A marketing team's agent needed data from three internal tools last month. It spun up three short-lived service identities to get it, then deleted itself an hour later. No ticket, no review, no one in IT ever saw it happen. Multiply that across every team running agents and your
We lead in security of Cloud, AI and Zero Trust. Follow our research, education, certification and events.
- Quick gut check: if a new hire asked you to point to the exact line where your cloud provider's responsibility ends and yours begins, could you do it without googling first? Most people who've worked in cloud for years still can't. CCSK is built to close that exact gap:
- If your security page is the only proof of your controls, that's not proof—it's a claim. Prospects have no way to verify it, so they default to distrust (or worse, skip diligence and hope). STAR Registry flips that: publish your assessment where every buyer can check it against
- CISO Daily Briefing: npm's keyv worm hijacked a maintainer account, hitting deps with 500M+ downloads/mo; Ruflo's MCP bridge had an unauth'd CVSS 10 RCE (CVE-2026-59726), patched but rogue policies persist; LiteLLM callback hooks enable tool-call hijacking, no patch exists. Four
- A product team gave an agent broad write access to a production database this week to unblock a launch. It worked in minutes. Security didn't hear about it until the retro. That's not a rogue engineer story — it's the default clock speed of agentic AI now: capability ships in

