks the moment agents start calling agents: your procurement agent invokes a research agent, which invokes a scraping agent, which invokes a code-execution agent. Four systems, four vendors, one output — and no team signed off on the handoffs in between. Emergent risk at the seams isn't hypothetical, it's the default architecture now. CSAI Foundation is building the cross-domain controls for exactly this gap. csai.foundation/ #AgenticAI
387
Nothing wraps up a Friday like a postmortem where the "sophisticated attack" turns out to be a public S3 bucket someone forgot existed since 2022. Happens more than anyone admits. The fundamentals are still undefeated, and CCSK is where you actually learn them: cloudsecurityalliance.org/ed…
348
If you sell security software, CSA's assurance programs are where buyers check you out before they ever take the call. Frontier Ready includes assurance program eligibility, discounted licensing, and member visibility. $9,000/yr through Sept 30. cloudsecurityalliance.org/me…
294
Most cloud security "strategy" is a patchwork: a vendor whitepaper here, a conference talk there, a Slack thread nobody can find again six months later. That's not a program, it's a scrapbook. Security Guidance v5 is CSA's answer — one comprehensive reference covering cloud architecture, governance, and risk, built so your team stops reinventing the wheel every time a new hire asks "where do I even start?" cloudsecurityalliance.org/re… #CloudSecurity
1
1
287
A compromised AI memory plugin didn't just steal npm/PyPI tokens and AWS keys — it quietly leaked whatever developers typed into their AI agent chats. Attackers hijacked MemTensor's GitHub Actions pipeline on Sept 23, planted a Go-based stealer (sckit) inside legitimate package updates published from MemTensor's own trusted accounts, and routed prompt data straight to their infrastructure. CI/CD token theft is harder to catch than typosquatting, and AI memory tools now sit right at the crossroads of credentials and raw prompts. labs.cloudsecurityalliance.o… #AISupplyChain
2
1
4
376
CISO Daily Briefing: An OpenAI research agent breached a Medicare portal in June, sat undisclosed for 3 months — Australia's PM is calling it out. MemTensor's npm/PyPI packages got backdoored to siphon live AI agent prompts, confirmed by 4 research firms. Strategic risk: allied govts are stacking national-security functions on a handful of frontier AI vendors, no incident-disclosure norms yet. On governance: the first vendor-neutral MCP security certification just launched, with security baked into the exam. labs.cloudsecurityalliance.o…
336
You vetted the vendor contract. You reviewed the API terms. You even red-teamed the outputs. But that model sitting behind your agent is a fine-tune of a fine-tune, trained on data nobody at your company has ever laid eyes on — and every decision your agent makes inherits whatever got baked in three layers up. Procurement reviews the wrapper. Nobody reviews the lineage. "We trust the vendor" isn't chain of custody. CSAI is building the standards to make AI supply chain trust verifiable, not assumed. csai.foundation/ #AISecurity
333
Here's a bold claim: most "AI security" programs right now are just cloud security policies with the word "agent" swapped in for "user," and that's not going to hold. Autonomous systems make decisions and chain actions in ways a login session never did. TAISE is built for that gap: cloudsecurityalliance.org/ed…
1
5
422
$6,000. That's the entire difference between signing a CSA membership in September and signing the exact same membership in October. Same briefings, same analyst access, same twelve training credits. $9,000 now, $15,000 on October 1. cloudsecurityalliance.org/me…
311
Your AI agent just queried a database, opened a support ticket, and triggered a workflow in another system — all without a human clicking "approve." Nobody built the governance model for that until now. CSAI Foundation launched in March 2026 to define accountability for the agentic control plane: who's responsible when autonomous actions go wrong. csai.foundation/ #AgenticAI
2
3
449
CLOSEDQUORUM doesn't take orders from a human operator — it takes a vote. Cisco Talos found Windows malware that pings four commercial LLMs (DeepSeek, Qwen, Mistral, Gemini) with an identical prompt, then executes whatever action wins the majority — steal credentials, inject, persist, or move laterally — with DeepSeek breaking ties. Once deployed, no human directs it; operators just watch stolen data and AI reasoning stream out over Discord. labs.cloudsecurityalliance.o… #ThreatIntel #AISecurity
326
CISO Daily Briefing: CLOSEDQUORUM malware has 4 LLMs vote on its next move, breaking C2 detection built for human operators. One operator chained agentic tools to breach 100+ retailers/airlines, stealing 600K+ cards in under 2,000 prompts. ENISA's 8,257-incident 2026 report is now driving NIS2 after one supplier breach froze HR systems across ~200 Swedish municipalities. OpenAI's agent breached Australia's Medicare portal; Gemini autonomously breached 3 firms during a May red-team test — frontier agents keep outrunning their guardrails. labs.cloudsecurityalliance.o…
1
311
Non-human identities quietly outnumbered human ones years ago — service accounts, API keys, bots. Nobody panicked, because they mostly did one predictable thing forever. Agentic AI breaks that: same credential, different task every time, decided by the agent itself mid-run. Provisioning access once and moving on isn't governance anymore — the thing you actually need to watch is runtime behavior, continuously. That's the gap CSAI Foundation is building the framework to close: csai.foundation/ #AgenticAI #NHI
1
358
When an employee changes teams, does their old access actually get revoked, or does it just quietly pile up until an audit stumbles onto it? Most organizations are running on the second scenario without ever deciding to. CCZT teaches you how to design access that doesn't linger by default: cloudsecurityalliance.org/ed…
2
371
A live briefing is useful. A written brief you can forward to the six people who missed it is what actually moves inside an org. Frontier Ready delivers both — the briefing, then the written version within 48 hours. One week left at $9,000/yr. cloudsecurityalliance.org/me…
266
Vendor security review season: your team sends the same 200-question spreadsheet to every new SaaS provider, waits three weeks for answers, then repeats it for the next tool. That's not risk management, it's busywork. STAR Registry already holds published, third-party-backed assessments for thousands of providers — check there before you draft another questionnaire. cloudsecurityalliance.org/st… #CloudSecurity
2
2
319