Cloud Security Alliance Blog
Blog
CSA Cloud Files is an easily accessible repository of research and organizational downloads from the Cloud Security Alliance. Source
Actions
Media Outlet details
| Scope | Trade/B2B |
|---|---|
| Language | English |
| Country | United States of America |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesNew Chaos Malware Variant Exploiting Misconfigurations in the Cloud
Originally published by Darktrace. Introduction To observe adversary behavior in real time, Darktrace operates a global honeypot network known as “CloudyPots”, designed to capture malicious activity across a wide range of services, protocols, and cloud platforms. These honeypots provide valuable insights into the techniques, tools, and malware actively targeting internet‑facing infrastructure.
7 Claude Tag Security Risks: The Agent Identity Gap
Anthropic's Claude Tag places an AI agent inside shared Slack channels with its own identity in connected systems. Rather than borrowing a person's credentials, the agent authenticates as itself, holds its own permissions, and acts for everyone in the channel. The design solves a real problem: it keeps a shared channel from becoming a side door into private accounts, and gives every action a clean, revocable owner. It also relocates the hardest decision. Agent identity settles who acted.
The Human Factor of AI and Coding
Written by Eyal Estrin, Author, Cloud Security Architect at Undisclosed. Since the beginning of the hype around GenAI (around 2023), no week goes by without a headline similar to “Is AI going to replace developers?” So, has the technology evolved that much that developers can drink a margarita on the beach while an AI agent or AI coding assistance completely replaces developers?
GDPR, NIS 2, and DORA Converge on One Problem: Third-Party Risk
Regulators no longer ask whether you manage vendor risk—they assume you do. And if you don’t, you pay for it. Three independent EU regulations, the GDPR, NIS 2 directive, and Digital Operations Resilience Act (DORA), stress that it’s your responsibility to manage third-party risk. These regulations offer security frameworks that support different industries and risk profiles, but they all lead with strict fines and pressure to enforce third-party risk management.
What is ISO 9001? Everything You Need to Know About This Key Quality Management Standard
ISO 9001 is an internationally recognized standard that helps organizations across industries demonstrate their commitment to quality. The standard outlines baseline requirements for establishing, implementing, maintaining, and continually improving what’s known as a quality management system (QMS).
A Network Security Strategy for AI-Accelerated Attacks
AI is changing the speed of offensive security. Attackers are rapidly identifying vulnerabilities that once took months or years to discover and exploit. The technical barriers required to turn those vulnerabilities into attacks are rapidly collapsing. For network defenders, that means a familiar set of best practices (patching, segmentation, visibility) now has to operate on a very different timeline.
The Hidden Cost of Shorter Certificate Lifecycles: Why DNSPM Matters More Than Ever
The Industry is Focusing on Certificate Renewal. It Should Be Focusing on Visibility. When the CA/Browser Forum approved the roadmap to reduce certificate validity periods, the industry response was largely positive. The logic was difficult to argue with. If a certificate is compromised, a shorter validity period limits how long it can be abused. It also encourages organizations to automate certificate issuance and renewal processes rather than relying on manual intervention.
Jack of All Trades: Designing Meta-Cognition for Agentic AI
Written by Dr. Chantal Spleiss. AI excels in closed systems; the real world, though, is open. When real-world data is analyzed through high-speed correlation but without anchoring the outputs in context, data driven decision-making is at risk. Humanity eliminated the "Jack of all Trades" — the integrator — and is now replicating that fragmented, multi-expert culture into AI, emphasizing silos while trying to escape them.
Agent vs. Agentless Cloud Security: Why Deployment Methods Matter
The rapid adoption of cloud technologies has brought significant security challenges for organizations of all sizes. According to recent studies, over 70% of enterprises now operate in hybrid or multi-cloud environments, with 93% employing a multi-cloud strategy[1]. This complexity requires robust security tools, but opinions vary on the best deployment method—agent-based, agentless, or a combination of both.
Cloud Disaster Recovery vs. Ransomware: The Cyber-Resilience Gap
TL;DR The threat model has changed. Cloud DR was built to recover from passive failure. Ransomware is an adversary that has been inside the environment for weeks, mapping your recovery so it fails when you need it. The gap is measurable. In Veeam's 2026 Data Trust and Resilience Report, 90% of organizations said they could recover from a cyber incident. Fewer than 1 in 3 ransomware victims actually did. The familiar cloud safety net was built for a different problem. Replication isn't a backup.