惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hacker News: Front Page
P
Palo Alto Networks Blog
T
ThreatConnect
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
T
True Tiger Recordings
P
Privacy & Cybersecurity Law Blog
B
Blog
IT之家
IT之家
Last Week in AI
Last Week in AI
F
Full Disclosure
Hacker News: Ask HN
Hacker News: Ask HN
C
Comments on: Blog
Microsoft Azure Blog
Microsoft Azure Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
N
News and Events Feed by Topic
NISL@THU
NISL@THU
腾讯CDC
雷峰网
雷峰网
Security Latest
Security Latest
李成银的技术随笔
M
Microsoft Research Blog - Microsoft Research
L
LangChain Blog
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Check Point Blog
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
博客园 - Franky
N
News | PayPal Newsroom
V
V2EX
A
About on SuperTechFans
The Register - Security
The Register - Security
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google Online Security Blog
Google Online Security Blog
MyScale Blog
MyScale Blog
Cisco Talos Blog
Cisco Talos Blog
Vercel News
Vercel News
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
The Hacker News
The Hacker News
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
爱范儿
爱范儿
A
Arctic Wolf
L
LINUX DO - 最新话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

NETSCOUT

The 1 A.M. Cloud Migration Meltdown Communication Service Provider Supports Banking Application Success Across International Borders Defending Against DDoS Attacks at Scale AI-Driven Workflow Automation Is the New North Star for Communication Service Providers Key Takeaways from the EMA Network Management Megatrends 2026 The Digital Foundation of Public Trust Is More Than Skin Deep Unlocking the Full Value of 5G with Network Slicing NETSCOUT to Have a Strong Presence at Cisco Live Why Airlines and Airports Must Embrace Observability Ahead of the Summer Travel Surge Beyond “Best Effort”: Why Carrier Grade 5G Slicing Matters More Than Ever The Shrinking Lifespan of SSL/TLS Certificates From Packets to Insight: How Curated Network Data Powers AI Data Centers Are Feeling the Heat, and That’s OK If You Can’t See the Slice, You Can’t Sell the SLA Insights from the GigaOm Radar for Network Observability v6 Report NETSCOUT Earns Eight Leader Badges in the G2 Spring 2026 Grid Reports Your Modern Manufacturing Network Deserves a Modern Observability Strategy How Botnet-Driven DDoS Attacks Evolved in 2H 2025 The Hidden Cost of Poor Network Observability Insurance Systems Look Simple, but the Infrastructure Isn’t How AI is Transforming the RAN With the Right Data When Cloud SaaS DDoS Mitigation Offerings Aren’t Enough Frictionless Banking Experiences Start with Observability Colocation Growth Demands Scalable End-to-End Observability Bringing Shadow AI Into the Light AIOps Outcomes Depend on Data Quality, Not Algorithms Why AI, Zero Trust, and Modern Security Require Deep Visibility How Service Behavior Changes in Remote Locations The 10-Hour Problem: How Visibility Gaps Are Burning Out the SOC From Insight to Impact: Observability Fuels AI-Driven Innovation How Orphaned Applications Are Quietly Fueling Your Shadow IT Problem Why Today’s Security Tools Can’t See the Network Anymore How NETSCOUT Addresses Modern Network Observability Challenges Helping IT Organizations Prevent Disruptions Before They Impact Business How Hidden Blind Spots Quietly Became Cybersecurity’s Biggest Vulnerability The Blame Game! Is it the Network or Gaps in Observability? Six Winter 2026 G2 Leader Badges Prove This DDoS Protection Stands Out The Value of Combining Modern Observability Solutions for Actionable Insights AI Failure Is the Norm Because Most Initiatives Are Flying Blind NETSCOUT Distinguished by Frost & Sullivan with the 2025 Company of the Year Recognition 5 Emerging AI Data Trends Enterprise IT Teams Cannot Ignore What is Network Slicing NETSCOUT’s Omnis Cyber Intelligence Earns Security Today’s 2025 CyberSecured Award Turning a Flood of 5G Data into Rocket Fuel for AIOps NETSCOUT Recognized by Comparably as a Top Workplace for Q4 2025 How to deliver consistent ultra-low latency, high-throughput, and total reliability across complex networks Smart Data: The Super Fuel Driving Next-Gen Observability NETSCOUT Recognized for Leadership in Network Detection and Response Integrating Deep Packet Inspection in 5G Networks Removing Barriers to Digital Transformation Gain Real-time Visibility to Future Proof Your Network for Autonomous Operations Why Is Cloud Performance Still Foggy? Smarter DDoS Security at Scale How DPI Is Transforming Observability and Operational Resilience 10 Key Challenges to Optimizing Radio Access Networks in the 5G Era Why Arbor Edge Defense and CDN-Based DDoS Protection Are Better Together NETSCOUT’s Holiday Playlist for IT Teams and Leaders More Data Does Not Always Equate to Better Business Visibility Seeing Clearly with Deep Packet Inspection at Scale How to Ensure High Availability for FWA Services System Integrators and the Future of Enterprise IT The Transformative Power of ‘Thinking’ AI and the Implications for Business How Fast Can Your Organization Identify and Resolve IT Outages? Observability for the “Always On” Power Industry
How Shadow AI Creates Zombie Infrastructure
2026-04-02 · via NETSCOUT

Modern information technology (IT) environments move too fast for static inventories to keep up. Unauthorized apps and devices, unmonitored generative artificial intelligence (GenAI) tools, and temporary cloud resources appear faster than they can be documented, often before systems are fully deployed.

