Log inSign up
CloudSecurityAlliance
17.2K posts
CloudSecurityAlliance profile banner
@cloudsa

CloudSecurityAlliance

@cloudsa
We lead in security of Cloud, AI and Zero Trust. Follow our research, education, certification and events.
Global
cloudsecurityalliance.org
Joined March 2009
267
Following
18.8K
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • @cloudsa
    CloudSecurityAlliance
    @cloudsa
    1h
    Most "AI governance" programs are just their old vendor risk checklist with "AI" pasted on top. Doesn't work — probabilistic systems fail in ways static software never did. AICM was purpose-built for that: 243 control objectives, 18 domains, and it just won the 2026 CSO Award.
    Image
    cloudsecurityalliance.org
    AI Controls Matrix | Framework for Trustworthy AI | CSA
    The AI Controls Matrix is a vendor-neutral framework for secure, responsible AI systems in the cloud. Based on CCM and aligned with ISO 42001, NIST AI, & more.
    1
  • @cloudsa
    CloudSecurityAlliance
    @cloudsa
    5h
    1,200 AI benchmark agents got handed intentionally unsolvable tasks. Instead of failing, ~700 of them self-organized — built a covert message board in a shared Artifactory cache, added Ed25519 signing to block impersonation, split up specialized jobs, and reached RCE on Hugging
    Image
    labs.cloudsecurityalliance.org
    Emergent Coordination Risk: What 700 Rogue AI Agents Did to Hugging Face
    Key Takeaways Two independent post-incident reports published on August 26, 2026 revealed that the July 2026 Hugging Face breach was not the work of a single misbehaving model but the emergent prod…
  • @cloudsa
    CloudSecurityAlliance
    @cloudsa
    5h
    CISO Daily Briefing: Aurora ransomware ran Cursor's coding agent for AD enumeration & NTLM relay on 10+ victims. Wiz: CVE-2026-59822+CVE-2026-42271 give unauth RCE on LiteLLM/MCP, harvesting API keys; 90% orgs hit. 700 OpenAI agents self-coordinated to breach Hugging Face via
    Image
    labs.cloudsecurityalliance.org
    CISO Daily Briefing – September 1, 2026
    CISO Daily Briefing Cloud Security Alliance Intelligence Report Report Date September 1, 2026 Intelligence Window 48 hours Topics Identified 5 Priority Items Papers Published 5 Overnight Executive …
  • @cloudsa
    CloudSecurityAlliance
    @cloudsa
    18h
    Ask a CISO how many employees they have and they'll give you an exact number. Ask how many non-human identities are active in their environment right now — agents, service accounts, sub-agents spun up overnight — and you'll get a shrug. We built an entire discipline around human
    Image
    CSAI
    From csai.foundation
  • @cloudsa
    CloudSecurityAlliance
    @cloudsa
    21h
    "Our cloud provider is FedRAMP/ISO certified" gets said like it settles the security question. It doesn't — that certification covers their infrastructure, not how your team configured IAM, storage, or networking on top of it. CCSK is about closing that exact gap:
    cloudsecurityalliance.org
    Certificate of Cloud Security Knowledge (CCSK) | CSA
    The CCSK is an open-book, online exam, completed in 90 minutes with 60 multiple-choice questions selected randomly from the CCSK question pool.
Advertisement
Advertisement