search

Sections

Cyber Security

2432 articles

NVD in the AI Era: The Case for Multi-Source Vulnerability Intelligence
cybersecurity

NVD in the AI Era: The Case for Multi-Source Vulnerability Intelligence

NIST’s shift to risk-based enrichment makes one thing clear: modern security teams need more than a single public source. In the AI era, trusted vulnerability intelligence depends on multiple signals, human validation, and clear context.

Blog RSS Feed | Snyk ·
SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon
cybersecurity

SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon

Varonis Threat Labs has identified a significant vulnerability known as SearchLeak in Microsoft 365 Copilot Enterprise. This multi-stage vulnerability allows attackers to easily access and steal sensitive information, including MFA codes, emails, meeting details, and confidential organizational files, with just one click. The discovery highlights serious security risks associated with Microsoft 365 Copilot, which can be exploited for silent data exfiltration.

Cloud Security Alliance ·
Restrict AWS Management Console access to expected networks with sign-in resource-based policies and RCPs
cybersecurity

Restrict AWS Management Console access to expected networks with sign-in resource-based policies and RCPs

Amazon Web Services (AWS) recently announced support for resource-based policies and resource control policies (RCPs) for AWS Sign-In. By using resource-based policies and RCPs, you can restrict access to the AWS Management Console sign-in and aws login CLI sessions to requests from your expected networks, your on-premises data center networks, and your Amazon Virtual Private

AWS Security Blog ·
CNAPP evolution: How Microsoft aligns with leading cloud risk management platforms
cybersecurity

CNAPP evolution: How Microsoft aligns with leading cloud risk management platforms

Learn how CNAPP platforms are helping organizations prioritize exploitable risks, reduce exposure, and operationalize security across the application lifecycle. The post CNAPP evolution: How Microsoft aligns with leading cloud risk management platforms appeared first on Microsoft Security Blog.

Cloud security Insights | Microsoft Security Blog ·
Native Xet Protocol Support in JFrog Artifactory: How Enterprise Model Management Actually Works
cybersecurity

Native Xet Protocol Support in JFrog Artifactory: How Enterprise Model Management Actually Works

Machine learning models are not like other software artifacts. A single fine-tuned LLM can weigh 70 GB. A model family may share 95% of its weights across dozens of variants. When hundreds of developers, training jobs, and GPU clusters all need the same model at the same time, the infrastructure underneath needs to be built

From the Frog's mouth - JFrog Blog ·
The SaaS Security Problem Most Organizations Still Treat Like an IT Issue
cybersecurity

The SaaS Security Problem Most Organizations Still Treat Like an IT Issue

Organizations have traditionally viewed SaaS security primarily as an access management issue, focusing on implementing Single Sign-On (SSO), Multi-Factor Authentication (MFA), and efficient user provisioning processes. However, the landscape of SaaS breaches has evolved, as illustrated by the recent ADT breach linked to the ShinyHunters extortion group. Reports indicate that attackers exploited an employee’s Okta account via a voice phishing attack, highlighting the need for a more comprehensive approach to security.

Cloud Security Alliance ·
AI Regulation Keeps Evolving: How to Develop an AI Governance Framework That Adapts
cybersecurity

AI Regulation Keeps Evolving: How to Develop an AI Governance Framework That Adapts

The landscape for AI regulation is changing quickly, influenced by new federal policies, a surge of state-level laws, and specific industry compliance needs. Organizations recognize the necessity for AI governance but often struggle with the complexities of this evolving environment. Proactive companies are not waiting for definitive regulations; instead, they are developing governance frameworks to ensure they can adapt to and comply with emerging requirements effectively.

Cloud Security Alliance ·
Top 6 Claude Cowork Security Risks to Watch
cybersecurity

Top 6 Claude Cowork Security Risks to Watch

Claude Cowork is not just a chatbot with additional features; it operates as a local agent on employees’ machines. This allows it to access files, execute shell commands, navigate the web using stored cookies, and connect to various enterprise systems. According to Anthropic, the potential impact of an issue with Cowork hinges on its access and permissions, significantly altering the threat model. A prompt injection attack can have varied consequences based on what Claude can read and execute.

Cloud Security Alliance ·
The Role of CSA STAR in Vendor Security Assessments
cybersecurity

The Role of CSA STAR in Vendor Security Assessments

Organizations increasingly rely on complex digital ecosystems that encompass cloud services, SaaS applications, API integrations, and outsourced infrastructure. Although these technologies enhance scalability and efficiency, they raise significant security challenges. As businesses expand their vendor networks, security and procurement teams face lengthy due diligence processes, repetitive security questionnaires, and a lack of visibility into third-party risks, complicating risk management.

Cloud Security Alliance ·
Quantum Computing & AI: When AI Starts Writing Quantum Code
cybersecurity

Quantum Computing & AI: When AI Starts Writing Quantum Code

Quantum computing and artificial intelligence (AI) are commonly seen as distinct technologies, each poised to revolutionize their respective fields. Quantum computing expands the boundaries of computational capabilities, while AI is transforming software development, data analysis, and decision-making processes. However, a more intriguing aspect lies in the potential synergy between these two technologies. The CSA’s recent publication discusses how quantum computing could enhance AI, creating a future of Quantum Artificial Intelligence.

Cloud Security Alliance ·
Validating LLM-Generated Control Mappings Beyond Aggregate Accuracy
cybersecurity

Validating LLM-Generated Control Mappings Beyond Aggregate Accuracy

Security control frameworks are expanding in both scope and complexity, with the CSA AI Controls Matrix featuring 243 control objectives and the NIST CSF containing hundreds of subcategories. Organizations utilizing multiple frameworks must perform mapping for compliance, gap analysis, risk aggregation, and audit preparation. Large Language Models (LLMs) have become essential for this task, enabling rapid and structured mapping across frameworks, streamlining the compliance process significantly.

Cloud Security Alliance ·