惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
IT之家
IT之家
博客园 - 叶小钗
雷峰网
雷峰网
T
Tailwind CSS Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
S
SegmentFault 最新的问题
Apple Machine Learning Research
Apple Machine Learning Research
爱范儿
爱范儿
博客园 - 【当耐特】
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
大猫的无限游戏
大猫的无限游戏
Last Week in AI
Last Week in AI
月光博客
月光博客
酷 壳 – CoolShell
酷 壳 – CoolShell
Jina AI
Jina AI
博客园 - Franky
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
宝玉的分享
宝玉的分享
阮一峰的网络日志
阮一峰的网络日志
Hugging Face - Blog
Hugging Face - Blog
博客园 - 司徒正美

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Key Takeaways from the 2026 State of AI in the Cloud Report
Wiz Threat Research · 2026-04-30 · via Wiz Blog | RSS feed

Artificial Intelligence has officially crossed the chasm from experimental pilot to foundational cloud infrastructure. In just a few years, AI systems have moved from limited rollouts to a core layer embedded across applications, developer workflows, and business operations.

But as AI becomes more autonomous and deeply connected to real systems and data, the security landscape is shifting. Securing AI is no longer just about protecting models; it is about understanding how AI interacts with infrastructure, identities, and automation.

The 2026 State of AI in the Cloud report analyzed hundreds of thousands of real world cloud environments to see how organizations are deploying and how attackers are targeting AI today.

Read the full report to see the full scope of data findings, but here are a few key takeaways you need to know.

1. AI is Now Core Cloud Infrastructure

AI adoption has stabilized at scale. At least 81% of cloud environments we observed use managed AI services, and 90% run self hosted AI software. AI is no longer a niche project; it is present within every major industry across development workflows and automation tooling.

The shift is moving from pure consumption of managed services toward greater ownership. However, this ownership is often indirect: 68% of organizations running self hosted models ingest them through third party software. This suggests that some organizations may be operating self-hosted AI components without fully realizing it.

2. AI-Assisted Development Is the Default, with Systemic Effects Across Applications

AI assisted development is now the default behavior for engineers. At least 80% of organizations have developers using AI IDE extensions, and 71% have at least one AI coding assistant present.

The risk here is structural. When AI generated code, configurations, and access patterns are repeated across projects, small mistakes become systemic weaknesses. In late 2025, Wiz Research found that roughly one in five organizations using AI powered "vibe coding" platforms had applications affected by systemic security issues rooted in shared generation patterns.

3. Agents and MCP Servers Expand the Attack Surface

We are seeing a rapid shift from AI that assists humans to AI that acts autonomously. At least 57% of organizations have deployed self hosted AI agent technologies, and Model Context Protocol (MCP) servers appear in 80% of environments.

These orchestration layers introduce new control plane risks. If an agent is overprivileged or connected to the internet without proper guardrails, it can create a "lethal trifecta" where an attacker hijacks an autonomous entity to move laterally through sensitive data stores.

4. AI is Changing the Economics of Exploitation

AI isn’t just part of the environment. It’s reshaping how attacks are executed.

As we explored in our 2026 Cloud Threats Retrospective, AI reduces the cost of discovery, accelerates exploit development, and enables attackers to scale familiar techniques more efficiently.

This shift is already visible. Research from Wiz and other vendors has documented malware using LLMs to dynamically generate commands and adapt execution logic at runtime, reducing reliance on static payloads. Attackers have also abused AI-enabled OAuth integrations to move laterally across SaaS environments by leveraging trusted automation paths.

AI is also accelerating vulnerability discovery. In the Zeroday.cloud research effort, AI-assisted analysis contributed to the discovery of 13 zero-day vulnerabilities in widely deployed cloud software. This trend is already visible in frontier models like Anthropic’s Claude Mythos, which has demonstrated the ability to autonomously discover zero-day vulnerabilities and generate working exploits, significantly compressing the time between discovery and exploitation.

These are not new attack classes. They are established techniques executed faster and at greater scale. As vulnerability discovery and exploit development become more automated, attackers can iterate more quickly, test more hypotheses, and reduce the cost of exploitation. The result is more attempts, faster cycles, and sustained pressure on defensive teams.

The Path Forward

AI security is not a future discipline. It is a present day extension of cloud security that must account for autonomy and the rapid spread of AI driven systems. To stay ahead, organizations must:

  • Inventory AI as core infrastructure: Treat AI components as first class citizens in your asset inventory.

  • Extend governance across distributed ownership: AI security cannot sit in a silo; it must be integrated into AppSec and data governance.

  • Use context to cut through the noise: Understand how AI assets connect to identities, permissions, and sensitive data to prioritize the risks that actually matter.

State of AI in the Cloud 2026

Download the full State of AI in the Cloud 2026 report to explore the data, trends, and practical steps needed to secure AI as core cloud infrastructure.