1. X
  2. CloudSecurityAlliance
Log inSign up
CloudSecurityAlliance
17.1K posts
Image
user avatar
CloudSecurityAlliance
@cloudsa
We lead in security of Cloud, AI and Zero Trust. Follow our research, education, certification and events.
Global
cloudsecurityalliance.org
Joined March 2009
267
Following
18.8K
Followers
RepliesRepliesMediaMedia
  • user avatar
    CloudSecurityAlliance
    @cloudsa
    50m
    A marketing team's agent needed data from three internal tools last month. It spun up three short-lived service identities to get it, then deleted itself an hour later. No ticket, no review, no one in IT ever saw it happen. Multiply that across every team running agents and your
    Image
    CSAI
    From csai.foundation
  • user avatar
    CloudSecurityAlliance
    @cloudsa
    3h
    Quick gut check: if a new hire asked you to point to the exact line where your cloud provider's responsibility ends and yours begins, could you do it without googling first? Most people who've worked in cloud for years still can't. CCSK is built to close that exact gap:
    cloudsecurityalliance.org
    Certificate of Cloud Security Knowledge (CCSK) | CSA
    The CCSK is an open-book, online exam, completed in 90 minutes with 60 multiple-choice questions selected randomly from the CCSK question pool.
  • user avatar
    CloudSecurityAlliance
    @cloudsa
    7h
    If your security page is the only proof of your controls, that's not proof—it's a claim. Prospects have no way to verify it, so they default to distrust (or worse, skip diligence and hope). STAR Registry flips that: publish your assessment where every buyer can check it against
    cloudsecurityalliance.org
    STAR | Cloud Security Alliance (CSA)
    The Security Trust Assurance and Risk (STAR) Program encompasses key principles of transparency, rigorous auditing, and harmonization of standards. Companies who use STAR indicate best practices and...
  • user avatar
    CloudSecurityAlliance
    @cloudsa
    12h
    CISO Daily Briefing: npm's keyv worm hijacked a maintainer account, hitting deps with 500M+ downloads/mo; Ruflo's MCP bridge had an unauth'd CVSS 10 RCE (CVE-2026-59726), patched but rogue policies persist; LiteLLM callback hooks enable tool-call hijacking, no patch exists. Four
    Image
    labs.cloudsecurityalliance.org
    CISO Daily Briefing – August 5, 2026
    CISO Daily Briefing Cloud Security Alliance Intelligence Report Report Date August 5, 2026 Intelligence Window 48 hours Topics Identified 5 Priority Items Papers Published 4 Overnight Executive Sum…
  • user avatar
    CloudSecurityAlliance
    @cloudsa
    Aug 5
    A product team gave an agent broad write access to a production database this week to unblock a launch. It worked in minutes. Security didn't hear about it until the retro. That's not a rogue engineer story — it's the default clock speed of agentic AI now: capability ships in
    Image
    CSAI
    From csai.foundation

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Advertisement
Advertisement