CSAIChaptersEventsBlog
Join CSA, RSAC, and UNLV for a one-day summit in Las Vegas exploring how AI is reshaping enterprise cybersecurity →

CSA Research

Best practices, guidance, frameworks and tools to help the industry secure the cloud. Read our research to get your questions around cloud security answered.
Research

CSA Research is created by the industry for the industry and is both vendor-neutral and consensus driven. Our research is created by subject matter experts who volunteer for our working groups. Each working group focuses on a unique topic or aspect of cloud security, from IoT, DevSecOps, Serverless and more, we have working groups for over 20 areas of cloud computing. You can view a list of all active research working groups. To find out more about how our research is created and the process we follow you can view the CSA Research Lifecycle.

Contribute to CSA Research

Peer reviews allow security professionals from around the world to collaborate on CSA research. Provide your feedback on the following documents in progress.

Latest Research

Leveraging the Health Data from IoT Wearables

Leveraging the Health Data from IoT Wearables

Release Date: 07/20/2026

Healthcare organizations are increasingly looking to IoT wearables to support continuous health monitoring, remote patient monitoring, personalized treatment, and more proactive care. This publication explores the many facets of these groundbreaking technologies.

Readers will learn what wearable...
Hugging Face's Autonomous AI Agent Breach

Hugging Face's Autonomous AI Agent Breach

Release Date: 07/19/2026

Security Implications and Guidance for Agentic-Attacker Incidents. Key Takeaways Hugging Face disclosed on July 16, 2026 that an intrusion into its production infrastructure was driven end-to-end by an autonomous AI agent rather than a human operator at the keyboard, a scenario the company...
Agent Data Injection: A New Attack Class Beyond Prompt Injection

Agent Data Injection: A New Attack Class Beyond Prompt Injection

Release Date: 07/16/2026

How Corrupted Metadata Bypasses Existing Agent Defenses. Agent Data Injection: A New Attack Class Beyond Prompt Injection Key Takeaways Researchers from Seoul National University, the University of Illinois Urbana-Champaign, and Largosoft have identified Agent Data Injection (ADI), a distinct...