Links
AddOn April 21, 2026, a major breakthrough in cybersecurity happened: leading standardization initiatives gathered in Washington DC and agreed to begin coordinating collectively on AI security. A personal dream come true. The result: MOSAIC: Multi-Organization Secure AI Coordination. The goal: turn a fragmented landscape into clear, consistent standards and guidelines, to deal with the mounting risks of AI.
This important step was taken at the AI Security Policy Forum, organised and led by the OWASP AI Exchange, with SANS Institute as co-host - convening standard makers and policy stakeholders.
The initiatives at the table included: π BIML (Berryville Institute of Machine Learning) π Center for Internet Security (CIS) π Cloud Security Alliance (CSA) π Coalition for Secure AI (CoSAI) π National Institute of Standards and Technology (NIST) π OWASP AI Exchange (AIX) π OWASP GenAI Security Project π SANS Institute
The group agreed that it is now more important than ever to coordinate around the rapidly evolving possibilities and challenges of AI, as AI security risks mount.
One of the next steps is to provide a standardized map of the participating initiatives and a communication platform to exchange insights on a first list of identified topics (e.g., aligning with other initiatives such as SC42, building on OpenCRE, consensus on definitions), improve consistency, clarity, quality, and prevent unnecessary duplication. The idea is to move fast while maintaining independence and with lightweight coordination - not add more committees.
In addition to the organizations mentioned, the discussion also included journalists, representatives from International Telecommunication Union (ITU), The Aspen Institute, academia, and government β providing valuable perspectives on developments in both policy and industry. This helped prioritize the topics to focus on.
In the picture, from left to right, standing to sitting: Disesdi Shoshana Cox (AIX), Gary McGraw(BIML), Rob van der Veer (AIX), Anonymous, Duncan Sparrell, John Yeoh (CSA), Rock Lambros (GenAI), Norma Krayem, Brian Calkin (CIS), Matt Altomare (Aspen), Omar Santos (CoSAI), Aruneesh Salhotra (AIX), Jonathan Gibson (The Dispatch), Apostol Vassilev (NIST), Rhea Nygard, Ken Huang, Lav Varshney (Stony Brook University), Sounil Yu, and Sharon Goldman (Fortune)
Not in the picture, but involved, in alphabetical order: Rob T. Lee (SANS), Ryan Galluzzo (NIST), Soribel F.
A big thank you to: π Disesdi Shoshana CoxΒ for her idea to bring everybody together in a room to fulfil the connecting mission of the Exchange π The amazing thinktank at the AI Exchange π Spyros Gasteratos for his work on OpenCRE π Violeta Klein, CISSP, CEFA for shaping the story for the Forum π Straiker, Casco (YC X25), AI Security Academy, and SANS for supporting the Forum. π Software Improvement Group for donating the original threat model and initiating the AI Exchange
Letβs make AI a success! | 28 comments on LinkedIn
The most repairable pro laptop is here. Get 20 hours of battery & peak performance with Intel Core Ultra Series 3. CNC aluminum with excellent Linux support. Secure yours today!
bgp.tools allows you to do bgp debugging and gives insight into internet routing with ease in a user friendly way
Team chat without the bloat. Unlimited search, even on free. No AI tax. No feature overload. Built for startups who ship.
more details: https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan Most likely, a maintainer's GitHub and npm accounts are compromised as these issues are getting deleted. I have also rep...
SaturnCI: Continuous Integration for Ruby on Rails
Eastman Kodak, the 133-year-old photography company, is warning investors thats it might not survive much longer.
Customize the web to work exactly how you want
Create clips from media on your personal media server - TechSquidTV/Cliparr
With informed decision-making, organizations can strengthen their overall resilience and maintain the agility needed to adapt to emerging threats, without sacrificing innovation or productivity.
AWS serverless experts Chris Munns & Ronald Widha walk you through developing a simple serverless application. You will learn how to use AWS Lambda, Amazon...
Jigsaw is an interdisciplinary unit within Google that builds technology that inspires scalable solutions.
In this article, I will present some cool tools that can be used to test and ensure the quality of your Docker image. Tagged with testing, docker.
Itβs still legal to pick locks, even when you swing your legs.
SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.
Suppose you're wandering around a space without any particular destination in mind β exploring a park maybe, or ambling across a music festival site.
SMBC is a daily comic strip about life, philosophy, science, mathematics, and dirty jokes.
OpenCoder is an open and reproducible code LLM family which includes 1.5B and 8B models, supporting chat in English and Chinese languages.
Introduction