<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Cloud Security Alliance</title>
    <description>The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment.</description>
    <link>https://cloudsecurityalliance.org/feed</link>
    <language>en</language>
    <item>
      <title>SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon</title>
      <pubDate>Wed, 24 Jun 2026 14:30:04 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/searchleak-how-we-turned-m365-copilot-into-a-one-click-data-exfiltration-weapon</link>
      <guid>https://cloudsecurityalliance.org/articles/searchleak-how-we-turned-m365-copilot-into-a-one-click-data-exfiltration-weapon</guid>
      <description>
  


Varonis Threat Labs discovered SearchLeak, a critical vulnerability chain in Microsoft 365 Copilot Enterprise that allows an attacker to steal sensitive data — MFA codes, email messages, meeting details, and private organizational files — with a single click.

Varonis Threat Labs&amp;nbsp;has uncovered a new three-stage vulnerability chain that turns Microsoft 365 Copilot Enterprise Search into a silent data exfiltration weapon.

Dubbed SearchLeak, the chain combines a relatively new class ...</description>
    </item>
    <item>
      <title>Securing the Swarm: Governance, Attack Surfaces, and Zero-Trust Architectures in Multi-Agent AI Environments</title>
      <pubDate>Mon, 08 Jun 2026 17:27:42 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/securing-the-swarm-governance-attack-surfaces-and-zero-trust-architectures-in-multi-agent-ai-environments</link>
      <guid>https://cloudsecurityalliance.org/articles/securing-the-swarm-governance-attack-surfaces-and-zero-trust-architectures-in-multi-agent-ai-environments</guid>
      <description>
  



	
		
			
			EXECUTIVE SUMMARY
			Enterprise artificial intelligence has transitioned from isolated, static Large Language Model (LLM) prompts to dynamic, multi-agent systems (MAS) operating at high levels of operational autonomy. While these systems dramatically accelerate software development, supply chain orchestration, and threat response, they introduce unprecedented security blind spots that render legacy identity, data protection, and boundary defense mechanisms obsolete. This bl...</description>
    </item>
    <item>
      <title>Dangling CNAMEs: The Critical DNS Misconfiguration Most Organizations Still Miss</title>
      <pubDate>Mon, 08 Jun 2026 17:27:25 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/dangling-cnames-the-critical-dns-misconfiguration-most-organizations-still-miss</link>
      <guid>https://cloudsecurityalliance.org/articles/dangling-cnames-the-critical-dns-misconfiguration-most-organizations-still-miss</guid>
      <description>
  
In cybersecurity, the most damaging attacks are not always the most sophisticated. Sometimes, they begin with something as mundane as a forgotten DNS record.

That reality came into sharp focus when researchers uncovered a large-scale campaign involving hijacked university subdomains across institutions including UC Berkeley, Columbia University, and Washington University in St. Louis. Attackers exploited abandoned CNAME records to take control of trusted .edu subdomains and use them to h...</description>
    </item>
    <item>
      <title>Is Financial Services Ready for Agentic Payments?</title>
      <pubDate>Mon, 08 Jun 2026 17:26:58 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/is-financial-services-ready-for-agentic-payments</link>
      <guid>https://cloudsecurityalliance.org/articles/is-financial-services-ready-for-agentic-payments</guid>
      <description>
  
Imagine telling an AI assistant: “Find me the best flight to Chicago next Thursday. Book a hotel within walking distance of the conference center, stay under my travel budget, and use my rewards points if it makes sense.”

Now imagine that assistant not only making recommendations, but actually completing the purchases on your behalf. No extra approvals, switching between apps, or manually entering payment information.

That is the emerging reality of agentic payments.

AI agents are quic...</description>
    </item>
    <item>
      <title>5 Claude Agent Skills Risks Every CISO Should Know</title>
      <pubDate>Mon, 08 Jun 2026 17:26:44 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/5-claude-agent-skills-risks-every-ciso-should-know</link>
      <guid>https://cloudsecurityalliance.org/articles/5-claude-agent-skills-risks-every-ciso-should-know</guid>
      <description>
  
The SKILL.md file is the new package.json. And it's already compromised.

Developers and business users trust Claude Skills the way engineers once trusted npm packages. Install a skill on Claude Code, claude.ai, or via the API. Extend the agent's capabilities. Ship faster.

But the parallels don't stop at convenience. They extend to the attack surface.

