#identitysecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #identitysecurity, aggregated by home.social.
-
🟦 Entra Tenant Governance | Find Configuration Drift
New preview lets admins detect tenant configuration drift natively across Entra and related services. 🔹
Define JSON baselines as configuration as code and create scheduled monitors. Monitors run every six hours and produce run summaries and detailed drift objects with property level diffs. Govern external tenants via B2B signals and role based templates from a single admin center. 💡
💡 Configuration as code baseline
🔍 Six hour monitor interval
⚖️ Cross tenant governance via B2B signals -
🟦 Entra Tenant Governance | Find Configuration Drift
New preview lets admins detect tenant configuration drift natively across Entra and related services. 🔹
Define JSON baselines as configuration as code and create scheduled monitors. Monitors run every six hours and produce run summaries and detailed drift objects with property level diffs. Govern external tenants via B2B signals and role based templates from a single admin center. 💡
💡 Configuration as code baseline
🔍 Six hour monitor interval
⚖️ Cross tenant governance via B2B signals -
Strengthening Active Directory Password Rules Without Frustrating Users
Want to boost your Active Directory password security without driving users crazy? Ditch outdated complexity rules and switch to passphrases - longer, multi-word passwords that are easier to remember and harder for hackers to crack.
#ActiveDirectory #PasswordManagement #Passphrases #IdentitySecurity #Authentication
-
VIKI SNIFFER analyzed 72,953 CVEs in the latest OSINT cycle.
Key findings:
47,064 CVEs still have no CVSS
64 MITRE ATT&CK techniques identified
Strong growth in:
T1071 — Application Layer Protocol
T1055 — Process Injection
T1003.005 — Cached Credentials
T1020 — Automated Exfiltrationhttps://jaroslawkuchta.substack.com/p/tlpamber-viki-sniffer-threat-brief?r=8gt0a0
#CyberSecurity #ThreatIntelligence #SOC #BlueTeam #MITREATTACK #ExposureManagement #CTEM #ThreatHunting #OSINT #CVE #KEV #InfoSec #IdentitySecurity #LLMSecurity #OpenAPI #MCP #DetectionEngineering
-
VIKI SNIFFER analyzed 72,953 CVEs in the latest OSINT cycle.
Key findings:
47,064 CVEs still have no CVSS
64 MITRE ATT&CK techniques identified
Strong growth in:
T1071 — Application Layer Protocol
T1055 — Process Injection
T1003.005 — Cached Credentials
T1020 — Automated Exfiltrationhttps://jaroslawkuchta.substack.com/p/tlpamber-viki-sniffer-threat-brief?r=8gt0a0
#CyberSecurity #ThreatIntelligence #SOC #BlueTeam #MITREATTACK #ExposureManagement #CTEM #ThreatHunting #OSINT #CVE #KEV #InfoSec #IdentitySecurity #LLMSecurity #OpenAPI #MCP #DetectionEngineering
-
Shashwat Sehgal, CEO & Co-Founder of P0 Security, warns that AI agents are recreating the same access problems that broke early cloud security.
🔐 Broad standing permissions are returning
🔐 Visibility alone does not reduce blast radius
🔐 Runtime governance matters more than authentication“The organizations that avoid repeating the cloud security cycle will be the ones that treat agents as a new class of privileged non-human identity from day one.”
#Cybersecurity #AISecurity #IdentitySecurity #CloudSecurity #AIAgents
-
Shashwat Sehgal, CEO & Co-Founder of P0 Security, warns that AI agents are recreating the same access problems that broke early cloud security.
🔐 Broad standing permissions are returning
🔐 Visibility alone does not reduce blast radius
🔐 Runtime governance matters more than authentication“The organizations that avoid repeating the cloud security cycle will be the ones that treat agents as a new class of privileged non-human identity from day one.”
#Cybersecurity #AISecurity #IdentitySecurity #CloudSecurity #AIAgents
-
Shashwat Sehgal, CEO & Co-Founder of P0 Security, warns that AI agents are recreating the same access problems that broke early cloud security.
🔐 Broad standing permissions are returning
🔐 Visibility alone does not reduce blast radius
🔐 Runtime governance matters more than authentication“The organizations that avoid repeating the cloud security cycle will be the ones that treat agents as a new class of privileged non-human identity from day one.”
