惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hacker News: Front Page
P
Palo Alto Networks Blog
T
ThreatConnect
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
T
True Tiger Recordings
P
Privacy & Cybersecurity Law Blog
B
Blog
IT之家
IT之家
Last Week in AI
Last Week in AI
F
Full Disclosure
Hacker News: Ask HN
Hacker News: Ask HN
C
Comments on: Blog
Microsoft Azure Blog
Microsoft Azure Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
N
News and Events Feed by Topic
NISL@THU
NISL@THU
腾讯CDC
雷峰网
雷峰网
Security Latest
Security Latest
李成银的技术随笔
M
Microsoft Research Blog - Microsoft Research
L
LangChain Blog
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Check Point Blog
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
博客园 - Franky
N
News | PayPal Newsroom
V
V2EX
A
About on SuperTechFans
The Register - Security
The Register - Security
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google Online Security Blog
Google Online Security Blog
MyScale Blog
MyScale Blog
Cisco Talos Blog
Cisco Talos Blog
Vercel News
Vercel News
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
The Hacker News
The Hacker News
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
爱范儿
爱范儿
A
Arctic Wolf
L
LINUX DO - 最新话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Cloud Security Alliance

Agentic AI Threats: Five Powers | CSA AISMM: AI Security Maturity Model for Cloud | CSA Globee® Awards for Artificial Intelligence (AI) Honors Cloud | CSA Patching Smarter for Mythos Security | CSA SDP v3: Identity-First Zero Trust for AI | CSA AI-Ready Security Documents Beyond STIX, OSCAL, and SARIF | CSA AI Agent Posture: Data-First Security Guardrails | CSA AI Agents Go Beyond Output: Enterprise Security | CSA AI Agent Security Starts with Scope Control | CSA Identity Spoofing vs. Identity Abuse AARM: Securing the Agentic Runtime | CSA Securing the Agentic Control Plane | CSA CSAI Foundation Announces Key Milestones to Secure the Agentic | CSA Catastrophic AI Risk Controls | CSA Cloud to AI: Building Secure Programs | CSA Identity in AI Era: Zero Trust's First Pillar | CSA Achieving Complete SDLC Visibility and Security in a Multi-Cloud World Cloud Risk: Top 3 Threats & AI Tools | CSA AI Agent Identity Is Being Solved Backwards - And the Window to Fix It Is Now 8 Dangerous Truths About Excessive Privileges in Cloud and SaaS Platforms AI Governance: Mature Programs | CSA Agent Access Management: Data-First Security | CSA Glasswing: AI-Driven Security for Safer Software | CSA Runtime Security: Detection & Real-Time Cloud | CSA Identity as the OS for AI Security | CSA Cloud Misconfigurations Drive Attacks at Scale | CSA Sensing AI Behavior with the WBSC Probe Library | CSA An Actionable Guide to GDPR Compliance for Startups | CSA Cloud Security LIVE 2026: AI Risk & Trust | CSA Shadow AI Agents: Enterprise Governance | CSA Rethinking Non-Human Identity Security | CSA New Cloud Security Alliance Survey Reveals 82% of Enterprises Have Unknown AI Agents in Their Environments More Than Half of Organizations Experience AI Agent Scope | CSA SANS Institute, Cloud Security Alliance, [un]prompted, and OWASP GenAI Security Project Release Emergency Strategy Briefing as AI-Driven Vulnerability Discovery Compresses Exploit Timelines from Weeks to Hours AI Agents Are Talking: Are You Listening? | CSA Software Supply Chain Security Needs an Upgrade Choosing the Right AI Standard: 7-Point Guide | CSA When AI Agents Serve Shared Workspaces, Authorization Must Follow the Audience A CISO's Guide to Cloud Security Architecture | CSA Who’s Behind That Action? The AI Agent Identity Crisis Standardizing the SaaS Ecosystem: The Case for SSCF Adoption Anthropic’s Mythos is Here: Defending from the Vulnpocalypse AI Security Risks Start with Poor Data Visibility From Compliance to Credibility: How to Turn CCM/CAIQ Work Into Content People Actually Cite The State of Cybersecurity in the Finance Sector: Six Trends to Watch EU AI Act Compliance with prEN 18286 & ISO 42001 | CSA Rethinking Incident Response as Engineering System | CSA Defense Depends on the Creator: AI Security | CSA Every RSAC Keynote Asked the Same Five Questions. Here's the Framework That Answers Them. Cybersecurity Needs a New Data Architecture CSA STAR v4.1 Explained: Key Updates for Cloud Security and Assurance Unstructured Data Surges as Enterprises Struggle to Maintain Visibility and Security, Cloud Security Alliance Study Finds SC Media Names Cloud Security Alliance’s Trusted AI Safety Expert (TAISE) Certificate a Winner of the 2026 SC Awards How an Exposed AWS Access Key Can Lead to Full Account Takeover Post-Quantum Cryptographic Migration for Cloud-Native Zero-Trust Architectures: What CSA Members Need to Deploy Now AI Identity Security Compliance Checklist The Agentic Trust Deficit: Why MCP's Authentication Vacuum Demands a New Security Paradigm More Than Two-Thirds of Organizations Cannot Clearly Distinguish AI Agent from Human Actions as Over-Privileged Access Becomes Widespread, Cloud Security Alliance Study Finds The State of AI Cybersecurity 2026: Unveiling Insights from Over 1,500 Security Leaders The Three-Body Problem of Data, AI, and Identity: Why the Future of Security Depends on All Three AI Security: When Agents Control Physical Systems, IAM Becomes Safety Infrastructure When Saving on Kubernetes Costs Creates Security Debt: The FinOps Guardrails Most Teams Miss Code-to-Cloud Security: Embracing a Unified, Ecosystem-Wide View of Cyber Risk 5 Retail Misconfigurations Attackers Exploit First Rethinking Authorization for the Age of Agentic AI From Guardrails to Governance: Why Enterprise AI Needs a Control Layer
AI Security in the Cloud: Exposure Management | CSA
2026-04-01 · via Cloud Security Alliance

