惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
SecWiki News
SecWiki News
爱范儿
爱范儿
Jina AI
Jina AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Apple Machine Learning Research
Apple Machine Learning Research
Vercel News
Vercel News
S
SegmentFault 最新的问题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
GbyAI
GbyAI
V
V2EX
博客园 - 司徒正美
WordPress大学
WordPress大学
Y
Y Combinator Blog
B
Blog RSS Feed
H
Help Net Security
C
Check Point Blog
P
Proofpoint News Feed
Google DeepMind News
Google DeepMind News
Application and Cybersecurity Blog
Application and Cybersecurity Blog
B
Blog
Help Net Security
Help Net Security
罗磊的独立博客
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
H
Heimdal Security Blog
大猫的无限游戏
大猫的无限游戏
Security Latest
Security Latest
Cisco Talos Blog
Cisco Talos Blog
Blog — PlanetScale
Blog — PlanetScale
A
Arctic Wolf
T
The Blog of Author Tim Ferriss
P
Proofpoint News Feed
The Register - Security
The Register - Security
F
Fortinet All Blogs
S
Securelist
Microsoft Security Blog
Microsoft Security Blog
O
OpenAI News
P
Privacy & Cybersecurity Law Blog
C
Cybersecurity and Infrastructure Security Agency CISA
The GitHub Blog
The GitHub Blog
云风的 BLOG
云风的 BLOG
AWS News Blog
AWS News Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
I
InfoQ
T
Threat Research - Cisco Blogs
Martin Fowler
Martin Fowler
D
Docker
C
Cisco Blogs
C
CERT Recently Published Vulnerability Notes
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events

Cloud Security Alliance

SearchLeak: Copilot Data Exfiltration Exploited | CSA Zero-Trust AI Governance for Multi-Agent Systems | CSA Dangling CNAMEs: Hidden Cloud Risk | CSA Agentic Payments in Financial Services | CSA Mythos and the Future of Cybersecurity | CSA AI-Driven Cloud Risk: Defenders Lose Ground | CSA Financial Services Industry Shifts from AI Adoption to | CSA CSAI Foundation Announces RiskRubric V2 as the Next Key | CSA RiskRubric Updates: AI Risk Assessment | CSA Over 80% of Organizations that Miss 24-Hour Patch Window Report | CSA ORCHIDEAS & MAESTRO: Secure AI Design | CSA Top 6 Claude Security Risks to Watch | CSA Cloud Cost Optimization in 2026 | CSA HIPAA Rule Overhaul in 2026 | CSA AI-Driven Exploits Outsmart Detection | CSA MCP Risks CISOs Should Prepare For | CSA AI Governance for Trust and Compliance | CSA MTTP: Patch Cycles Too Slow | CSA Cloud Security Evolution: Security Teams Lead | CSA Misconfigurations Break Customer Trust in Apps | CSA Taming Shadow AI: C-Suite Strategies | CSA Agentic AI Threats: Five Powers | CSA AIUC-1: Agentic AI Governance | CSA 2026 Threat Report for CISOs | CSA Securing AI in AWS: Runtime Detection & Response | CSA SLMs, LLMs, and the DSPM Difference | CSA OT Security Timeline: Mythos and Patch Pace | CSA Blast Radius and Cloud Threat Detection | CSA State of AI Cybersecurity 2026: 92% Concerned | CSA AI in MDR for Franchise & Multi-Location Ops | CSA AI Regulation: Identity and Authorization Gap | CSA MITRE ATT&CK for Cloud: Detection Coverage Guide | CSA Shadow AI Agents: The Insider Threat | CSA Medical Device Breaches Reveal Cloud Security Gaps | CSA AISMM: AI Security Maturity Model for Cloud | CSA Globee® Awards for Artificial Intelligence (AI) Honors Cloud | CSA Patching Smarter for Mythos Security | CSA SDP v3: Identity-First Zero Trust for AI | CSA AI-Ready Security Documents Beyond STIX, OSCAL, and SARIF | CSA Penetration Testing for ISO 42001 & Trust | CSA AI Agent Posture: Data-First Security Guardrails | CSA AI Agents Go Beyond Output: Enterprise Security | CSA AI Agent Security Starts with Scope Control | CSA Identity Spoofing vs. Identity Abuse | CSA AARM: Securing the Agentic Runtime | CSA Securing the Agentic Control Plane | CSA CSAI Foundation Announces Key Milestones to Secure the Agentic | CSA Catastrophic AI Risk Controls | CSA Cloud to AI: Building Secure Programs | CSA Identity in AI Era: Zero Trust's First Pillar | CSA SDLC Visibility: Securing Multi-Cloud Development Lifecycles | CSA Cloud Risk: Top 3 Threats & AI Tools | CSA AI Agent Identity Is Solved Backwards | CSA 8 Truths About Cloud Privilege Risk | CSA AI Governance: Mature Programs | CSA Agent Access Management: Data-First Security | CSA Glasswing: AI-Driven Security for Safer Software | CSA Runtime Security: Detection & Real-Time Cloud | CSA Identity as the OS for AI Security | CSA Cloud Misconfigurations Drive Attacks at Scale | CSA Sensing AI Behavior with the WBSC Probe Library | CSA An Actionable Guide to GDPR Compliance for Startups | CSA Cloud Security LIVE 2026: AI Risk & Trust | CSA Shadow AI Agents: Enterprise Governance | CSA Rethinking Non-Human Identity Security | CSA New Cloud Security Alliance Survey Reveals 82% of Enterprises Have Unknown AI Agents in Their Environments More Than Half of Organizations Experience AI Agent Scope | CSA SANS Institute, Cloud Security Alliance, [un]prompted, and OWASP | CSA AI Agents Are Talking: Are You Listening? | CSA Software Supply Chain Security Needs an Upgrade Choosing the Right AI Standard: 7-Point Guide | CSA Audience-Driven Authorization for AI Agents | CSA A CISO's Guide to Cloud Security Architecture | CSA Who’s Behind That Action? The AI Agent Identity Crisis SSCF Adoption for SaaS Security | CSA Mythos and the Vulnpocalypse: Cloud Defenses | CSA AI Security Risks and Data Visibility | CSA From Compliance to Credibility with CAIQ/CCM | CSA The State of Cybersecurity in the Finance Sector: Six Trends to Watch EU AI Act Compliance with prEN 18286 & ISO 42001 | CSA Rethinking Incident Response as Engineering System | CSA Defense Depends on the Creator: AI Security | CSA ATF: Zero Trust for AI Agents | CSA Cybersecurity Needs a New Data Architecture | CSA CSA STAR v4.1 Updates for Cloud Security | CSA Unstructured Data Surges as Enterprises Struggle to Maintain | CSA SC Media Names Cloud Security Alliance’s Trusted AI Safety | CSA Exposed AWS Key Leads to Full Account Takeover | CSA Post-Quantum Cloud Migration for CSA Members | CSA AI Identity Security Compliance Checklist | CSA The Agentic Trust Deficit: MCP's Authentication Vacuum | CSA More Than Two-Thirds of Organizations Cannot Clearly Distinguish | CSA AI Cybersecurity 2026: Insights from 1,500 Leaders | CSA Three-Body Security: Data, AI & Identity | CSA IAM as Safety for AI-Controlled Systems | CSA Kubernetes Cost Savings and Security Debt | CSA Code to Cloud Security: Unified Exposure Management | CSA Retail Misconfigurations Attackers Exploit | CSA Rethinking Authorization for the Age of Agentic AI | CSA Enterprise AI: Guardrails to Governance | CSA
AI Security in the Cloud: Exposure Management | CSA
2026-04-01 · via Cloud Security Alliance

