New way to build itTVM-04 · 2026-07-20
CSA Publishes MAESTRO: First Agentic AI Threat Modeling Framework with Beginner-Accessible Guide
The Cloud Security Alliance published MAESTRO (Multi-Agent Environment, Security, Threat, Risk, and Outcome) in February 2025, a seven-layer threat modeling framework designed specifically for agentic AI systems. The framework addresses gaps left by STRIDE, PASTA, and other traditional methods that fail to model autonomous agent behavior, emergent properties, and multi-agent interactions. A detailed blog post on the CSA site provides a beginner-accessible walkthrough comparing MAESTRO against existing frameworks and explaining each layer. The framework has gained adoption in 2026 as agentic AI deployment accelerates, making it an essential methodology for AI security newcomers to learn.
Sharpens: Study the MAESTRO framework by reading the CSA blog post, then apply it to a hands-on exercise: pick an AI agent scenario (e.g., a coding agent with tool access), map its seven layers, and identify at least one threat per layer. Compare your findings against what STRIDE alone would have caught to understand where MAESTRO adds value for agentic AI systems. · source
New way to build itHRS-14 · 2026-07-20
Heron AI Security Research Fellowship Opens Autumn 2026 Cohort for Cybersecurity-to-AI Transitions
Heron launched its AI Security Research Fellowship for September-November 2026, matching experienced cybersecurity professionals with frontier AI security researchers on 10-12 collaborative projects. Focus areas include adversarial and model security, AI control and containment, AI infrastructure security, and cybersecurity evaluations. Teams receive $1,000+ in compute credits, Claude Code Team Accounts, and up to $5,000 in conference travel funding. While the program targets professionals with 5+ years of cybersecurity experience, it serves as a structured onramp for transitioning into AI security research from traditional cybersecurity roles, with no prior AI background required.
Sharpens: If you have 5+ years of cybersecurity experience and want to transition into AI security research, apply to the next Heron fellowship cycle. Even if applications for the current cohort are closed, submit an expression of interest for future cohorts. Build your application profile by contributing to open-source AI security tools (Garak, Counterfit) and reading recent AI security papers on arXiv. · source
New way to build itTVM-07 · 2026-07-20
Comprehensive Beginner AI Red Teaming Guide Maps Career Pathways and Tools for 2026
Practical DevSecOps published an updated beginner guide to AI red teaming in January 2026, covering the full landscape of adversarial testing for AI systems: manual vs. automated approaches, top open-source tools (Garak, Counterfit, AugLy), frameworks (MITRE ATLAS, OWASP Top 10 for LLMs), and career pathways. The guide outlines specific skills for AI red teamers including Python, machine learning fundamentals, threat modeling, and adversarial thinking. AI security roles such as AI Security Consultant and Red Team Lead are highlighted with high salary and rapid growth potential.
Sharpens: Start your AI red teaming journey by reading the complete beginner guide, then install Garak (open-source LLM vulnerability scanner) and run it against a local model to practice identifying prompt injection, jailbreak, and bias vulnerabilities. Document your findings and build a portfolio project around your first AI security assessment. · source
New way to build itHRS-14 · 2026-07-20
Anthropic Academy Releases 11 Free Self-Paced AI Courses with Certificates
Anthropic Academy launched 11 free, self-paced AI courses with completion certificates in 2026, covering AI fluency fundamentals, building with the Claude API, and the Model Context Protocol (MCP) for connecting AI agents to external tools. The flagship course, AI Fluency: Framework and Foundations, teaches effective, ethical, and safe collaboration with AI systems. Specialized tracks exist for educators, students, and nonprofits. No Anthropic account is required to enroll, making this one of the most accessible free AI learning pathways available for newcomers to AI security.
Sharpens: Enroll in the free AI Fluency: Framework and Foundations course at Anthropic Academy to build a structured understanding of AI collaboration fundamentals, then progress to the MCP course to learn how AI agents connect to external tools, a rapidly growing skill area for AI security professionals. · source
New way to build itHRS-14 · 2026-07-20
CompTIA SecAI+ Certification Launches as First Vendor-Neutral AI Security Credential
CompTIA launched SecAI+ in 2026 as the first vendor-neutral certification for AI security, targeting cybersecurity professionals who want to validate skills in securing AI systems, automating defenses, and managing AI-specific risks. The certification assumes foundational cybersecurity knowledge and bridges traditional security skills into the AI domain. Multiple training providers now offer bootcamps (5-day intensive programs) and self-study paths for the exam. This credential addresses the growing demand for standardized AI security competency assessment at the entry and mid-career levels.
Sharpens: Pursue the CompTIA SecAI+ certification by completing the official study guide or a 5-day bootcamp (approximately $1,000), then pass the exam to add an AI-specific credential to your security resume. Pair this with hands-on practice using free tools like Garak and Counterfit to demonstrate practical AI security skills alongside the certification. · source
What just shiftedTVM-04 · 2026-07-19
HiddenLayer 2026 AI Threat Landscape Report reveals agentic AI breaches and shadow AI surge reshaping entry-level priorities
Released March 18, 2026, HiddenLayer's third annual AI Threat Landscape Report surveyed 250 IT and security leaders. Key findings: 1 in 8 reported AI breaches now linked to agentic systems, malware in public model repositories is the most cited breach source (35%), shadow AI surged to 76% of organizations (up from 61% in 2025), and 31% of organizations do not know if they experienced an AI breach. Only 34% partner externally for AI threat detection, and 73% report internal conflict over AI security ownership. The report identifies three major shifts: agentic AI moving to production, reasoning/self-improving models becoming mainstream, and smaller edge AI models decentralizing attack surfaces away from cloud controls.
Sharpens: Newcomers must prioritize agentic AI security as the fastest-growing attack surface. Learn AI supply chain security fundamentals since public model repositories are the top breach vector. Develop shadow AI detection and governance skills. Build competency in AI-specific incident response and breach detection since 31% of orgs cannot confirm breaches. Understand the security implications of edge AI deployment patterns and agent-to-agent communication protocols. · source
Control ids above refer to the CSA AI Controls Matrix (AICM).