#Cybersecurity #AISecurity #IdentitySecurity #CloudSecurity #AIAgents
-
Shashwat Sehgal, CEO & Co-Founder of P0 Security, warns that AI agents are recreating the same access problems that broke early cloud security.
🔐 Broad standing permissions are returning
🔐 Visibility alone does not reduce blast radius
🔐 Runtime governance matters more than authentication“The organizations that avoid repeating the cloud security cycle will be the ones that treat agents as a new class of privileged non-human identity from day one.”
#Cybersecurity #AISecurity #IdentitySecurity #CloudSecurity #AIAgents
-
Shashwat Sehgal, CEO & Co-Founder of P0 Security, warns that AI agents are recreating the same access problems that broke early cloud security.
🔐 Broad standing permissions are returning
🔐 Visibility alone does not reduce blast radius
🔐 Runtime governance matters more than authentication“The organizations that avoid repeating the cloud security cycle will be the ones that treat agents as a new class of privileged non-human identity from day one.”
#Cybersecurity #AISecurity #IdentitySecurity #CloudSecurity #AIAgents
-
AI agents are scaling faster than enterprise identity controls can keep up with, says Alex Bovee, CEO & Co-Founder of C1.
⚡ Humans overapprove access
⚡ Manual IAM workflows cannot scale
⚡ AI agents require real-time governance“Companies need automated, policy-driven access controls that work in real time.”
Full discussion:
https://www.technadu.com/ai-scaling-is-outpacing-enterprise-identity-controls-why-companies-need-ai-level-monitoring/628021/ -
AI agents are scaling faster than enterprise identity controls can keep up with, says Alex Bovee, CEO & Co-Founder of C1.
⚡ Humans overapprove access
⚡ Manual IAM workflows cannot scale
⚡ AI agents require real-time governance“Companies need automated, policy-driven access controls that work in real time.”
Full discussion:
https://www.technadu.com/ai-scaling-is-outpacing-enterprise-identity-controls-why-companies-need-ai-level-monitoring/628021/ -
AI agents are scaling faster than enterprise identity controls can keep up with, says Alex Bovee, CEO & Co-Founder of C1.
⚡ Humans overapprove access
⚡ Manual IAM workflows cannot scale
⚡ AI agents require real-time governance“Companies need automated, policy-driven access controls that work in real time.”
Full discussion:
https://www.technadu.com/ai-scaling-is-outpacing-enterprise-identity-controls-why-companies-need-ai-level-monitoring/628021/ -
AI agents are scaling faster than enterprise identity controls can keep up with, says Alex Bovee, CEO & Co-Founder of C1.
⚡ Humans overapprove access
⚡ Manual IAM workflows cannot scale
⚡ AI agents require real-time governance“Companies need automated, policy-driven access controls that work in real time.”
Full discussion:
https://www.technadu.com/ai-scaling-is-outpacing-enterprise-identity-controls-why-companies-need-ai-level-monitoring/628021/ -
AI agents are scaling faster than enterprise identity controls can keep up with, says Alex Bovee, CEO & Co-Founder of C1.
⚡ Humans overapprove access
⚡ Manual IAM workflows cannot scale
⚡ AI agents require real-time governance“Companies need automated, policy-driven access controls that work in real time.”
Full discussion:
https://www.technadu.com/ai-scaling-is-outpacing-enterprise-identity-controls-why-companies-need-ai-level-monitoring/628021/ -
I published a reflection on AI, costs, vibe coding and human work.
The thesis is simple: AI is not a bluff. It is powerful, useful and changing how we build software. But the idea that it can cheaply replace human teams is much more fragile than it looks.
Tokens, compute, inference, review, security and governance all have a cost. And AI agents, when acting on our behalf, become identities that must be governed.
-
I published a reflection on AI, costs, vibe coding and human work.
The thesis is simple: AI is not a bluff. It is powerful, useful and changing how we build software. But the idea that it can cheaply replace human teams is much more fragile than it looks.
Tokens, compute, inference, review, security and governance all have a cost. And AI agents, when acting on our behalf, become identities that must be governed.
-
Ho pubblicato una riflessione su IA, costi, vibe coding e lavoro umano.
La tesi è semplice: l'IA non è un bluff. È potente, utile e sta cambiando il modo in cui costruiamo software. Ma la narrativa secondo cui può sostituire team umani a basso costo è molto più fragile di quanto sembri.