These resources remain connected, quietly consuming compute. Forgotten and neglected over time, they become zombie infrastructure: systems still running with no clear owner. In modern environments, these are often called zombie servers, zombie APIs, or orphaned resources. Many originate from abandoned AI workloads.

Gartner predicts that by 2030, 40% of enterprises will experience security or compliance incidents related to “shadow AI” as employees adopt AI tools outside approved oversight. 

In fact, some recent surveys suggest that as many as 90% of enterprise AI systems could be breached within 90 minutes.

The most dangerous system is often the one no one knows exists.

A data scientist may allocate GPUs for model training, or a developer may spin up a temporary service during a migration to bypass slow procurement. These shortcuts may solve problems now but create new ones when they bypass standard asset tracking, landing in personal cloud accounts or sandboxes that never make it into official inventories or workflows.

A widely cited example of shadow AI from the semiconductor industry involved engineers entering proprietary source code and internal meeting notes into ChatGPT while debugging software. Incidents like this show how easily tools adopted outside normal governance can expose sensitive data and create liabilities that may affect revenue, reputation, and compliance.

Industry coverage of AI typically focuses on model safety and output quality, emphasizing what AI might do in the future. It often overlooks the digital clutter that AI experimentation leaves behind in the data center and the observability and security gaps that allow these systems to remain unnoticed.

Agentic AI makes this harder. Autonomous agents interact with other services through API calls, and frameworks such as Model Context Protocol (MCP) allow them to connect dynamically with enterprise systems. When the projects supporting these agents are abandoned, the agents don't stop; they keep running in the background. Researchers are already warning about "Shadow MCP," where unapproved MCP servers allow AI agents to maintain connections to internal tools or sensitive data outside normal governance.

Why Zombie Infrastructure Is Hard to Detect

A S&P Global survey found that organizations abandoned 46 percent of AI proof-of-concepts before they reached production. Traditional monitoring often depends on knowing a system exists before it can be tracked. Asset databases assume infrastructure follows official channels. Shadow systems break that. They're routinely excluded from performance, health, observability pipelines, and security checks, and carry real consequences:

  • Systems outside the inventory get missed during patching cycles, leaving them exposed to known exploits and zero-day threats. This isn't a theoretical risk. Unpatched systems are among the most common entry points for lateral movement across the network in enterprise breach investigations.
  • Service performance issues become much harder to diagnose when undocumented systems are influencing application behavior, increasing mean time to knowledge (MTTK) and limiting the effectiveness of artificial intelligence for IT operations (AIOps) systems.
  • Idle cloud and GPU resources quietly inflate infrastructure costs, burning through budgets set aside for legitimate AI work.
  • Undocumented systems storing or processing sensitive data can cause serious problems in General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act (HIPAA), or Service Organization Control 2 (SOC 2) audits, and "we didn't know it existed" is not a defense that regulators accept.

AI coding tools now “catch and patch” many flaws before deployment. That improves code quality, but the operational risk sits downstream. Perfectly patched code running on zombie infrastructure, or inside an undocumented agentic workflow, still represents operational blind spots for IT teams. The code is clean, but the infrastructure it lives on is invisible.

What the Network Shows

Infrastructure inventories describe what should exist; network activity reveals what actually exists. Every service and system communicates. Even forgotten resources continue generating traffic and interacting with other services.

Traffic-derived telemetry surfaces systems that traditional monitoring missed. Unknown hosts and persistent connections regularly expose technology operating outside documented inventories. As architectures become more distributed, analyzing network traffic in real time is the most reliable way to restore visibility and understand how services are actually behaving.

The advantage of network traffic as a discovery mechanism is that it requires nothing from the systems being discovered. Agent-based monitoring only sees what it's been installed on. Log aggregation only captures what's been configured to ship logs. But packets traverse the network regardless. A system doesn't need to be documented, enrolled, or even known to generate traffic that can be observed and analyzed. That passive quality is what makes it reliable precisely in the scenarios where everything else fails.

Closing the Gaps with NETSCOUT

Shadow IT and shadow AI allow resources to emerge faster than they can be tracked, leaving forgotten systems and APIs to create serious observability and security gaps. NETSCOUT's proprietary deep packet inspection (DPI) technology turns real-time network traffic into Smart Data, surfacing unknown systems and service dependencies that never made it into official inventories.

Download NETSCOUT’s shadow IT and shadow AI infographic to see how hidden systems and unauthorized AI tools create observability and security gaps across modern IT environments