Log inSign up
CloudSecurityAlliance
17.2K posts
CloudSecurityAlliance profile banner
@cloudsa

CloudSecurityAlliance

@cloudsa
We lead in security of Cloud, AI and Zero Trust. Follow our research, education, certification and events.
Global
cloudsecurityalliance.org
Joined March 2009
267
Following
18.8K
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • @cloudsa
    CloudSecurityAlliance
    @cloudsa
    1h
    Ask a CISO how many employees they have and they'll give you an exact number. Ask how many non-human identities are active in their environment right now — agents, service accounts, sub-agents spun up overnight — and you'll get a shrug. We built an entire discipline around human
    Image
    CSAI
    From csai.foundation
  • @cloudsa
    CloudSecurityAlliance
    @cloudsa
    4h
    "Our cloud provider is FedRAMP/ISO certified" gets said like it settles the security question. It doesn't — that certification covers their infrastructure, not how your team configured IAM, storage, or networking on top of it. CCSK is about closing that exact gap:
    cloudsecurityalliance.org
    Certificate of Cloud Security Knowledge (CCSK) | CSA
    The CCSK is an open-book, online exam, completed in 90 minutes with 60 multiple-choice questions selected randomly from the CCSK question pool.
  • @cloudsa
    CloudSecurityAlliance
    @cloudsa
    7h
    Every audit season, someone maps the same controls to SOC 2, ISO 27001, and NIST all over again — by hand, from scratch, like it's never been done before. It has. CCM v4.1 already cross-maps 207 controls across 17 domains to the major frameworks, free, vendor-neutral. Stop
    cloudsecurityalliance.org
    Cloud Controls Matrix | CSA
    The CSA Cloud Controls Matrix (CCM) is a framework created by the Cloud Security Alliance (CSA) to help organizations assess the security of cloud service providers (CSPs). It provides security...
  • @cloudsa
    CloudSecurityAlliance
    @cloudsa
    7h
    A poisoned MCP server just beat install-time security review by doing nothing malicious at install time. Dubbed Deadbugz, it silently counts your tool calls — only after the 3rd one does its tool list flip to steal SSH keys, AWS creds, and kube configs. Pushed via 23 GitHub PRs
    Image
    labs.cloudsecurityalliance.org
    Deadbugz: Active MCP Campaign Poisons Agents After Trust
    Key Takeaways Security researchers at Pillar Security identified an active campaign, dubbed “Deadbugz,” that distributes a malicious Model Context Protocol (MCP) server through public G…
  • @cloudsa
    CloudSecurityAlliance
    @cloudsa
    7h
    CISO Daily Briefing: Wiz honeypot data — AI-infra attacks doubled in 6mo; MCP servers in ~80% of environments, 5% net-exposed; CVE-2026-59822/CVE-2026-42271 chain to CVSS 10 unauth RCE. Unit 42: LLM safety refusal sits in ~50 of 350K neurons, trivially ablated. APT28's HOOKEDGE
    Image
    Webhook.site
    From webhook.site
Advertisement
Advertisement