Token, compute, inference, review, sicurezza e governance hanno un costo. E gli agenti IA, quando agiscono per nostro conto, diventano identità da governare.
-
Ho pubblicato una riflessione su IA, costi, vibe coding e lavoro umano.
La tesi è semplice: l'IA non è un bluff. È potente, utile e sta cambiando il modo in cui costruiamo software. Ma la narrativa secondo cui può sostituire team umani a basso costo è molto più fragile di quanto sembri.
Token, compute, inference, review, sicurezza e governance hanno un costo. E gli agenti IA, quando agiscono per nostro conto, diventano identità da governare.
-
In modern security operations, the hardest problem isn’t detection — it’s maintaining integrity across distributed systems.
AI accelerates analysis, but resilience still depends on identity, verification, and the ability to reason under uncertainty.
Speed matters, but judgment matters more.#CyberSecurity #InfoSec #AI #SecurityEngineering #ThreatIntelligence #DistributedSystems #IdentitySecurity #Verification
-
In modern security operations, the hardest problem isn’t detection — it’s maintaining integrity across distributed systems.
AI accelerates analysis, but resilience still depends on identity, verification, and the ability to reason under uncertainty.
Speed matters, but judgment matters more.#CyberSecurity #InfoSec #AI #SecurityEngineering #ThreatIntelligence #DistributedSystems #IdentitySecurity #Verification
-
In modern security operations, the hardest problem isn’t detection — it’s maintaining integrity across distributed systems.
AI accelerates analysis, but resilience still depends on identity, verification, and the ability to reason under uncertainty.
Speed matters, but judgment matters more.#CyberSecurity #InfoSec #AI #SecurityEngineering #ThreatIntelligence #DistributedSystems #IdentitySecurity #Verification
-
In modern security operations, the hardest problem isn’t detection — it’s maintaining integrity across distributed systems.
AI accelerates analysis, but resilience still depends on identity, verification, and the ability to reason under uncertainty.
Speed matters, but judgment matters more.#CyberSecurity #InfoSec #AI #SecurityEngineering #ThreatIntelligence #DistributedSystems #IdentitySecurity #Verification
-
Device Security Must Complement Identity to Thwart Modern Threats
Authentication is no longer enough to guarantee security - even with multi-factor authentication in place, phishing kits can capture session tokens, allowing attackers to bypass security checks undetected. As a result, device security must step up to complement identity and prevent modern threats.
#PostauthenticationThreats #MfaBypass #DeviceSecurity #IdentitySecurity #EmergingThreats
-
Brandon Dixon, CTO & Co-Founder of Ent AI, explains how fake remote IT workers are bypassing interviews, onboarding, and enterprise workflows using legitimate credentials and approved tools.
👉 AI-generated interview responses
👉 Zoom-based remote access abuse
👉 KVM-controlled corporate laptops
👉 Behavioral drift after hiring
“Historically, the assumption has been that if somebody authenticated successfully, they’re probably trustworthy.”https://www.technadu.com/spot-fake-remote-workers-who-bypass-hiring-and-security-checks/628044/
#CyberSecurity #InsiderThreat #RemoteWork #IdentitySecurity #InfoSec
-
Brandon Dixon, CTO & Co-Founder of Ent AI, explains how fake remote IT workers are bypassing interviews, onboarding, and enterprise workflows using legitimate credentials and approved tools.
👉 AI-generated interview responses
👉 Zoom-based remote access abuse
👉 KVM-controlled corporate laptops
👉 Behavioral drift after hiring
“Historically, the assumption has been that if somebody authenticated successfully, they’re probably trustworthy.”https://www.technadu.com/spot-fake-remote-workers-who-bypass-hiring-and-security-checks/628044/
#CyberSecurity #InsiderThreat #RemoteWork #IdentitySecurity #InfoSec
-
Brandon Dixon, CTO & Co-Founder of Ent AI, explains how fake remote IT workers are bypassing interviews, onboarding, and enterprise workflows using legitimate credentials and approved tools.
