惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Tenable Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
V
Vulnerabilities – Threatpost
G
GRAHAM CLULEY
Simon Willison's Weblog
Simon Willison's Weblog
C
CXSECURITY Database RSS Feed - CXSecurity.com
P
Privacy International News Feed
H
Heimdal Security Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
S
Secure Thoughts
MyScale Blog
MyScale Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
V
Visual Studio Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
L
LINUX DO - 最新话题
D
Darknet – Hacking Tools, Hacker News & Cyber Security
The Cloudflare Blog
美团技术团队
Recorded Future
Recorded Future
T
Tailwind CSS Blog
Latest news
Latest news
Security Archives - TechRepublic
Security Archives - TechRepublic
Security Latest
Security Latest
Know Your Adversary
Know Your Adversary
Cloudbric
Cloudbric
Schneier on Security
Schneier on Security
I
Intezer
L
LINUX DO - 热门话题
P
Palo Alto Networks Blog
云风的 BLOG
云风的 BLOG
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Vercel News
Vercel News
Attack and Defense Labs
Attack and Defense Labs
人人都是产品经理
人人都是产品经理
L
LangChain Blog
爱范儿
爱范儿
博客园 - 三生石上(FineUI控件)
博客园 - 叶小钗
L
Lohrmann on Cybersecurity
S
SegmentFault 最新的问题
W
WeLiveSecurity
C
Cybersecurity and Infrastructure Security Agency CISA
S
Securelist
SecWiki News
SecWiki News
V2EX - 技术
V2EX - 技术
IT之家
IT之家
Cyberwarzone
Cyberwarzone
F
Full Disclosure
Spread Privacy
Spread Privacy
阮一峰的网络日志
阮一峰的网络日志

