TENB Tenable Holdings

Tenable Research Reveals Popular AI Tools Used in Cloud Environments are Highly Vulnerable

Tenable Research Reveals Popular AI Tools Used in Cloud Environments are Highly Vulnerable

Analysis finds 70% of cloud workloads using AI services contain unresolved vulnerabilities

COLUMBIA, Md. , March 19, 2025 (GLOBE NEWSWIRE) -- , the exposure management company, today announced the release of its , which found that cloud-based AI is prone to avoidable toxic combinations that leave sensitive AI data and models vulnerable to manipulation, data tampering and data leakage.

Cloud and AI are undeniable game changers for businesses. However, both introduce complex cyber risks when combined. The Tenable Cloud AI Risk Report 2025 highlights the current state of security risks in cloud AI development tools and frameworks, and in AI services offered by the three major cloud providers—Amazon Web Services (AWS), Google Cloud Platform (GCP) and Microsoft Azure. The key findings from the report include:

  • Cloud AI workloads aren’t immune to vulnerabilities: Approximately 70% of cloud AI workloads contain at least one unremediated vulnerability. In particular, Tenable Research found —a critical curl vulnerability—in 30% of cloud AI workloads.
  • Jenga®-style1 cloud misconfigurations exist in managed AI services: 77% of organizations have the overprivileged default Compute Engine service account configured in Google Vertex AI Notebooks. This means all services built on this default Compute Engine are at risk.
  • AI training data is susceptible to data poisoning, threatening to skew model results: 14% of organizations using Amazon Bedrock do not explicitly block public access to at least one AI training bucket and 5% have at least one overly permissive bucket.
  • Amazon SageMaker notebook instances grant root access by default: As a result, 91% of Amazon SageMaker users have at least one notebook that, if compromised, could grant unauthorized access, which could result in the potential modification of all files on it.

“When we talk about AI usage in the cloud, more than sensitive data is on the line. If a threat actor manipulates the data or AI model, there can be catastrophic long-term consequences, such as compromised data integrity, compromised security of critical systems and degradation of customer trust,” said Liat Hayun, VP of Research and Product Management, Cloud Security, Tenable. “ measures must evolve to meet the new challenges of AI and find the delicate balance between protecting against complex attacks on AI data and enabling organizations to achieve responsible AI innovation.”

1 The Jenga®-style concept, coined by Tenable, identifies the tendency of cloud providers to build one service on top of the other, with “behind the scenes” building blocks inheriting risky defaults from one layer to the next. Such cloud misconfigurations, especially in AI environments, can have severe risk implications if exploited.

About Tenable

Tenable® is the exposure management company, exposing and closing the cybersecurity gaps that erode business value, reputation and trust. The company’s AI-powered radically unifies security visibility, insight and action across the attack surface, equipping modern organizations to protect against attacks from IT infrastructure to cloud environments to critical infrastructure and everywhere in between. By protecting enterprises from security exposure, Tenable reduces business risk for approximately 44,000 customers around the globe. Learn more at .

Media Contact:

Tenable



EN
19/03/2025

Underlying

To request access to management, click here to engage with our
partner Phoenix-IR's CorporateAccessNetwork.com

Reports on Tenable Holdings

 PRESS RELEASE

Tenable Achieves FedRAMP Authorization for Tenable One and Tenable Clo...

Tenable Achieves FedRAMP Authorization for Tenable One and Tenable Cloud Security COLUMBIA, Md., April 02, 2025 (GLOBE NEWSWIRE) -- , the exposure management company, today announced that it achieved Federal Risk and Authorization Management Program (FedRAMP®) authorization at the Moderate impact level for its Exposure Management Platform as well as , underscoring its commitment to strengthening government infrastructure and reducing cybersecurity risk to support national security. Tenable released Tenable One FedRAMP and Tenable Cloud Security FedRAMP to enable U.S. federal agencies ...

 PRESS RELEASE

Tenable Earns Elite 5-Star Rating in 2025 CRN Partner Program Guide

Tenable Earns Elite 5-Star Rating in 2025 CRN Partner Program Guide COLUMBIA, Md., March 25, 2025 (GLOBE NEWSWIRE) -- , the exposure management company, today announced it has been recognized by , a brand of , with a prestigious 5-Star Award in the . The 5-Star Award is an elite recognition given to companies that have built their partner programs on the key elements needed to nurture lasting, profitable and successful channel partnerships. For the 2025 Partner Program Guide, the CRN research team evaluated vendors based on program requirements and offerings such as partner training ...

 PRESS RELEASE

Tenable Research Reveals Popular AI Tools Used in Cloud Environments a...

Tenable Research Reveals Popular AI Tools Used in Cloud Environments are Highly Vulnerable Analysis finds 70% of cloud workloads using AI services contain unresolved vulnerabilities COLUMBIA, Md. , March 19, 2025 (GLOBE NEWSWIRE) -- , the exposure management company, today announced the release of its , which found that cloud-based AI is prone to avoidable toxic combinations that leave sensitive AI data and models vulnerable to manipulation, data tampering and data leakage. Cloud and AI are undeniable game changers for businesses. However, both introduce complex cyber risks when combin...

 PRESS RELEASE

Tenable to Participate in Upcoming Investor Events

Tenable to Participate in Upcoming Investor Events COLUMBIA, Md., Feb. 25, 2025 (GLOBE NEWSWIRE) -- , the exposure management company, today announced its co-chief executive officer and chief financial officer, Steve Vintz, and co-chief executive officer and chief operating officer, Mark Thurmond, will attend the Morgan Stanley Technology, Media & Telecom Conference. Vintz will also attend the Cantor Global Technology Conference. Details for each event are as follows: Morgan Stanley Technology, Media & Telecom ConferenceMarch 4, 2025 Cantor Global Technology ConferenceMarch 11, 2...

 PRESS RELEASE

Tenable Strengthens Its Identity Exposure Capabilities to Protect Agai...

Tenable Strengthens Its Identity Exposure Capabilities to Protect Against Compromises Tenable Identity Exposure addresses identity sprawl security challenges with 360-degree visibility into identity risk COLUMBIA, Md., Feb. 18, 2025 (GLOBE NEWSWIRE) -- , the exposure management company, today announced the launch of Identity 360 and Exposure Center, two new capabilities designed to help organizations pinpoint identity risks and take swift, targeted action to prevent identity-based attacks. Identity management has become fragmented, leading to identity sprawl - a tangled web of account...

ResearchPool Subscriptions

Get the most out of your insights

Get in touch