👉 AI-generated interview responses
👉 Zoom-based remote access abuse
👉 KVM-controlled corporate laptops
👉 Behavioral drift after hiring
“Historically, the assumption has been that if somebody authenticated successfully, they’re probably trustworthy.”https://www.technadu.com/spot-fake-remote-workers-who-bypass-hiring-and-security-checks/628044/
#CyberSecurity #InsiderThreat #RemoteWork #IdentitySecurity #InfoSec
-
Brandon Dixon, CTO & Co-Founder of Ent AI, explains how fake remote IT workers are bypassing interviews, onboarding, and enterprise workflows using legitimate credentials and approved tools.
👉 AI-generated interview responses
👉 Zoom-based remote access abuse
👉 KVM-controlled corporate laptops
👉 Behavioral drift after hiring
“Historically, the assumption has been that if somebody authenticated successfully, they’re probably trustworthy.”https://www.technadu.com/spot-fake-remote-workers-who-bypass-hiring-and-security-checks/628044/
#CyberSecurity #InsiderThreat #RemoteWork #IdentitySecurity #InfoSec
-
AI Adoption Exposes Identity Security Blind Spots
As organizations rapidly adopt AI, they're unwittingly creating a surge in non-human identities - like AI agents and machine identities - that are outpacing their ability to manage and secure them, leaving them vulnerable to new security risks. This blind spot is exposing companies to excessive privileges, unmanaged access, and orphaned…
#AiAdoption #IdentitySecurity #NonhumanIdentities #CloudSecurity #EmergingThreats
-
Most organizations are still preparing for intrusions that look malicious.
I think that’s the mistake.
Modern infrastructures are becoming too interconnected, too identity-driven, and too automation-heavy for future attacks to remain obvious.
The more I study cloud trust relationships, SaaS ecosystems, APIs, and machine identities…
The more I think the next generation of offensive operations will revolve around something far quieter:
Blending into operational normalcy itself.
Not malware.
Not noisy exploit chains.
Not obvious persistence.
Just:
valid sessions
trusted automation
approved integrations
legitimate infrastructure
machine-to-machine trust
At that point, the problem is no longer:
“Can attackers get in?”
It becomes:
“Can defenders still distinguish trust from compromise?”
That’s the idea behind something I’ve been researching lately:
The Synthetic Insider.
An intrusion model where attackers stop behaving like external threats…
and start behaving like operationally legitimate internal presence.
Honestly, I think this shift is going to redefine modern offensive security over the next decade.
Wrote a deeper breakdown on it here:
🔗 https://dev.to/daniel_isaac_e/the-synthetic-insider-1kgf
Curious how others see identity + automation changing the future attack surface.
#CyberSecurity #RedTeam #OffensiveSecurity #IdentitySecurity #CloudSecurity #ThreatIntel
-
Most organizations are still preparing for intrusions that look malicious.
I think that’s the mistake.
Modern infrastructures are becoming too interconnected, too identity-driven, and too automation-heavy for future attacks to remain obvious.
The more I study cloud trust relationships, SaaS ecosystems, APIs, and machine identities…
The more I think the next generation of offensive operations will revolve around something far quieter:
Blending into operational normalcy itself.
Not malware.
Not noisy exploit chains.
Not obvious persistence.
Just:
valid sessions
trusted automation
approved integrations
legitimate infrastructure
machine-to-machine trust
At that point, the problem is no longer:
“Can attackers get in?”
It becomes:
“Can defenders still distinguish trust from compromise?”
That’s the idea behind something I’ve been researching lately:
The Synthetic Insider.
An intrusion model where attackers stop behaving like external threats…
and start behaving like operationally legitimate internal presence.
Honestly, I think this shift is going to redefine modern offensive security over the next decade.
Wrote a deeper breakdown on it here:
🔗 https://dev.to/daniel_isaac_e/the-synthetic-insider-1kgf
Curious how others see identity + automation changing the future attack surface.
#CyberSecurity #RedTeam #OffensiveSecurity #IdentitySecurity #CloudSecurity #ThreatIntel
-
AI Agents Expose Organizations to Identity Security Risks
Most organizations are unwittingly rolling out AI agents that can open the door to identity security breaches, with 93% using or planning to use them for sensitive tasks like password resets and VPN access. Despite this, many admit that these agents create new vulnerabilities.
#IdentitySecurity #AiAgents #EmergingThreats #Mfa #ArtificialIntelligence
-
Identity security programs were built for human users - but AI agents, APIs, and service accounts are now expanding the attack surface at machine speed.