Tenable Blog

Oracle July 2026 Critical Patch Update 1235 CVEs | Tenable® AI agent config attacks: How attackers turn trusted Dev harness files into payloads wp2shell: WordPress Core Pre-Auth RCE FAQ | Tenable® SharePoint CVEs FAQ: CVE-2026-56164, CVE-2026-32201, CVE-2026-45659 | Tenable® Build agentic AI security at Tenable Swarm, Black Hat 2026 SonicWall CVE-2026-15409 and CVE-2026-15410 zero-day exploited | Tenable® Understanding Anthropic’s new AI agent Claude Tag’s access model in Slack 5 reasons to integrate AppSec data with your exposure management platform July 2026 Patch Tuesday: Largest Patch Tuesday 569 CVEs FedRAMP High, IL5, and zero trust: How federal agencies can secure cloud environments OMB M-26-14: Why federal agencies must fix asset visibility first CISO’s guide to CISA BOD 26-04 and risk-based security metrics for vulnerability management How much cyber risk does AI create for organizations? 457 million security issues. Here’s what you can do about it. The Developer Credential Economy: An inside look at the Miasma worm campaign Oracle Critical Security Patch Update June 2026 | Tenable® How Tenable helps federal agencies comply with CISA BOD 26-04 Get critical cyber risk context: Understanding control validation, CTEM & Tenable One CISA BOD 26-04: Frequently asked questions about the new risk-based patching directive Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507) The June 2026 AI Executive Order: What federal agencies need to know and how Tenable can help Tenable joins Anthropic’s Project Glasswing to advance AI-era cyber defense Tenable CTO Vlad Korsunsky Q&A: Countering AI threat multipliers with AI-powered exposure management | Tenable CTO Q&A: C-suite views AI as massive threat, as cyber teams adopt exposure management to counter AI attacks Oracle May 2026 Critical Security Patch Update Addresses 35 CVEs Download pumping: New npm deception technique for supply chain attacks Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect EXPOSURE 2026 prepares cybersecurity professionals for the AI era Mini Shai-Hulud: Frequently asked questions about the TeamPCP npm and PyPI supply chain campaign CVE-2026-9082: Highly Critical SQL Injection Vulnerability in Drupal Core (SA-CORE-2026-004) Tenable One deepens third-party integrations with new Open Connector for unified risk visibility Implement agentic AI in cybersecurity with Tenable Hexa AI: Reduce cyber risk at machine speed Key findings from the Verizon DBIR 2026: Slower vulnerability remediation meets faster exploitation Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182) Bring out your dead: How agentic AI for cybersecurity helps you rid your cloud of forgotten, risky assets Fragnesia (CVE-2026-46300): Frequently asked questions about new Linux Kernel XFRM ESP-in-TCP privilege escalation Securing data centers in the agentic AI era Microsoft’s May 2026 Patch Tuesday Addresses 118 CVEs (CVE-2026-41103) Dirty Frag (CVE-2026-43284, CVE-2026-43500): Frequently asked questions about this Linux kernel privilege escalation vulnerability chain Why the approaching flood of vulnerabilities changes everything — and what to do about it The AI-vs-AI battle is already happening. Watch it live at EXPOSURE 2026. Anthropic’s CEO warns the “moment of danger” is real. But most are looking in the wrong place. Vulnerability remediation: Match CVEs to asset owners in seconds with Tenable Hexa AI Bridging the gap: How to integrate Claude Security into the Tenable One Exposure Management Platform Copy Fail (CVE-2026-31431): Frequently asked questions about Linux kernel privilege escalation vulnerability Mastering agentic AI security through exposure management As the NVD scales back CVE enrichment, here’s what Tenable customers need to know Five steps to become Mythos ready Oracle April 2026 Critical Patch Update Addresses 241 CVEs Beating the Mythos clock: Using Tenable Hexa AI custom agents for automated patching Unlocking foundational visibility for cyber-physical systems with OT vulnerability management Claude Mythos: Prepare for your board’s cybersecurity questions about the latest AI model from Anthropic Microsoft’s April 2026 Patch Tuesday Addresses 163 CVEs (CVE-2026-32201) Crushing the Axios supply chain threat with Tenable Hexa AI: Use cases for agentic AI What to Know About CyberAv3ngers: The IRGC-Linked Group Targeting Critical Infrastructure CVE-2026-35616: Fortinet FortiClientEMS improper access control vulnerability exploited in the wild The developer credential economy: Why exposure data is the new front line in the supply chain war Frequently Asked Questions About the Axios npm Supply Chain Attack by North Korea-Nexus Threat Actor UNC1069 Supply chain attack on Axios npm package: Scope, impact, and remediations What’s new in Tenable Cloud Security: Custom policies, AWS ABAC, and research-driven protection Uncover prompt injection, insider threats with the Tenable One Model Refusal Detection Security for AI: A guide to managing the risks of vibe coding and AI in software development Meet Tenable Hexa AI: Agentic AI for exposure management
Security for AI: A strategic framework for closing the AI exposure gap
Robert Huber · 2026-05-04 · via Tenable Blog

As AI adoption accelerates, CISOs face a dual challenge: fueling innovation while mitigating the risks of a rapidly expanding attack surface. Tenable’s five-step framework for securing AI offers a systematic approach to reducing AI security risks as your organization races to achieve the productivity benefits of AI. 

Key takeaways

  1. Get a five-step framework to help you secure AI usage throughout your organization and mitigate the security risks that AI tools create.
     
  2. Securing enterprise AI use demands a combination of robust AI discovery capabilities, mechanisms to secure AI workloads and the infrastructure running AI, prompt-level visibility, the ability to analyze AI security risks alongside other exposures, and technical controls to ensure compliance with your organization’s AI acceptable use policy. 
     
  3. Learn why your existing security controls may be inadequate when it comes to securing AI.

As AI transforms enterprises, security leaders like me are grappling with how to most effectively manage the security risks it creates.

The challenge is that AI is now embedded virtually everywhere across our organizations: in employee productivity tools, SaaS platforms, developer libraries, cloud services, APIs, and web apps. The result? Our teams are left with a growing AI exposure gap: a vast and largely invisible attack surface that our traditional security tools weren’t designed to monitor

Complicating matters is that we often can’t isolate AI risk to a single asset. Rather, it emerges from a string of interconnected elements (such as applications, infrastructure, identities, and data) that in aggregate create exposure. Here’s an example of what I mean.

