惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
美团技术团队
酷 壳 – CoolShell
酷 壳 – CoolShell
Y
Y Combinator Blog
T
Tailwind CSS Blog
D
Docker
博客园 - Franky
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Google DeepMind News
Google DeepMind News
腾讯CDC
Vercel News
Vercel News
Engineering at Meta
Engineering at Meta
U
Unit 42
The Cloudflare Blog
S
SegmentFault 最新的问题
WordPress大学
WordPress大学
爱范儿
爱范儿
Recent Announcements
Recent Announcements
博客园 - 聂微东
博客园 - 叶小钗
H
Help Net Security
MyScale Blog
MyScale Blog

SiliconANGLE

Will agentic AI governance run amok? The lesson of Asimov’s Three Laws - SiliconANGLE AI + quantum, Amazon vs. Starlink and the wide-open US-China internet battle - SiliconANGLE Team Cymru launches Total Insights Feed to replace legacy threat intelligence lists - SiliconANGLE AI Mode in Chrome adds split-screen view to enhance the web search experience - SiliconANGLE Resolve AI raises $40M at $1.5B valuation to optimize production environments - SiliconANGLE How Zscaler and OpenAI turn zero-trust security into an AI accelerator - SiliconANGLE OpenAI ratchets up Codex's agentic capabilities to rival Claude Code - SiliconANGLE Anthropic launches Claude Opus 4.7 with coding, visual reasoning improvements - SiliconANGLE Slash raises $100M at a $1.4B valuation to expand AI-powered banking platform for online businesses - SiliconANGLE Canva unveils Canva AI 2.0, recasting its platform as an agentic system for work - SiliconANGLE Data center, consumer device chips boost TSMC’s revenue - SiliconANGLE Mission-critical security cannot be bolted on, says Oracle - SiliconANGLE Agentic infrastructure reshapes enterprise AI - SiliconANGLE Data quality, and data freedom, foundational for AI success - SiliconANGLE Data trust is a bedrock in successful, scalable AI outcomes - SiliconANGLE Google introduces new agentic AI-ready tools and resources for Android developers  - SiliconANGLE Agentic AI orchestration separates winners from laggards - SiliconANGLE Data-driven tools turning the tide against human trafficking - SiliconANGLE Achieving trusted AI development goes beyond 'vibes' - SiliconANGLE Impinj boosts edge computing power in updated R700 RAIN RFID reader - SiliconANGLE Certinia powers professional services with AI - SiliconANGLE Antioch prepares to accelerate simulated testing for autonomous robots after raising $8.5M - SiliconANGLE Developer tooling startup Expo nabs $45M investment - SiliconANGLE Solidroad lands $25M to bring AI to customer support interactions - SiliconANGLE DuploCloud lands compliance and AI governance certifications as enterprise buyers tighten scrutiny - SiliconANGLE Lua lands $5.8M to help businesses build and manage AI agent workforces - SiliconANGLE Best of frenemies: Oracle's and AWS' clouds unite with dedicated, private connectivity - SiliconANGLE NIST shifts National Vulnerability Database to risk-based triage as CVE submissions hit record levels - SiliconANGLE Cisco goes to the races with new Churchill Downs multiyear partnership - SiliconANGLE Susecon 2026 will tackle the future of open-source platforms - SiliconANGLE
Wiz finds AI has moved from tool to infrastructure, broad...
Duncan Riley · 2026-04-30 · via SiliconANGLE

Wiz finds AI has moved from tool to infrastructure, broadening the attack surface

A new report out today from Google LLC-owned cloud security company Wiz Inc. finds that artificial intelligence has shifted from experimental tooling to default cloud infrastructure, with 81% of observed environments running managed AI services and 90% running self-hosted AI software.

The State of AI in the Cloud 2026 report used anonymized configuration metadata, AI asset discovery and hands-on investigations across hundreds of thousands of cloud environments throughout 2025. Wiz characterized its figures as lower-bound estimates rather than a measure of global adoption.

The headline finding in the report is that AI is no longer a discrete deployment decision. Some 63% of organizations were found to self-host AI models now, but 68% of those ingest models at least partly through third-party software and 18% rely exclusively on such transitive components. The result is an inherited attack surface that organizations did not explicitly choose and may not have inventoried.

Concentration risk was also found to be elevated. The report found that 42% of organizations depend on a single AI model, while fewer than 7% deploy more than 100. Only 21% operate 10 or more managed models.

Developer tooling showed similar saturation, with AI-integrated development environment extensions present in at least 80% of organizations and 71% having at least one AI copilot deployed. Wiz cites GitHub data indicating 80% of new developers adopt AI copilots within their first week, alongside a 25% year-over-year increase in total code pushes. Separate research from LogicStar AI AG and ETH Zürich found AI agents participate in up to 10% of public pull requests.

The intensified scale of usage detailed in the report matters because Wiz Research found in September 2025 that roughly one in five organizations using AI-powered vibe-coding platforms had applications affected by systemic security weaknesses.

The report cites issues at platforms including Base44 Ltd., where shared generation logic produced reproducible flaws allowing unauthorized access to private applications and Moltbook, where insufficient guardrails left sensitive data exposed. When AI-generated defaults replicate at scale, insecure patterns become systemic rather than isolated, the report said.

Orchestration infrastructure was also found to be expanding faster than security practice. At least 57% of organizations were found to have deployed self-hosted AI agent technologies and Model Context Protocol servers appear in at least 80% of cloud environments. Only 5% of environments have at least one MCP server exposed to the internet.

Wiz documents several incidents tied to the new layer.

The Probllama vulnerability, discovered by Wiz in 2024 and tracked as CVE-2024-37032, allowed remote code execution against Ollama instances, thousands of which were identified as publicly accessible. The singularity supply chain attack against the Nx build system abused command-line AI tools, including Anthropic PBC’s Claude, Alphabet Inc.’s Gemini and Amazon.com Inc.’s Amazon Q, to perform reconnaissance and harvest credentials on compromised hosts.

The report notably finds that the economics of exploitation are shifting in step with the changing layer and embrace of AI and agentic AI. Wiz argues AI is functioning as both target and accelerant, compressing exploit development timelines and lowering the skill floor rather than producing entirely new attack classes.

Added to the mix is that adoption of AI now spans regulated sectors including finance, energy and aerospace, meaning the inherited-AI exposure pattern is no longer confined to AI-forward industries.

The report concludes with the recommendation that organizations must treat AI as first-class cloud infrastructure rather than a separate discipline, subjecting AI systems to the same asset inventory, configuration review, identity governance and exposure management applied to any other workload.

Wiz’s researchers argue that governance can no longer sit with a single innovation team. It must be integrated across cloud security, application security and data governance functions to account for distributed ownership and transitive components.

Image: Wiz

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.

About SiliconANGLE Media

SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.