惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
Microsoft Azure Blog
Microsoft Azure Blog
人人都是产品经理
人人都是产品经理
博客园 - 聂微东
博客园_首页
阮一峰的网络日志
阮一峰的网络日志
V
V2EX
小众软件
小众软件
F
Fortinet All Blogs
Microsoft Security Blog
Microsoft Security Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
H
Hackread – Cybersecurity News, Data Breaches, AI and More
量子位
Google DeepMind News
Google DeepMind News
Jina AI
Jina AI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
aimingoo的专栏
aimingoo的专栏
B
Blog RSS Feed
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
宝玉的分享
宝玉的分享
有赞技术团队
有赞技术团队
J
Java Code Geeks
WordPress大学
WordPress大学
The Cloudflare Blog

ThreatDown by Malwarebytes

This SonicWall bug is 2 years old. Akira ransomware is still exploiting it. | ThreatDown AI threat so great that security “takes precedence over everything except critical business operations”  | ThreatDown How Grok unknowingly powers cybercrime | ThreatDown The guardrails problem just played out on both sides of the same incident | ThreatDown The AI era of cybercrime has arrived: The 2026 Cybercrime in the age of AI report | ThreatDown Prinz Eugen ransomware: a deep dive into a new Go-based encryptor - ThreatDown by Malwarebytes GachiLoader adopts AI skill lure - ThreatDown by Malwarebytes The Attacks Hiding in Your Identity Logs - ThreatDown by Malwarebytes The identity nobody is watching - ThreatDown by Malwarebytes Weaponizing autonomy: The rise of malicious AI agent skills Why identity-based threats are the new battleground for cybersecurity CastleRAT attack first to abuse Deno JavaScript runtime to evade enterprise security 100% malware detection at 1.7% CPU: how ThreatDown stops Mac info stealers Machine-scale cybercrime: The 2026 State of Malware report How to prevent a rootkit attack The anatomy of an Akira ransomware attack AI-orchestrated cyberattacks Tracking remote ransomware attacks at their source Inside EDR-Freeze: How ThreatDown stops the attack before it spreads
74% of organizations exposed to shadow AI | ThreatDown
Luke T. · 2026-08-12 · via ThreatDown by Malwarebytes
Shadow AI

Companies vastly underestimate how much unknown and ungoverned AI is running in their environment, creating an entirely new attack surface.

If you were to guess how many AI tools you need to monitor inside your organization right now, you’d likely be wrong, and not by a small margin. 

Research we conducted before the recent launch of ThreatDown AI Detection & Response (AIDR) revealed that:

74% of organizations were running more AI tools than they expected. 

That’s a systemic miss, not a rounding error.

That matters because of what it could hide. Someone on your team pasted a customer contract into a chatbot last week to save a few minutes. Someone else dropped in a chunk of source code to debug it faster. Neither of them thought twice about it. Both of them moved company data onto infrastructure your security team has never seen, never audited, and can’t control. Once that data gets out, there’s no pulling it back.  

This isn’t one overeager employee. If you’re one of the 74% of organizations already running more AI than you planned for, this same moment, an unreviewed tool, a quick paste, a permission granted without a second thought, is playing out in multiple departments, on multiple tools, right now. Marketing has its favorite tools. Engineering has the latest and greatest. They both make their own separate decisions about what enters and leaves your environment. Neither checks with the other, and nobody is asking legal or security. 

It gets worse. These tools don’t just take input anymore. They act. Many now run as agents: software with standing permissions to read your files, write and run code, and make decisions. They reach out to other systems through protocols like MCP (Model Context Protocol), quietly building a supply chain nobody signed off on and nobody is watching. 

If an attacker hijacks one of those shadow agents with a malicious skill, they inherit its access to everything it was trusted to touch: the files, the credentials, and the open connections into the rest of your environment.

The companies we surveyed expected AI tool sprawl to be the exception, not the rule. Most predicted 5 or fewer tools running in their environments. 

Instead, 30% of organizations found 16 or more tools already active.

How many AI tools organizations think they are running vs reality
How many AI tools organizations think they are running vs the reality

If your organization expected a few tools but is actually running 16 or more, that means most of the AI tools your employees rely on are operating with no oversight as they process company data, execute unreviewed code, or reach out to systems nobody signed off on. 

More AI use than you expect

Tool count wasn’t the only blind spot. Surveyed companies assumed about 33% of their workforce was using AI tools. The actual median: 58%. 

What percentage of the workforce organizations think is using AI vs the reality

More usage means more exposure. Every one of those additional users is another way for company data to leave through a tool your security team doesn’t know it should be watching.

Find out what’s actually running

This is exactly the blind spot AIDR is built to close. It shows you which AI tools are actually in use across your environment, not just the ones on your approved list, so you’re governing shadow AI instead of discovering it after the fact.