Let's say an employee uses an approved AI chatbot for technical support resolution that relies on Amazon Bedrock agents, and those agents have elevated privileges to access sensitive internal systems like enterprise resource planning and customer resource management tools. If a threat actor gains access to the agent through an unpatched vulnerability on the employee’s laptop, then the threat actor can use the agent to breach sensitive data, and a seemingly safe use of an approved AI tool turns out to be a high-impact exposure.

Protecting data in today’s AI-assisted work environments becomes exponentially more difficult because each one of the myriad interactions with AI assets (e.g., every prompt, file upload, generated response, integration, and configuration) can put intellectual property, customer information, and confidential plans at risk.

So, how do we tame this challenging new attack surface that grows unchecked as our organizations expand their use of AI? Here’s a strategic framework I’ve implemented for governing, discovering, and securing AI wherever it crops up and creates risk for your organization. 

Strategic framework: 5 steps for securing enterprise AI

1. Establish an AI governance committee, framework, and acceptable use policy

Securing AI starts with setting clear expectations with employees about acceptable use. Establish an AI acceptable use policy that:

  • provides a list of approved and unapproved AI tools;
  • defines appropriate and inappropriate business use cases;
  • explains the types of data that can and can’t be shared with LLMs;
  • prescribes rules for data handling;
  • addresses copyright laws; and
  • states the consequences of policy violations.

Based on your organization’s AI acceptable use policy, you can implement controls to enforce and monitor compliance with it.

2. Discover AI across your entire attack surface 

When I talk with other CISOs about securing AI, they say discovering and detecting it is one of their biggest challenges. And I get it: it’s freakin’ everywhere, and a lot of it is really hard to find, in part because AI’s presence extends well beyond centrally-managed systems that are clearly visible. 

As security leaders, we need to account for: 

  • AI assets, agents, plugins, browser extensions, and workloads, regardless of whether they’re...
    • run in the cloud or on-premises
    • internally or externally accessible
    • approved or unapproved
  • Forgotten AI test deployments
  • AI tools embedded in endpoints and applications
  • All AI software, libraries, models, and services
  • Publicly exposed AI services, large language model (LLM) APIs, and AI chatbots on endpoints and in cloud applications.

Your existing data loss prevention (DLP), cloud access security brokers (CASB), and cloud security posture management (CSPM) solutions can provide a good initial starting point to discover AI assets. But holistic discovery requires specialized discovery tools because the non-deterministic nature of AI defies traditional rules-based security protections. It also requires unique detection capabilities to identify embedded AI tools and libraries and understand how AI systems work together to create exposure.

With a continuous and complete view of your enterprise’s AI usage, you’ll know precisely what workloads and infrastructure you need to secure, and you can begin to assess your organization’s overall AI exposure and prioritize specific remediation actions accordingly.

3. Secure AI workloads and agents

Because AI workloads are deeply interconnected and often severely misconfigured or over-permissioned, this step involves proactively securing the infrastructure where AI runs and hardening AI workloads before attackers can exploit them. For example, if developers at your organization are building AI-enabled applications in the cloud, you want to make sure that cloud infrastructure is secure. 

Effective protections require capabilities to: 

  • Identify misconfigurations and risky configurations in cloud-based AI workloads.
  • Detect vulnerabilities that could expose models, agents, data, or APIs to unauthorized access.
  • Implement identity-driven exposure reduction, since AI relies heavily on non-human identities.
  • Detect the overprivileged service accounts, roles, and machine identities that AI workflows use and strictly enforce least-privilege access.
  • Understand potential attack pathways from AI assets and workloads that could impact business-critical systems or lead to sensitive data.
  • Quickly isolate erratic or compromised AI agents into controlled environments to minimize potential breach impact.