Originally published by Tenable.

Written by Thomas Nuth, Head of Product Marketing - Cloud, Tenable.

TL; DR

Unify AI and cloud exposures into a clear and manageable security view — before your board asks why your organization is moving so fast without AI and cloud security guardrails.

Key takeaways

  • Protect business value by prioritizing attack paths over vulnerability lists.
  • Use governance frameworks as guardrails that enable AI and cloud adoption.
  • Consolidate your cybersecurity tool stack to eliminate blind spots between siloed security tools and teams.

Manual security reviews fuel shadow AI and employee workarounds

If you’re in security, watching your organization deploy AI and cloud resources at breakneck speed can feel like trying to inspect every car on a highway from a single, manual toll booth.

If you try to stop every new AI or cloud project for a prolonged security and compliance review, employees will find unique ways to bypass your cloud security and AI acceptable use policies (AI AUP). A developer might use a personal API key to finish a sprint. Or a marketer might feed sensitive data into an unvetted browser extension to meet a deadline. These shadow AI workflows leave your security teams blind to where your data goes.

When teams go around your controls, they leave behind a trail of misconfigurations, unpatched vulnerabilities, and service accounts with excessive permissions. Those shortcuts quickly add up.

According to the State of Cloud and AI Security Report 2025, 59% of professionals said insecure identities and risky permissions are the single greatest threat to their cloud infrastructure, and 34% with AI workloads have already experienced an AI-related breach. That same report also found that 53% of organizations have given external accounts the ability to assume critical severity, excessive permissions.

Since AI is effectively the most data-hungry workload in your cloud, these gaps become building blocks of an attack path that leads straight to your AI models and your most sensitive data.

The current strategy of layering more specialized tools to regain control has left the typical large-scale enterprise with 70 or more security vendors, which creates exposures adversaries exploit. They can move across silos, from a misconfigured cloud identity to sensitive AI data.

Understanding your AI exposure gap

Many organizations have an invisible attack surface of unsanctioned large language models (LLMs) and unvetted AI agents. The risk is in your internal AI development lifecycle, and the shadow AI and data buckets in your cloud that siloed security tools don’t know exist.

One study says that 3% of organizations expose AI-related API keys (like OpenAI and Anthropic) within cloud data resources, while 18% have overprivileged identity and access management (IAM) roles that AWS AI services can instantly assume. These exposures are a silent, wide-open backdoor for data exfiltration.