Over the past six months, security researchers have converged on the same finding: the Claude agent skills ecosystem carries systemic sec...</description>
    </item>
    <item>
      <title>What Claude Mythos Reveals About the Future of Cybersecurity</title>
      <pubDate>Mon, 08 Jun 2026 17:25:33 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/what-claude-mythos-reveals-about-the-future-of-cybersecurity</link>
      <guid>https://cloudsecurityalliance.org/articles/what-claude-mythos-reveals-about-the-future-of-cybersecurity</guid>
      <description>
  
It is tempting to read Mythos as a weapon that arrived overnight. It is more useful to treat Mythos as two things at once: an audit you have already failed, and an alarm for the attacks you have not yet seen.

When Anthropic unveiled Claude Mythos Preview in April 2026, the headlines wrote themselves. A model too dangerous to release. Thousands of vulnerabilities surfaced across every major operating system and browser. A 27-year-old flaw in OpenBSD, an operating system whose entire reput...</description>
    </item>
    <item>
      <title>AI Has Turned Cloud Risk Into a Race and Human Defenders are Losing</title>
      <pubDate>Mon, 08 Jun 2026 17:20:44 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/ai-has-turned-cloud-risk-into-a-race-and-human-defenders-are-losing</link>
      <guid>https://cloudsecurityalliance.org/articles/ai-has-turned-cloud-risk-into-a-race-and-human-defenders-are-losing</guid>
      <description>
  


Originally published by&amp;nbsp;Skyhawk Security.

Cloud security used to be framed as a&amp;nbsp;posture&amp;nbsp;problem: find&amp;nbsp;the critical&amp;nbsp;vulnerabilities, fix the most severe misconfigurations, and reduce the visible attack surface. That model is no longer enough. The defining change is not that artificial intelligence has created a completely new class of attacks. The change is that AI helps attackers move faster, connect more weak&amp;nbsp;posture findings, and operationalize attack pa...</description>
    </item>
    <item>
      <title>Financial Services Industry Shifts from AI Adoption to Governance as Autonomous Systems Proliferate, Cloud Security Alliance Survey Finds</title>
      <pubDate>Mon, 08 Jun 2026 15:49:45 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/financial-services-industry-shifts-from-ai-adoption-to-governance-as-autonomous-systems-proliferate-cloud-security-alliance-survey-finds</link>
      <guid>https://cloudsecurityalliance.org/articles/financial-services-industry-shifts-from-ai-adoption-to-governance-as-autonomous-systems-proliferate-cloud-security-alliance-survey-finds</guid>
      <description>
  

As AI systems gain ground in financial sector, limited visibility raises flags about governance and risk management

SEATTLE – June 9, 2026 — A new survey from the Cloud Security Alliance (CSA), the world's leading not-for-profit organization committed to AI, cloud, and Zero Trust cybersecurity education, found that the financial services sector has moved beyond debating whether to adopt Artificial Intelligence (AI), and is now grappling with how to govern it effectively before autonomy ...</description>
    </item>
    <item>
      <title>CSAI Foundation Announces RiskRubric V2 as the Next Key Milestone to Secure the Agentic Control Plane</title>
      <pubDate>Thu, 04 Jun 2026 14:33:14 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/csai-foundation-announces-riskrubric-v2-as-the-next-key-milestone-to-secure-the-agentic-control-plane</link>
      <guid>https://cloudsecurityalliance.org/articles/csai-foundation-announces-riskrubric-v2-as-the-next-key-milestone-to-secure-the-agentic-control-plane</guid>
      <description>
  


Deloitte Italy, PointGuardAI, and Tumeryk partner with CSA to evolve the reference framework for assessing the security of AI systems

SEATTLE – June 8, 2026 — Cloud Security Alliance (CSA), the world's leading not-for-profit organization committed to AI, cloud, and Zero Trust cybersecurity education, today announced the upcoming launch of RiskRubric V2, the next key milestone in expanding the CSAI Foundation's capacity to deliver on its 2026 mission of Securing the Agentic Control Plan...</description>
    </item>
    <item>
      <title>RiskRubric Updates: AI Risk Assessment for the Agentic Era</title>
      <pubDate>Thu, 04 Jun 2026 11:31:10 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/riskrubric-updates-ai-risk-assessment-for-the-agentic-era</link>
      <guid>https://cloudsecurityalliance.org/articles/riskrubric-updates-ai-risk-assessment-for-the-agentic-era</guid>
      <description>
  

RiskRubric, CSA’s evidence-based risk rating system for AI technologies, is getting some timely updates. These updates aim to expand AI risk assessment beyond the model layer, reduce blind spots, and address maturing threats. 

