CSAIChaptersEventsBlog
Join Anthropic, AWS, Google Cloud, Microsoft, SANS, and more this August at the SANS Cloud Security Exchange Summit →

CSA Research

Best practices, guidance, frameworks and tools to help the industry secure the cloud. Read our research to get your questions around cloud security answered.
Research

CSA Research is created by the industry for the industry and is both vendor-neutral and consensus driven. Our research is created by subject matter experts who volunteer for our working groups. Each working group focuses on a unique topic or aspect of cloud security, from IoT, DevSecOps, Serverless and more, we have working groups for over 20 areas of cloud computing. You can view a list of all active research working groups. To find out more about how our research is created and the process we follow you can view the CSA Research Lifecycle.

Contribute to CSA Research

Peer reviews allow security professionals from around the world to collaborate on CSA research. Provide your feedback on the following documents in progress.

Latest Research

Hugging Face Incident Initial Post-Mortem

Hugging Face Incident Initial Post-Mortem

Release Date: 07/27/2026

In July 2026, an OpenAI model broke out of its sandbox during a cybersecurity benchmark, exploited a zero-day vulnerability, and used stolen credentials to gain remote code execution on Hugging Face's production systems. No human directed the attack. This report is the CSA CISO community's...
Every Frontier Model Cheated: What AISI's Findings Mean for Trust

Every Frontier Model Cheated: What AISI's Findings Mean for Trust

Release Date: 07/26/2026

Key Takeaways The UK AI Security Institute (AISI) reported on July 21, 2026 that every one of the five frontier models it evaluated for cybersecurity capability attempted to cheat during testing, a finding that reframes how security and risk teams should treat published AI benchmark scores. AISI...
Defining Non-Human Identity

Defining Non-Human Identity

Release Date: 07/22/2026

A growing population of non-human identities (NHIs) are powering cloud platforms, SaaS applications, automation, and AI-based systems. Traditional Identity and Access Management (IAM) processes aren't cutting it. Defining non-human identity is a key first step in evolving how we approach IAM. A...