The solution is an AI exposure management strategy that treats AI tools and the cloud infrastructure they run on as a single, interconnected stack. Managing automated agents or AI model training separate from cloud security is a mistake that could end in an incident report you can’t defend.

The high-velocity cloud risk gap

Think of your cloud environment like a high-performance car you’re actively building while it’s speeding down a highway.

Most security tools are like a dashboard full of blinking lights. Individually, they tell you one problem at a time, but they don’t have context. You know you have alerts, but you can’t see they’re connected. Eventually, your engine will fail and cost you a lot of time and money.

It’s the same with AI security in the cloud. You don’t need more data. You need telemetry that connects the dots. Finding those toxic combinations, like a known vulnerability on a public-facing web server that shares a service account with an AI data lake, is what prevents an oversight from becoming a critical cyber incident.

Effective cloud exposure management helps your teams see these high-risk pathways. You can protect your cloud infrastructure and AI data by locking down your identity perimeter and stripping away those excessive entitlements. It’s more than routine maintenance. It’s how you keep the company car on the road without becoming the one who has to tell the board about the massive financial loss from an accident no one saw coming.

The power of a unified exposure management platform

In the context of AI security in the cloud, a fragmented view is a liability. That’s because you can’t secure an AI data lake using the same siloed logic used for legacy databases.

For example, you’ve probably sat through multiple consecutive status meetings where three different teams (IT, cloud security, and OT security) present three versions of the same risk. Fragmented reporting happens when IT, security, and compliance teams work in domain-specific silos that don’t talk to each other.

But attackers don’t care about organizational silos. They exploit the friction between them to move from a compromised cloud app to your AI data lake. By integrating AI and cloud security, you can find these attack chains before threat actors and reduce the time to contain a breach.

Defensibility matters

You can’t stop your organization from rapidly adopting LLMs, automated agents, or more cloud containers and workloads. What you can do is not be the one who has to write the incident report when a siloed tool doesn’t find shadow AI or a cloud service an employee spun up to bypass your manual review.

According to the IBM Cost of A Data Breach Report 2025, organizations using AI and automation extensively for security saved about $1.9 million in breach costs and reduced the breach lifecycle by about 80 days.

Your goal this year is to stop collecting disjointed security tools that only create more noise while your organization speeds past you. When you unify your AI cloud security and infrastructure governance, you can build a security guardrail that maintains AI and cloud speed without ending up in a 2 a.m. breach crisis meeting.

AI-powered exposure management is the only way to keep your eyes on the road and ensure your entire organization sees security as a competitive advantage, not a roadblock.

How can my organization manage AI and cloud security without slowing down business?

Start by acknowledging your organization is already AI and the cloud. Trying to block every LLM or cloud instance is a losing game that encourages shadow IT. Instead, implement an AI in cloud security governance framework with visibility into how data moves into these models and across the cloud. If you can show your organization that you have guardrails in place, you become a partner in the rollout instead of a bottleneck.

Why is identity the new perimeter in cloud security?

Most breaches start with an over-privileged service account or a leaked key. If an attacker gets access to an identity with excessive entitlements, they can move laterally across your environment, regardless of your firewall settings. Focusing on exposure management helps you find and kill exposures and their attack paths.

Can one exposure management platform replace dozens of specialized security tools?

Yes. The best exposure management platform enables tool and data consolidation to close the gaps that naturally form between disconnected security products. When your vulnerability data, cloud configuration, AI security, and identity permissions are in one place, like within an exposure assessment platform (EAP), you get a clear view of your most critical exposures.

Thomas Nuth is a seasoned cybersecurity executive with over 15 years of experience driving global go-to-market strategy, brand development, and market adoption for some of the world’s most innovative security companies. With a deep understanding of the evolving threat landscape—from cloud-native risk to AI-powered attacks—Thomas has played a pivotal role in shaping industry narratives and positioning next-gen technologies at the forefront of the cybersecurity conversation. Before joining Tenable, Thomas held positions at Wiz, Qualys, Fortinet, Forescout, and other innovative leaders in cybersecurity.