New insights from Keeper Security CEO Darren Guccione:
https://www.technadu.com/the-environment-has-changed-but-your-identity-security-still-hasnt/627850/ -
CyberArk + Palo Alto Networks launch Idira for AI-era identity security. 🔐
The platform focuses on securing human, machine & agentic identities with unified PAM and governance.
Is identity becoming the primary AI attack surface?
Follow @technadu for more.
-
📰 89% of IT Leaders Struggle with Identity Sprawl Amid AI Expansion: Report
New report from Keeper Security: 89% of IT leaders are struggling with identity sprawl, a problem accelerated by AI. 72% can't detect credential misuse in real-time, creating major security gaps. 🔑 #IdentitySecurity #AI #CyberSecurity
-
Cisco acquires Astrix Security to tackle non-human identity risks — API keys, service accounts, OAuth tokens… The identities that never sleep, never rotate, and quietly accumulate privileges over time.
Sometimes the biggest attack surface is the one that can't log in with a face. 🔑
#infosec #NHI #IdentitySecurity
https://www.securityweek.com/cisco-moves-to-acquire-astrix-security-to-tackle-non-human-identity-risks/ -
The store that has everything – except what you actually need. #HackWithHeart #ToonThursday #CyberSecurity #IdentitySecurity
Subscribe to the weekly comic - https://hackwithheart.com/subscribe
-
The store that has everything – except what you actually need. #HackWithHeart #ToonThursday #CyberSecurity #IdentitySecurity
Subscribe to the weekly comic - https://hackwithheart.com/subscribe
-
Silverfort Injects AI into Access Decisions with Fabrix Buy
With Fabrix acquisition, Silverfort supercharges access decisions with AI, aiming to revolutionize identity security by automating routine tasks and reserving human oversight for high-stakes situations. This game-changing move enables businesses to scale security efficiently, freeing up human experts to…
#IdentitySecurity #ArtificialIntelligence #AccessManagement #AipoweredSecurity #RuntimeAccessDecisions
-
🚨 Most people think red teaming is about exploits.
It’s not.
The most effective attacks today don’t start with vulnerabilities —
they start with **trust**.Modern environments are cloud-heavy, identity-driven, and full of SaaS integrations. In these systems, attackers don’t always need to “break in.”
They move quietly through:
• Over-permissioned identities
• Weak approval workflows
• Misconfigured cloud roles
• OAuth tokens and API access
• Human behavior under pressure
• Business processes no one questionsThis is what I’ve been studying and calling the **Quiet Kill Chain** —
a sequence of legitimate-looking actions that, when chained together, become an attack path.No loud exploits.
No obvious malware.
Just normal activity… used the wrong way.## What changes at an advanced level?
You stop asking:
“What exploit should I use?”And start asking:
• Where does this system trust too easily?
• Which action would look completely normal?
• What would defenders ignore?
• How can I blend into business operations?Because the strongest intrusion today is not the one that is invisible.
It’s the one that looks **legitimate**.
## My takeaway
Offensive security is shifting from breaking systems
to understanding them deeply enough to move inside them unnoticed.I’ve written a full deep-dive on this concept here 👇
Curious to hear your thoughts —
Is detection today ready for this level of subtlety?#CyberSecurity #RedTeam #OffensiveSecurity #ThreatIntel #CloudSecurity #IdentitySecurity #EthicalHacking #BlackCipher
-
Microsoft Fixes Entra ID Flaw That Enabled Service Principal Takeovers
Microsoft has patched a vulnerability in Entra ID that allowed hackers to hijack service principals, potentially leading to full takeover of sensitive systems. A security researcher discovered the flaw, which stemmed from overly broad permissions in the Agent ID Administrator role.
#EntraId #ServicePrincipalTakeover #IdentitySecurity #PrivilegeEscalation #Microsoft
-
The next breach won’t start with malware. It’ll start with an AI agent
https://youtu.be/ATmE3VceSOA #Cybersecurity #ArtificialIntelligence #AIAgents #AgenticAI #AISecurity #EnterpriseSecurity #ZeroTrust #IdentitySecurity #AutomationRisk #DigitalTransformation #Infosec #CyberRisk -
82% of enterprises are running AI agents they don't know about.
That number came out of #RSAC Conference 2026 — and it wasn't the most alarming stat on the table.