I’ll dive deeper into this specific topic of securing AI workloads and agents in a follow-up blog I have planned. In the meantime, you can understand how identity weaknesses and infrastructure flaws combine to create critical exposure by conducting deep risk analysis of your AI stack. Based on these insights, you can provide actionable playbooks to your security teams to harden environments and ensure services run on secure, resilient, and validated architectures.

4. Assess AI usage and interactions

This step involves understanding how your employees interact with generative AI tools and autonomous agents to make sure employees aren’t violating your organization’s AI acceptable use policy. It’s critical to understand how data flows through all AI applications and determine where exposure is being created. 

This requires granular visibility into: 

  • Who’s using AI
  • For what purpose
  • Where risky behavior and misuse originates
  • What data employees are sharing through prompts, uploads, or automated actions
  • Attempts to jailbreak approved AI tools and provide malicious prompts

Prompt-level visibility into employee AI use allows your security team to detect policy violations and reinforce safe AI behavior. It also allows your security team to identify any sensitive data, including intellectual property and PII, that employees or agents share with AI tools via prompts, uploads, and automated interactions and that could create exposure via an accidental leak. And it enables your security team to detect and respond to new AI-specific threats and misuse, like prompt injection attempts and other malicious instructions designed to manipulate AI systems. 

Whether it’s discovering a malicious tool connected to a Microsoft Copilot agent or an employee misusing AI for inappropriate situations that the tool was not designed for (e.g., internal hiring decisions), you need to respond quickly to address the exposure and reinforce safe use.

5. Analyze AI security risks in the context of other exposures

To mitigate AI security risks, it’s not enough to detect in isolation unpatched vulnerabilities in AI software, weak configurations of AI systems, and overprivileged agents. After all, AI is becoming fully integrated into all of our apps, data, and business processes.

Mitigating AI security risks requires a unified, automated approach to gathering contextually-rich AI security data and correlating and analyzing it alongside other exposure data, such as a publicly exposed S3 bucket, a vulnerable laptop, or an orphaned account with admin privileges. At Tenable, we call this approach exposure management, and we see the industry quickly catching on. Exposure management allows you to proactively see how security weaknesses across your environment combine to create exposure: high-risk attack paths leading to your organization’s most sensitive systems and data. 

Exposure management also surfaces risks with precise context — including the specific AI engine, user, and session — to enable high-fidelity issues management and rapid response. It’s about understanding how toxic combinations of risk coalesce to create business exposure. One medium-criticality misconfiguration in Amazon Bedrock could be connected to an unsecured LLM providing over-provisioned entitlement access for agents. Exposure management requires this complete understanding of the entire environment and attack surface.

Securing the future of AI innovation

The rapid integration of AI across the enterprise has created a complex, interconnected attack surface that traditional security controls are simply not equipped to handle. To close the AI exposure gap, security leaders must shift from a reactive, tool-centric approach to a proactive, unified strategy.

By implementing this five-step framework, you can create a resilient security posture that evolves alongside AI technology. Ultimately, effective exposure management isn't about slowing down innovation; it's about providing the necessary guardrails to ensure your organization can embrace the power of AI safely and confidently.

Robert Huber

Robert Huber

Chief Security Officer, Head of Research and President of Tenable Public Sector

As Tenable’s Chief Security Officer, Head of Research and President of Tenable Public Sector, LLC, Robert Huber oversees the company's global security and research teams, working cross-functionally to reduce risk to the organization, its customers and the broader industry. He has more than 25 years of cyber security experience across the financial, defense, critical infrastructure and technology sectors. Prior to joining Tenable, Robert was a chief security and strategy officer at Eastwind Networks. He was previously co-founder and president of Critical Intelligence, an OT threat intelligence and solutions provider, which cyber threat intelligence leader iSIGHT Partners acquired in 2015. He also served as a member of the Lockheed Martin CIRT, an OT security researcher at Idaho National Laboratory and was a chief security architect for JP Morgan Chase. Robert is a board member and advisor to several security startups and served in the U.S. Air Force and Air National Guard for more than 22 years. Before retiring in 2021, he provided offensive and defensive cyber capabilities supporting the National Security Agency (NSA), United States Cyber Command and state missions.