< ciso
brief />
Tag Banner

All news with #zero trust tag

235 articles

Improving SPIRE Security and Resiliency on AWS

๐Ÿ”’ This post explains how to strengthen SPIRE (the SPIFFE Runtime Environment) deployments by offloading core functions to AWS managed services. It outlines replacing default SPIRE components with AWS KMS, AWS Private CA, Amazon Aurora, Amazon S3, AWS Secrets Manager, and Amazon Verified Permissions to improve security, scalability, and operational resiliency. A GitHub repository provides deployment templates and configuration examples to follow along.
read more โ†’

AWS Client VPN adds device posture assessment

๐Ÿ”’ AWS Client VPN now supports device posture assessment, enabling verification that connecting user devices meet security and compliance requirements before granting access. This integrates with existing posture providers such as CrowdStrike, Jamf, and JumpCloud and uses Cedar policies for fine-grained control. A Test Policy tool helps you author and validate posture rules, and evaluations can be enforced or run in monitoring-only mode. The feature continuously re-evaluates active sessions and is available in all AWS Regions at no extra cost, requiring AWS VPN Client v6.2.0+.
read more โ†’

The State of Cybersecurity in 2026: Key Trends

๐Ÿ”Ž This vendor-focused overview summarizes how cloud expansion, AI, distributed systems, and complex digital environments are reshaping security. It highlights shifts toward continuous visibility, least-privilege identity controls, telemetry management, AI-native SOCs, and exposure reduction. The piece profiles vendors addressing identity, telemetry, endpoint, human risk, exposure, email, device, AI, and cloud security.
read more โ†’

Protected Quick Tunnels: Email-Restricted Local URLs

๐Ÿ”’ Cloudflare introduces email-based access controls for Quick Tunnels so developers and agents can publish local services securely. Add the --allowed-mail flag to cloudflared to restrict access to specific email addresses or domains; visitors verify ownership with a one-time PIN via Cloudflare Access. The design keeps authorization rules on the developer's machine while using a stateless authentication broker to validate emails, ensuring guest lists never leave the host.
read more โ†’

Microsoft Security at Ignite 2026: What to Expect

๐Ÿ”’ Join Microsoft Security at Ignite 2026 in San Francisco or online from November 17โ€“20, 2026, with a Security Pre-Day on November 16. Hear executive keynotes, get hands-on with agentic security solutions, attend expert meetups and MISA partner demos, and participate in sessions across four security themes covering agentic SOCs, securing deployed agents, foundational Zero Trust practices, and data protection.
read more โ†’

Google Cloud CLI remote MCP server enters preview

๐Ÿ› ๏ธ The Google Cloud CLI remote MCP server is now available in public preview, enabling AI agents to run gcloud and bq commands from a secure, network-isolated execution sandbox. This managed server removes the need to install CLI binaries locally, supports hosted agent platforms, and enforces enterprise-grade controls including zero ambient credentials, IAM-based permissions, Model Armor screening, and Cloud Audit Logging. Agents connect via the MCP standard and authenticate through Agent Identity or OAuth 2.0.
read more โ†’

Kinesis Video Streams adds VPC PrivateLink support

๐Ÿ”’ Amazon Kinesis Video Streams now supports interface VPC endpoints powered by AWS PrivateLink, enabling private connectivity from your Amazon VPC. Traffic between your VPC and Kinesis Video Streams remains on the AWS network for control plane, ingestion, and playback data planes, avoiding the public internet. Customers can ingest, store, and play back video from private subnets without internet gateways, NAT, or public IPs, and can create endpoints via the console, AWS CLI, or SDKs with endpoint policies to control access.
read more โ†’

KDDI Launches SASE Gateway with SP Interconnect

๐Ÿš€ KDDI Corporation has launched the "SASE Gateway powered by Palo Alto Networks" using the new SP Interconnect (SPI) architecture to directly link carrier-grade closed networks (WVS2) with Prisma SASE. The service eliminates IPsec overhead, enhances performance and flexibility for Japanese enterprises, and centralizes security management under a single policy engine. It can be extended with Cortex XDR, Prisma Browser and SOC/IR services to support AI adoption, hybrid work and cloud migration.
read more โ†’

OT Resilience Becomes a Boardroom Imperative

๐Ÿ”’ The long-standing assumption that operational technology (OT) is safe due to physical isolation is no longer valid. Integration of OT with IT and cloud has exposed nearly 20 million OT assets online, increasing risk and making operational resilience a strategic concern. Modern industrial environments require continuous verification, micro-segmentation, and governance to protect safety, availability, and business continuity.
read more โ†’

MCP Servers Create Significant Governance Gaps

๐Ÿ›ก๏ธ New research from Ox Security warns that Model Context Protocol (MCP) servers are creating an enterprise governance gap as AI adoption grows. MCP standardizes connections between AI models and external tools or data, but in doing so can bypass residency controls, zero trust boundaries and granular IAM policies. Analysis of public registries found many hosts outside the US and some unregistered, while permission models like โ€œalways-allowโ€ enabled unauthorized data access in tested scenarios.
read more โ†’