The upcoming updates to RiskRuric include:


	A multi-scanner ecosystem powered by independent partners Deloitte Italy, PointGuard, and Tumeryk.
	Expanded assessment coverage beyond AI models to include MCP servers and AI agents.
	Modernized evaluation pillars add...</description>
    </item>
    <item>
      <title>Over 80% of Organizations that Miss 24-Hour Patch Window Report Security Incidents Involving Known Vulnerabilities</title>
      <pubDate>Mon, 01 Jun 2026 17:48:19 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/over-80-of-organizations-that-miss-24-hour-patch-window-report-security-incidents-involving-known-vulnerabilities</link>
      <guid>https://cloudsecurityalliance.org/articles/over-80-of-organizations-that-miss-24-hour-patch-window-report-security-incidents-involving-known-vulnerabilities</guid>
      <description>
  



	Survey of 900+ security leaders shows runtime is the breach battlefield
	Even pre-production controls are not stopping known vulnerabilities in the AI age, as 82% of organizations lack real-time visibility into AI runtime behavior.


NEW YORK, June 2, 2026 – The Cloud Security Alliance (CSA), the world's leading not-for-profit organization committed to AI, cloud, and Zero Trust cybersecurity education, has released the 2026 State of Modern Application &amp;amp; AI Security Report. The rep...</description>
    </item>
    <item>
      <title>Designing Agentic AI Systems with the ORCHIDEAS Framework</title>
      <pubDate>Thu, 28 May 2026 09:26:09 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/designing-agentic-ai-systems-with-the-orchideas-framework</link>
      <guid>https://cloudsecurityalliance.org/articles/designing-agentic-ai-systems-with-the-orchideas-framework</guid>
      <description>
  


A secure-by-construction approach to nine-pillar agentic AI design, integrated with the Cloud Security Alliance MAESTRO threat modeling framework

&amp;nbsp;

Introduction: Security as a Structural Property

Most security failures in software systems come from treating security as something added on top of an otherwise-complete design. A team builds the application, then adds authentication; ships the feature, then writes the audit log; designs the architecture, then performs a penetration ...</description>
    </item>
    <item>
      <title>Top 6 Claude Security Risks to Watch as AI Becomes Your Employees' Operating System</title>
      <pubDate>Wed, 27 May 2026 15:51:33 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/top-6-claude-security-risks-to-watch-as-ai-becomes-your-employees-operating-system</link>
      <guid>https://cloudsecurityalliance.org/articles/top-6-claude-security-risks-to-watch-as-ai-becomes-your-employees-operating-system</guid>
      <description>
  
Originally published by Akto.

&amp;nbsp;



If there's one product that has quietly embedded itself into how your employees actually work, it's Claude.

Two years ago, it was summarizing meetings. Today, it's reading local files, running shell commands, browsing the web with employee session cookies, and connecting to your Slack, GitHub, and production databases. What started as a productivity shortcut now operates with the same privileges as the person using it, and in many organizations, s...</description>
    </item>
    <item>
      <title>Top Cloud Cost Optimization Techniques in 2026 for Maximum ROI</title>
      <pubDate>Wed, 27 May 2026 15:31:52 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/top-cloud-cost-optimization-techniques-in-2026-for-maximum-roi</link>
      <guid>https://cloudsecurityalliance.org/articles/top-cloud-cost-optimization-techniques-in-2026-for-maximum-roi</guid>
      <description>
  

As cloud adoption continues to accelerate, organizations are spending more than ever on infrastructure, storage, and services. In 2026, businesses are projected to invest over $1 trillion in cloud computing, yet studies suggest that up to 35% of this spend is wasted due to over-provisioning, idle resources, and inefficient practices. The challenge is clear: how can organizations maximize value from their cloud investments while controlling costs?

With the right approach, from dynamicall...</description>
    </item>
    <item>
      <title>The HIPAA Security Rule Is About to Change: What Healthcare CISOs Need to Do Before the Final Rule Drops</title>
      <pubDate>Wed, 27 May 2026 15:31:44 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/the-hipaa-security-rule-is-about-to-change-what-healthcare-cisos-need-to-do-before-the-final-rule-drops</link>
      <guid>https://cloudsecurityalliance.org/articles/the-hipaa-security-rule-is-about-to-change-what-healthcare-cisos-need-to-do-before-the-final-rule-drops</guid>
      <description>
  
For the first time in more than twenty years, the HIPAA Security Rule is getting a serious overhaul. On December 27, 2024, the U.S. Department of Health &amp;amp; Human Services (HHS) Office for Civil Rights (OCR) issued a Notice of Proposed Rulemaking that would fundamentally reshape how covered entities and business associates are expected to secure electronic protected health information. The public comment period closed in March 2025, and OCR received more than 4,700 comments.

