Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog

All Articles

All Articles
RiskRubric Updates: AI Risk Assessment for the Agentic Era

Blog Published: 06/08/2026

RiskRubric, CSA’s evidence-based risk rating system for AI technologies, is getting some timely updates. These updates aim to expand AI risk assessment beyond the model layer, reduce blind spots, and address maturing threats. The upcoming updates to RiskRuric include: A multi-scanner e...

CSAI Foundation Announces RiskRubric V2 as the Next Key Milestone to Secure the Agentic Control Plane

Press Release Published: 06/08/2026

Deloitte Italy, PointGuardAI, and Tumeryk partner with CSA to evolve the reference framework for assessing the security of AI systems SEATTLE – June 8, 2026 — Cloud Security Alliance (CSA), the world's leading not-for-profit organization committed to AI, cloud, and Zero Trust cybersecurity...

Financial Services Industry Shifts from AI Adoption to Governance as Autonomous Systems Proliferate, Cloud Security Alliance Survey Finds

Press Release Published: 06/09/2026

As AI systems gain ground in financial sector, limited visibility raises flags about governance and risk management SEATTLE – June 9, 2026 — A new survey from the Cloud Security Alliance (CSA), the world's leading not-for-profit organization committed to AI, cloud, and Zero Trust cybersecur...

AI Has Turned Cloud Risk Into a Race and Human Defenders are Losing

Blog Published: 06/12/2026

Originally published by Skyhawk Security. Cloud security used to be framed as a posture problem: find the critical vulnerabilities, fix the most severe misconfigurations, and reduce the visible attack surface. That model is no longer enough. The defining change is not...

What Claude Mythos Reveals About the Future of Cybersecurity

Blog Published: 06/22/2026

It is tempting to read Mythos as a weapon that arrived overnight. It is more useful to treat Mythos as two things at once: an audit you have already failed, and an alarm for the attacks you have not yet seen. When Anthropic unveiled Claude Mythos Preview in April 2026, the headlines wrote th...

5 Claude Agent Skills Risks Every CISO Should Know

Blog Published: 06/25/2026

The SKILL .md file is the new package.json. And it's already compromised. Developers and business users trust Claude Skills the way engineers once trusted npm packages. Install a skill on Claude Code, claude.ai, or via the API. Extend the agent's capabilities. Ship faster. But the parallel...

Is Financial Services Ready for Agentic Payments?

Blog Published: 06/23/2026

Imagine telling an AI assistant: “Find me the best flight to Chicago next Thursday. Book a hotel within walking distance of the conference center, stay under my travel budget, and use my rewards points if it makes sense.” Now imagine that assistant not only making recommendations, but actual...

Dangling CNAMEs: The Critical DNS Misconfiguration Most Organizations Still Miss

Blog Published: 06/25/2026

In cybersecurity, the most damaging attacks are not always the most sophisticated. Sometimes, they begin with something as mundane as a forgotten DNS record. That reality came into sharp focus when researchers uncovered a large-scale campaign involving hijacked university subdomains across i...

Securing the Swarm: Governance, Attack Surfaces, and Zero-Trust Architectures in Multi-Agent AI Environments

Blog Published: 06/24/2026

EXECUTIVE SUMMARY Enterprise artificial intelligence has transitioned from isolated, static Large Language Model (LLM) prompts to dynamic, multi-agent systems (MAS) operating at high levels of operational autonomy. While these systems dramatically accelerate software develop...

Proof is the Application Security Bottleneck

Blog Published: 07/01/2026

For years, application security programs have focused on a single goal: finding vulnerabilities earlier in the software lifecycle. We've invested heavily in shift-left security, app security testing, CI/CD scanning, and dev-focused remediation workflows. But according to CSA and Miggo Sec...

Agentic AI Red Teaming: Tool Misuse is the Test That Matters

Blog Published: 06/29/2026

Agentic AI changes the red teaming conversation. Traditional generative AI testing often focuses on whether a model will produce harmful text. Agentic AI raises the question of what happens when an AI system can plan, reason, and interact with tools, workflows, and downstream systems. That i...

How AI Governance and Data Governance Are Converging in the Cloud

Blog Published: 06/30/2026

Businesses of all sizes are dabbling in data and AI. And as they scale, they’re becoming increasingly aware of the need to develop strict data and AI governance oversight and protocols. However, they’re not always interested in purchasing the equipment and software needed to keep their data ...

AI Security Asymmetry: Why Speed Alone Won't Save Defenders

Blog Published: 07/03/2026

AI has made something painfully clear: finding vulnerabilities faster does not automatically make an organization safer. That may sound odd, since vulnerability discovery has long been one of the hardest parts of cybersecurity. If a tool can identify more flaws, analyze more logs, and prio...

Validating LLM-Generated Control Mappings Beyond Aggregate Accuracy

Blog Published: 07/02/2026

Security control frameworks continue to grow in scope and complexity. The CSA AI Controls Matrix (AICM) alone has 243 control objectives. NIST CSF has hundreds of subcategories. Organizations operating under multiple frameworks need to map between them for compliance cross-referencing, gap ...

Quantum Computing & AI: When AI Starts Writing Quantum Code

Blog Published: 07/10/2026

We often discuss quantum computing and artificial intelligence as separate revolutions. One promises to change what is computationally possible. The other is already changing how organizations build software, analyze data, and automate decisions. But the more interesting question may be what ...

The Role of CSA STAR in Vendor Security Assessments

Blog Published: 07/13/2026

Most organizations operate across complex digital ecosystems that include cloud providers, SaaS platforms, API integrations, and outsourced infrastructure.  While these technologies enable scalability and operational efficiency, they also introduce additional security considerations. As...

Top 6 Claude Cowork Security Risks to Watch

Blog Published: 07/08/2026

Most security teams evaluate Claude Cowork as if it were a chatbot with extra buttons. It isn't. Cowork is a local agent that runs on the employee's machine, reads their files, runs shell commands, browses the web with their logged-in cookies, and connects to the enterprise systems they can...

AI Regulation Keeps Evolving: How to Develop an AI Governance Framework That Adapts

Blog Published: 07/06/2026

The regulatory landscape for AI is shifting rapidly between evolving federal policies, an explosion of state-level legislation, and the emergence of industry-specific compliance requirements. Many organizations know they need AI governance but may face uncertainty about how to navigate the ...

The SaaS Security Problem Most Organizations Still Treat Like an IT Issue

Blog Published: 07/09/2026

For years, organizations approached SaaS security as an access management problem. Enable SSO. Turn on MFA. Provision users correctly. Deprovision them quickly. Audit permissions periodically. That model no longer reflects how modern SaaS breaches actually happen. The recent ADT breach att...

SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon

Blog Published: 06/24/2026

Varonis Threat Labs discovered SearchLeak, a critical vulnerability chain in Microsoft 365 Copilot Enterprise that allows an attacker to steal sensitive data — MFA codes, email messages, meeting details, and private organizational files — with a single click. Varonis Threat Labs has u...

Looking for the CCM?

Start using the Cloud Controls Matrix to simplify compliance with multiple standards & regulations.