1. X
  2. CloudSecurityAlliance
Log inSign up
CloudSecurityAlliance
17.1K posts
Image
user avatar
CloudSecurityAlliance
@cloudsa
We lead in security of Cloud, AI and Zero Trust. Follow our research, education, certification and events.
Global
cloudsecurityalliance.org
Joined March 2009
267
Following
18.8K
Followers
RepliesRepliesMediaMedia
  • user avatar
    CloudSecurityAlliance
    @cloudsa
    4h
    We built software supply chain security around one idea: know your dependencies, track every version, trace every change. An SBOM tells you exactly what's in your code. Now ask what tells you what's in your agent's model — which checkpoint answered, what data trained it, what
    Image
    CSAI
    From csai.foundation
  • user avatar
    CloudSecurityAlliance
    @cloudsa
    7h
    Most companies treat AI security as a checkbox for after launch — ship the agent, then bolt on guardrails once someone in legal asks a hard question. By then it's already touched every system you didn't mean to expose it to. TAISE is for teams who'd rather design that control in
    cloudsecurityalliance.org
    Trusted AI Safety Expert (TAISE) Certificate | CSA
    Built by CSA and Northeastern University, gain skills in AI safety, governance, and security with TAISE. Advance your career with the world's first trusted AI safety credential.
  • user avatar
    CloudSecurityAlliance
    @cloudsa
    11h
    Ask around your org: who owns the security of your AI agents once they start acting on their own? AppSec says it's a model problem. The AI team says it's a security problem. Cloud security says it's not in their remit. Meanwhile the agent has API access and nobody's name is on
    Image
    CSAI
    From csai.foundation
  • user avatar
    CloudSecurityAlliance
    @cloudsa
    15h
    Three separate agent platforms — AWS Bedrock AgentCore, Google's Agent Development Kit, Vercel AI SDK — just got flagged for the same structural flaw, dubbed CoreBreak: attackers can trigger tool execution by forging tool-call blocks that skip the model turn entirely. No prompt
    Image
    labs.cloudsecurityalliance.org
    When the Model Never Runs: Agent Guardrail Bypasses
    Key Takeaways Researchers disclosed a cross-platform vulnerability pattern, dubbed CoreBreak, showing that the tool-execution layers of Amazon Bedrock AgentCore, Google’s Agent Development Ki…
  • user avatar
    CloudSecurityAlliance
    @cloudsa
    15h
    CISO Daily Briefing: Patch TeamCity now — CVE-2026-63077 (CVSS 9.8), added to CISA's KEV, Aug 8 deadline, build-server creds at risk. CoreBreak flaws in AWS Bedrock, Google ADK, Vercel's AI SDK trigger tool calls with zero model turn, bypassing filters; all three patched.
    Image
    labs.cloudsecurityalliance.org
    CISO Daily Briefing – August 6, 2026
    CISO Daily Briefing Cloud Security Alliance Intelligence Report Report Date August 6, 2026 Intelligence Window 48 hours Topics Identified 5 Priority Items Papers Published 4 Overnight Executive Sum…

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Advertisement
Advertisement