Originally published by Tenable.

Written by Thomas Nuth, Head of Product Marketing - Cloud, Tenable.

TL; DR

Unify AI and cloud exposures into a clear and manageable security view — before your board asks why your organization is moving so fast without AI and cloud security guardrails.

Key takeaways

  • Protect business value by prioritizing attack paths over vulnerability lists.
  • Use governance frameworks as guardrails that enable AI and cloud adoption.
  • Consolidate your cybersecurity tool stack to eliminate blind spots between siloed security tools and teams.

Manual security reviews fuel shadow AI and employee workarounds

If you’re in security, watching your organization deploy AI and cloud resources at breakneck speed can feel like trying to inspect every car on a highway from a single, manual toll booth.

If you try to stop every new AI or cloud project for a prolonged security and compliance review, employees will find unique ways to bypass your cloud security and AI acceptable use policies (AI AUP). A developer might use a personal API key to finish a sprint. Or a marketer might feed sensitive data into an unvetted browser extension to meet a deadline. These shadow AI workflows leave your security teams blind to where your data goes.

When teams go around your controls, they leave behind a trail of misconfigurations, unpatched vulnerabilities, and service accounts with excessive permissions. Those shortcuts quickly add up.

According to the State of Cloud and AI Security Report 2025, 59% of professionals said insecure identities and risky permissions are the single greatest threat to their cloud infrastructure, and 34% with AI workloads have already experienced an AI-related breach. That same report also found that 53% of organizations have given external accounts the ability to assume critical severity, excessive permissions.

Since AI is effectively the most data-hungry workload in your cloud, these gaps become building blocks of an attack path that leads straight to your AI models and your most sensitive data.