Sean Martin sat back down with Itamar Apelblat, Co-Founder and CEO of Token Security, to unpack what he heard walking the show floor and what the CSA data now makes impossible to ignore: 65% of organizations have already had an AI agent-related incident in the last twelve months. 82% found agents in their environment that nobody authorized. Only 21% have any formal process to retire an agent when it's done.
Discovery alone is not governance. Intent-based enforcement is. That's where this conversation lands — and it's worth your time.
A huge thank you to the team at Token Security for joining Sean Martin and Marco Ciappelli on this journey — both on the floor at #RSAC2026 and in the recap. We loved sharing your story and we're looking forward to many more conversations ahead. 🙌
📍 Where are we headed next? Glad you asked: Infosecurity Europe and Black Hat USA — see you there.
🎙️ Recap: https://youtu.be/ZeI5bSbQ070
🎙️ On Location: https://youtu.be/uWjCQC3LnaY
🌐 RSAC Coverage: https://www.itspmagazine.com/rsac
🌐 Next Coverages: https://www.itspmagazine.com/technology-and-cybersecurity-conference-coverage#TokenSecurity #AIAgents #AgentSecurity #CyberSecurity #CISO #CloudSecurity #AIGovernance #IdentitySecurity #CSAReport #InfoSec #RSAC2026 #InfosecurityEurope #BlackHatUSA #CyberSecurityPodcast
-
82% of enterprises are running AI agents they don't know about.
That number came out of #RSAC Conference 2026 — and it wasn't the most alarming stat on the table.
Sean Martin sat back down with Itamar Apelblat, Co-Founder and CEO of Token Security, to unpack what he heard walking the show floor and what the CSA data now makes impossible to ignore: 65% of organizations have already had an AI agent-related incident in the last twelve months. 82% found agents in their environment that nobody authorized. Only 21% have any formal process to retire an agent when it's done.
Discovery alone is not governance. Intent-based enforcement is. That's where this conversation lands — and it's worth your time.
A huge thank you to the team at Token Security for joining Sean Martin and Marco Ciappelli on this journey — both on the floor at #RSAC2026 and in the recap. We loved sharing your story and we're looking forward to many more conversations ahead. 🙌
📍 Where are we headed next? Glad you asked: Infosecurity Europe and Black Hat USA — see you there.
🎙️ Recap: https://youtu.be/ZeI5bSbQ070
🎙️ On Location: https://youtu.be/uWjCQC3LnaY
🌐 RSAC Coverage: https://www.itspmagazine.com/rsac
🌐 Next Coverages: https://www.itspmagazine.com/technology-and-cybersecurity-conference-coverage#TokenSecurity #AIAgents #AgentSecurity #CyberSecurity #CISO #CloudSecurity #AIGovernance #IdentitySecurity #CSAReport #InfoSec #RSAC2026 #InfosecurityEurope #BlackHatUSA #CyberSecurityPodcast
-
82% of enterprises are running AI agents they don't know about.
That number came out of #RSAC Conference 2026 — and it wasn't the most alarming stat on the table.
Sean Martin sat back down with Itamar Apelblat, Co-Founder and CEO of Token Security, to unpack what he heard walking the show floor and what the CSA data now makes impossible to ignore: 65% of organizations have already had an AI agent-related incident in the last twelve months. 82% found agents in their environment that nobody authorized. Only 21% have any formal process to retire an agent when it's done.
Discovery alone is not governance. Intent-based enforcement is. That's where this conversation lands — and it's worth your time.
A huge thank you to the team at Token Security for joining Sean Martin and Marco Ciappelli on this journey — both on the floor at #RSAC2026 and in the recap. We loved sharing your story and we're looking forward to many more conversations ahead. 🙌
📍 Where are we headed next? Glad you asked: Infosecurity Europe and Black Hat USA — see you there.
🎙️ Recap: https://youtu.be/ZeI5bSbQ070
🎙️ On Location: https://youtu.be/uWjCQC3LnaY
🌐 RSAC Coverage: https://www.itspmagazine.com/rsac
🌐 Next Coverages: https://www.itspmagazine.com/technology-and-cybersecurity-conference-coverage#TokenSecurity #AIAgents #AgentSecurity #CyberSecurity #CISO #CloudSecurity #AIGovernance #IdentitySecurity #CSAReport #InfoSec #RSAC2026 #InfosecurityEurope #BlackHatUSA #CyberSecurityPodcast