Zero Trust for AI Agents Begins with Visibility

๐Ÿ” Organizations racing to deploy AI agents face critical visibility gaps that undermine governance. Research shows many AI workflows touch sensitive data without oversight, and Shadow AI complicates discovery. The SANS cheat sheet emphasizes inventory before enforcement: you cannot govern what you cannot see. Practical steps include treating agent spend and API keys as discovery signals, correlating network, endpoint, browser, and SaaS telemetry, and giving each agent a distinct identity for logging and authorization.
read more โ†’

AWS STS VPC endpoints for OIDC discovery

๐Ÿ”’ AWS IAM outbound identity federation now supports VPC endpoints for OIDC discovery, allowing workloads to access OIDC metadata and JWKS verification keys over AWS PrivateLink without traversing the public internet. This enables short-lived JWTs from AWS STS to be verified by external services while keeping traffic inside the AWS network. The feature addresses network security requirements for VPCs with restricted internet access and is available in all commercial, GovCloud (US), and China Regions with standard PrivateLink pricing.
read more โ†’

September 2026 Microsoft Security updates and features

๐Ÿ”’ This post summarizes September 2026 security updates across Microsoft Security, highlighting new controls for local AI agents, expanded Zero Trust for agentic traffic, and SOC improvements. It covers AI-powered detonation summaries for emails, Purview and Entra integration for data protection, Purview auto-labeling and eDiscovery enhancements, data lifecycle management for SharePoint, and new GCC High capabilities for Intune and PKI.
read more โ†’

AI reshapes nation-state threat landscape for CISOs

๐Ÿ”’ The accelerating use of AI by nation-state actors is blurring lines between national-security and enterprise threats, forcing CISOs to integrate geopolitical risk into everyday security planning. Experts urge closer collaboration with government agencies while organizations must reassess whether they are strategic targets. Practical steps include planning to operate through compromises, reducing exposure with controls like zero trust and MFA, and securing board-level support for resilience investments.
read more โ†’

Strengthen Fundamentals to Enable Nextโ€‘Gen Security

๐Ÿ”’ Effective cyber defense hinges on strong fundamentals rather than constantly chasing the latest tools. The author, a CISO with large-enterprise experience, argues that visibility, identity management, riskโ€‘based prioritization, resilience and a common security language are core. Embracing AI and other innovations is valuable but only when built on these basics. Organizations should inventory assets, scale identity controls like MFA and passkeys, focus on crown-jewel protections, rehearse recovery plans, and translate technical risk into business terms.
read more โ†’

Security Fundamentals to Reduce AI-era Cyber Risk

๐Ÿ”’ This post outlines Microsoft's Secure Now initiative within Microsoft Security Exposure Management, introduced May 2026, to help organizations prioritize foundational controls as AI accelerates threat complexity. It summarizes recent agentic and campaign-based incidents that show how familiar weaknessesโ€”excessive permissions, unprotected authentication, unpatched systemsโ€”can chain rapidly into broader compromises. The blog maps practical mitigations, guided by Zero Trust, and highlights resources like FastTrack to operationalize continuous exposure reduction.
read more โ†’

CISA Guidance Urges Honeytokens for Intrusion Detection

๐Ÿ›ก๏ธ CISA has published guidance recommending that critical infrastructure operators deploy decoys such as fake files, accounts and credentials inside their networks to detect intruders who bypass perimeter defenses. The guidance emphasizes honeytokensโ€”low-complexity data tripwires with no legitimate useโ€”over internet-facing honeypots, and frames decoys as complementary to Zero Trust. It outlines three actions: deploy high-fidelity tripwires in high-value areas, map coverage using MITRE ATT&CK and MITRE Engage, and continuously refine through threat emulation.
read more โ†’

Architecting a Secure Landing Zone in EUSC

๐Ÿ”’ This post explains how to design a secure, scalable landing zone for the AWS European Sovereign Cloud (aws-eusc), a partitioned AWS environment operated within the EU. It covers account structure and governance, identity as IaC, centralized logging to a SIEM, data protection, perimeter and network design, CI/CD and artifact distribution, and incident response. The guidance maps to the AWS Security Reference Architecture and the AWS Well-Architected Framework, and highlights which behaviors are partition boundaries versus configurable choices.
read more โ†’

Securing Unpatchable Systems Amid AI-Driven Finding

๐Ÿ”’ AI-assisted analysis is exposing decades of unpatched technical debt, leaving operational technology and legacy systems with known vulnerabilities that cannot easily be fixed. Inventory and visibility enable identification of at-risk devices, while network controls such as micro-segmentation, VLANs, ACLs, and NGFW/IPS provide compensating protections. Full air-gapping or data diodes can help but are often bypassed in practice, so defenders must assume imperfect isolation and apply layered controls and monitoring.
read more โ†’

Agentic AI Challenges the Future of Zero Trust

๐Ÿ›ก๏ธ Many CISOs praise zero trust yet struggle to fully implement it, and the rise of agentic AI now threatens its practical effectiveness. Autonomous agents can chain permitted actions into harmful sequences, inherit privileges, spawn subagents, and communicate in ways that evade visibility, creating new exfiltration and escalation risks. Experts warn that inventory-based controls and identity alone are insufficient and recommend short-lived delegated credentials, strict transaction limits, sandboxing, and reversible actions to reduce high-consequence risks.
read more โ†’