惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
D
DataBreaches.Net
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
The GitHub Blog
The GitHub Blog
Blog — PlanetScale
Blog — PlanetScale
Microsoft Security Blog
Microsoft Security Blog
A
About on SuperTechFans
Vercel News
Vercel News
L
LangChain Blog
B
Blog RSS Feed
Y
Y Combinator Blog
IT之家
IT之家
H
Hackread – Cybersecurity News, Data Breaches, AI and More
GbyAI
GbyAI
V
V2EX
博客园 - 三生石上(FineUI控件)
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
阮一峰的网络日志
阮一峰的网络日志
有赞技术团队
有赞技术团队
D
Docker
V
Visual Studio Blog
aimingoo的专栏
aimingoo的专栏
Last Week in AI
Last Week in AI
月光博客
月光博客

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Key Takeaways from the 2025 State of AI in the Cloud Report
Amitai Cohen, Dan Segev · 2025-03-07 · via Wiz Blog | RSS feed

AI adoption continues to surge across cloud environments, driving innovation but also introducing new security challenges. In our second annual State of AI in the Cloud report, the Wiz Research team analyzed aggregated data from over 150,000 cloud accounts to explore the evolving AI landscape. This year’s findings highlight the rapid growth of self-hosted AI models, the rise of DeepSeek, and the persistent need for stronger security measures. Here’s what you need to know: 

AI Adoption Remains Strong, with Self-Hosted Models on the Rise 

Organizations continue to embrace AI in their cloud environments, with 74% now using managed AI services—up from 70% last year – and 85% hosting some sort of AI tech. However, the real shift is happening in self-hosted AI models, where adoption has skyrocketed from 42% to 75% over the past year. That surge is driven in large part by third-party models, a fact that also carries risk implications. Companies are increasingly looking to customize AI implementations while maintaining control over their data and infrastructure. 

DeepSeek’s Explosive Growth and the Risks of Rapid Innovation 

One of the most striking developments in this year’s report is the meteoric rise of DeepSeek. Adoption of its models tripled in under two weeks following the release of DeepSeek-R1, with 7% of organizations now using its self-hosted AI models. DeepSeek’s rapid ascent highlights the industry’s appetite for cost-effective, innovative AI solutions. However, a major security incident discovered by Wiz—where an exposed DeepSeek database leaked sensitive information—serves as a stark reminder that security must evolve alongside innovation. Additionally, use of the Chinese company's products has been banned in several countries and organizations due to national security concerns.  

OpenAI Still Leads, But Open-Source AI Gains Traction 

OpenAI remains the most widely used AI provider, with 63% of cloud environments leveraging OpenAI or Azure OpenAI SDKs, up from 53% last year. However, open-source AI continues to play a pivotal role, with 8 of the 10 most popular hosted AI technologies linked to open-source projects. The blend of open- and closed-source AI tools reflects a growing trend toward flexibility and vendor diversity in AI deployments. 

Critical AI Security Vulnerabilities Persist 

As AI adoption accelerates, security challenges continue to mount. Over the past year, the Wiz Research team has uncovered multiple high-risk vulnerabilities, including: 

  • DeepLeak – An exposed DeepSeek database leaking sensitive chat history and log streams. 

  • CVE-2024-0132 – A critical NVIDIA AI vulnerability affecting over 35% of cloud environments. 

  • SAPwned – A flaw in SAP AI Core that could allow attackers to take over services and access customer data. 

  • Probllama – A remote code execution vulnerability in the open-source AI infrastructure project Ollama. 

  • AI PaaS vulnerabilities – Flaws in services provided by Hugging Face, Replicate, and SAP could have allowed attackers to access customer data. 

The Path Forward 

AI is revolutionary technology, but its widespread adoption raises necessary questions about governance, security, and risk. The DeepSeek data exposure incident underscores the urgency of strengthening AI security, starting with visibility into AI deployments to manage risks like Shadow AI, and establishing controls to prevent data exposure and unauthorized use. 

Wiz’s AI Security Posture Management (AI-SPM) solution helps teams gain full visibility into AI adoption, mitigate risks, and enable secure innovation. As AI continues to reshape the cloud landscape, proactive security measures will be critical to harnessing its full potential safely. 

Want to dive deeper? Read the full State of AI in the Cloud 2025 report to explore the data and insights shaping the future of AI security.