1. X
  2. CloudSecurityAlliance
Log inSign up
CloudSecurityAlliance
17.1K posts
Image
user avatar
CloudSecurityAlliance
@cloudsa
We lead in security of Cloud, AI and Zero Trust. Follow our research, education, certification and events.
Global
cloudsecurityalliance.org
Joined March 2009
267
Following
18.8K
Followers
RepliesRepliesMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • user avatar
    CloudSecurityAlliance
    @cloudsa
    1h
    Most STRIDE and DFD threat models assume a human approves the risky step. Agentic AI breaks that assumption — the agent plans, remembers, and acts on its own, often chaining tool calls with nobody watching in real time. Your existing model has no box for "agent memory got
    cloudsecurityalliance.org
    Latest Research | Cloud Security Alliance (CSA)
    Download CSA research that guides organizations on how to improve cloud security, whether they are new adopters of the cloud or current innovators.
    126
  • user avatar
    CloudSecurityAlliance
    @cloudsa
    5h
    No malware, no VM escape needed — just authorized GPU workloads, deliberately timed. Zhejiang University's Bit2Watt research shows AI training jobs can be modulated to create power oscillations current grid telemetry literally can't see (monitoring tops out near 1kHz; the attack
    Image
    labs.cloudsecurityalliance.org
    Bit2Watt: GPU Workloads as a Power Grid Attack Vector
    Key Takeaways Researchers from Zhejiang University have demonstrated Bit2Watt, a cyber-physical attack in which a cloud tenant uses only its own legitimately provisioned GPU access to induce power …
    201
  • user avatar
    CloudSecurityAlliance
    @cloudsa
    6h
    CISO Daily Briefing: Patch AND rotate keys for SharePoint's actively-exploited zero-day (CVE-2026-50522, CVSS 9.8) — forged tokens survive patching alone. Azure DevOps' MCP server has an unpatched flaw where hidden PR comments hijack AI review agents into malicious approvals. EU
    Image
    labs.cloudsecurityalliance.org
    CISO Daily Briefing – August 1, 2026
    CISO Daily Briefing Cloud Security Alliance Intelligence Report Report Date August 1, 2026 Intelligence Window 48 hours Topics Identified 5 Priority Items Papers Published 5 Overnight Executive Sum…
    270
  • user avatar
    CloudSecurityAlliance
    @cloudsa
    18h
    We spent a decade locking down service-to-service calls — mTLS, API gateways, rate limits, an audit trail on every hop. Then agents started calling other agents to get work done, and most of that rigor quietly vanished. One agent invokes a second, which invokes a third, and the
    Image
    CSAI
    From csai.foundation
    296
  • user avatar
    CloudSecurityAlliance
    @cloudsa
    21h
    Nothing derails a Friday quite like a 4:45pm Slack message asking "quick question, is this bucket public?" Everyone else logs off, you're now three tabs deep in IAM policies. CCSK is how you know the answer before the question ever gets asked:
    cloudsecurityalliance.org
    Certificate of Cloud Security Knowledge (CCSK) | CSA
    The CCSK is an open-book, online exam, completed in 90 minutes with 60 multiple-choice questions selected randomly from the CCSK question pool.
    300
  • See @cloudsa's full profile

    Sign up
    Log in
Advertisement
Advertisement