Every major cloud platform has a control plane with real governance behind it — standards bodies, benchmarks, years of scrutiny. Agentic AI doesn't have that yet. Agents are authenticating, acting, and handing off tasks to each other with no dedicated body setting the rules. CSAI
We lead in security of Cloud, AI and Zero Trust. Follow our research, education, certification and events.
- Sandworm's latest trick hides malware in a VPN config file, not an executable. UAC-0145 poses as recruiters (Sopra Steria, ATLAS Business Group), runs candidates through weeks of Zoom "interviews," then has them install a "corporate VPN" for a technical assignment. It's
- CISO Daily Briefing: VMware vCenter CVE-2026-59310 (CVSS 9.8) is under active exploit in 47 countries, no workaround — patch now. Lazarus is weaponizing a new afd.sys kernel 0-day (CISA deadline Aug 25). Gov: NIST joined the $5B+ Genesis Mission, pushing AI agents into critical
- Genuine question: could you walk a new security hire through where your cloud provider's job ends and your team's begins — without pulling up a diagram? A surprising number of people who use cloud daily have never actually mapped that line. CCSK exists to make it second nature:
- Vendor risk teams still send the same 200-question security survey to every cloud provider, then wait weeks for answers nobody fully verifies. Skip it: STAR Registry already has thousands of providers listed with self-assessments, third-party audits, or continuous monitoring