The current strategy of layering more specialized tools to regain control has left the typical large-scale enterprise with 70 or more security vendors, which creates exposures adversaries exploit. They can move across silos, from a misconfigured cloud identity to sensitive AI data.

Understanding your AI exposure gap

Many organizations have an invisible attack surface of unsanctioned large language models (LLMs) and unvetted AI agents. The risk is in your internal AI development lifecycle, and the shadow AI and data buckets in your cloud that siloed security tools don’t know exist.

One study says that 3% of organizations expose AI-related API keys (like OpenAI and Anthropic) within cloud data resources, while 18% have overprivileged identity and access management (IAM) roles that AWS AI services can instantly assume. These exposures are a silent, wide-open backdoor for data exfiltration.

The solution is an AI exposure management strategy that treats AI tools and the cloud infrastructure they run on as a single, interconnected stack. Managing automated agents or AI model training separate from cloud security is a mistake that could end in an incident report you can’t defend.

The high-velocity cloud risk gap

Think of your cloud environment like a high-performance car you’re actively building while it’s speeding down a highway.

Most security tools are like a dashboard full of blinking lights. Individually, they tell you one problem at a time, but they don’t have context. You know you have alerts, but you can’t see they’re connected. Eventually, your engine will fail and cost you a lot of time and money.

It’s the same with AI security in the cloud. You don’t need more data. You need telemetry that connects the dots. Finding those toxic combinations, like a known vulnerability on a public-facing web server that shares a service account with an AI data lake, is what prevents an oversight from becoming a critical cyber incident.

Effective cloud exposure management helps your teams see these high-risk pathways. You can protect your cloud infrastructure and AI data by locking down your identity perimeter and stripping away those excessive entitlements. It’s more than routine maintenance. It’s how you keep the company car on the road without becoming the one who has to tell the board about the massive financial loss from an accident no one saw coming.

The power of a unified exposure management platform

In the context of AI security in the cloud, a fragmented view is a liability. That’s because you can’t secure an AI data lake using the same siloed logic used for legacy databases.

For example, you’ve probably sat through multiple consecutive status meetings where three different teams (IT, cloud security, and OT security) present three versions of the same risk. Fragmented reporting happens when IT, security, and compliance teams work in domain-specific silos that don’t talk to each other.

But attackers don’t care about organizational silos. They exploit the friction between them to move from a compromised cloud app to your AI data lake. By integrating AI and cloud security, you can find these attack chains before threat actors and reduce the time to contain a breach.

Defensibility matters

You can’t stop your organization from rapidly adopting LLMs, automated agents, or more cloud containers and workloads. What you can do is not be the one who has to write the incident report when a siloed tool doesn’t find shadow AI or a cloud service an employee spun up to bypass your manual review.

According to the IBM Cost of A Data Breach Report 2025, organizations using AI and automation extensively for security saved about $1.9 million in breach costs and reduced the breach lifecycle by about 80 days.

Your goal this year is to stop collecting disjointed security tools that only create more noise while your organization speeds past you. When you unify your AI cloud security and infrastructure governance, you can build a security guardrail that maintains AI and cloud speed without ending up in a 2 a.m. breach crisis meeting.

AI-powered exposure management is the only way to keep your eyes on the road and ensure your entire organization sees security as a competitive advantage, not a roadblock.

How can my organization manage AI and cloud security without slowing down business?

Start by acknowledging your organization is already AI and the cloud. Trying to block every LLM or cloud instance is a losing game that encourages shadow IT. Instead, implement an AI in cloud security governance framework with visibility into how data moves into these models and across the cloud. If you can show your organization that you have guardrails in place, you become a partner in the rollout instead of a bottleneck.

Why is identity the new perimeter in cloud security?

Most breaches start with an over-privileged service account or a leaked key. If an attacker gets access to an identity with excessive entitlements, they can move laterally across your environment, regardless of your firewall settings. Focusing on exposure management helps you find and kill exposures and their attack paths.

Can one exposure management platform replace dozens of specialized security tools?

Yes. The best exposure management platform enables tool and data consolidation to close the gaps that naturally form between disconnected security products. When your vulnerability data, cloud configuration, AI security, and identity permissions are in one place, like within an exposure assessment platform (EAP), you get a clear view of your most critical exposures.

Thomas Nuth is a seasoned cybersecurity executive with over 15 years of experience driving global go-to-market strategy, brand development, and market adoption for some of the world’s most innovative security companies. With a deep understanding of the evolving threat landscape—from cloud-native risk to AI-powered attacks—Thomas has played a pivotal role in shaping industry narratives and positioning next-gen technologies at the forefront of the cybersecurity conversation. Before joining Tenable, Thomas held positions at Wiz, Qualys, Fortinet, Forescout, and other innovative leaders in cybersecurity.