Here's the...</description>
    </item>
    <item>
      <title>Your Security Tools Are the Target Now: Why Detection-First Architectures Are Failing Against AI-Driven and Zero-Day Exploits</title>
      <pubDate>Wed, 27 May 2026 15:31:23 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/your-security-tools-are-the-target-now-why-detection-first-architectures-are-failing-against-ai-driven-and-zero-day-exploits</link>
      <guid>https://cloudsecurityalliance.org/articles/your-security-tools-are-the-target-now-why-detection-first-architectures-are-failing-against-ai-driven-and-zero-day-exploits</guid>
      <description>
  
Your endpoint detection tooling can no longer be your last line of defense. For attackers, it is the first thing they target and impact.

ESET researchers catalogued nearly 90 EDR killers actively used in ransomware intrusions right now. The attack sequence is consistent: get in, blind or bypass the security tool, then run the encryptor. Detection never fires because it can no longer see what is happening.

Two Linux kernel vulnerabilities disclosed this month show exactly how attackers g...</description>
    </item>
    <item>
      <title>7 MCP Risks CISOs Should Consider and How to Prepare</title>
      <pubDate>Tue, 19 May 2026 16:51:42 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/7-mcp-risks-cisos-should-consider-and-how-to-prepare</link>
      <guid>https://cloudsecurityalliance.org/articles/7-mcp-risks-cisos-should-consider-and-how-to-prepare</guid>
      <description>
  
&amp;nbsp;

Introduction: MCP risks&amp;nbsp;

As MCP becomes the control plane for autonomous AI agents, it also introduces a new attack surface whose potential impact can extend across development pipelines, operational systems and even customer workflows. From content-injection attacks and over-privileged agents to supply chain risks, traditional controls often fall short. For CISOs, the stakes are clear: implement governance, visibility, and safeguards before MCP-driven automation become the ...</description>
    </item>
    <item>
      <title>5 AI Governance Practices to Build Trust and Drive Results</title>
      <pubDate>Tue, 19 May 2026 16:51:36 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/5-ai-governance-practices-to-build-trust-and-drive-results</link>
      <guid>https://cloudsecurityalliance.org/articles/5-ai-governance-practices-to-build-trust-and-drive-results</guid>
      <description>
  
AI is embedded in hiring decisions, customer service workflows, financial systems, and product development pipelines, among other essential business operations and services. AI undoubtedly comes with enhanced efficiency, scalability, and productivity, but it also brings concerns around risks, bias, transparency, reliability, and security.

AI governance addresses this increased scrutiny around AI’s safety by encompassing the frameworks, policies, and practices that guide how organizations...</description>
    </item>
    <item>
      <title>Mean Time to Breach: Why Traditional Patch Cycles No Longer Protect You</title>
      <pubDate>Tue, 19 May 2026 16:51:07 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/mean-time-to-breach-why-traditional-patch-cycles-no-longer-protect-you</link>
      <guid>https://cloudsecurityalliance.org/articles/mean-time-to-breach-why-traditional-patch-cycles-no-longer-protect-you</guid>
      <description>
  
Adversaries operate on a short timeline that renders traditional defense cycles obsolete. The CrowdStrike 2025 Global Threat Report reveals average eCrime breakout times dropped to just 48 minutes, with the fastest lateral movement clocked at 51 seconds.

Let’s contrast this velocity with enterprise response capabilities. Data from the Automox 2026 State of Endpoint Management report indicates that half of organizations take five or more days to patch systems or cannot quantify their MTTP...</description>
    </item>
    <item>
      <title>Cloud Security Evolution: Why Security Teams are Taking the Lead</title>
      <pubDate>Tue, 19 May 2026 16:50:54 -0700</pubDate>
      <link>https://cloudsecurityalliance.org/articles/cloud-security-evolution-why-security-teams-are-taking-the-lead</link>
      <guid>https://cloudsecurityalliance.org/articles/cloud-security-evolution-why-security-teams-are-taking-the-lead</guid>
      <description>
  
Cloud adoption is rapidly on the rise. Gartner estimates that 90% of organizations will adopt hybrid clouds through 2027.&amp;nbsp;

There are many reasons why organizations are migrating on-premises infrastructure to the cloud. It can increase the speed and scale of computing resources, improve reliability and resilience, and save time by outsourcing the spinning up, patching, and updating of infrastructure.&amp;nbsp;

However, despite these benefits, it is complex to secure. Public clouds opera...</description>
    </item>
  </channel>
</rss>
