LIVE · cybersecurity feed
Live wire
ai

AI deployments are stretching enterprise security to its limits

CISOs and CTOs expect AI deployments to increase their organizations’ attack surface by an average of 14% over the next year. Nearly all lack visibility into AI deployments, and 90% are concerned about employees using unapproved AI tools outside formal oversight, according to NetFoundry’s 2026 State of Secure AI Access survey. Key aspects of AI deployments contributing most to attack surface chang

zeroday.news ·

Enterprise security leaders anticipate a significant expansion of their organizations' attack surfaces, with an average increase of 14% expected over the next year due to the proliferation of AI deployments. A recent survey, NetFoundry's 2026 State of Secure AI Access, indicates that nearly all organizations lack adequate visibility into these AI deployments, and a substantial 90% express concern over employees utilizing unapproved AI tools outside formal oversight channels.

AI-related risks have rapidly ascended to a top concern for security professionals, particularly within the retail, travel, healthcare, pharmaceutical, and technology sectors. Only 15% of survey respondents expressed high confidence that their existing security tools are sufficient to protect AI deployments, with CISOs reporting even lower levels of assurance. This lack of confidence extends to securing AI systems and other machine workloads, which are perceived as less protected than human users.

The past decade's security investments have largely centered on human identity, leaving current tools ill-equipped to manage the unique challenges posed by AI agents, APIs, and machine-to-machine communications. Software vulnerabilities have emerged as a primary vector for cybercriminals to gain initial access, accounting for approximately 31% of breaches. AI is now enabling attackers to identify and exploit these vulnerabilities at an accelerated pace, shrinking the window between vulnerability disclosure and active exploitation from months to mere hours. Concurrently, organizations are taking longer to remediate known exploited vulnerabilities, with the median patching time increasing to 43 days.

The distributed nature of AI applications, which rely on models, APIs, cloud services, data sources, and partner platforms across diverse environments, creates numerous new potential entry points. Internet-facing APIs, distributed workloads, and non-human identities are identified as key drivers of this expanding attack surface. AI agents frequently use static secrets, credentials, and service accounts that often possess excessive permissions, remain active for extended periods, and become increasingly difficult to manage as AI deployments scale.

Security teams are actively seeking improved methods for identifying, authenticating, and monitoring AI agents without relying on long-lived credentials, with most organizations evaluating new approaches to securing non-human identities. CTOs, who are responsible for building and operating AI environments, show greater concern for infrastructure security (60%) compared to CISOs (41%). Over a third of respondents report difficulties in monitoring AI agent activity, with the financial sector expressing the highest level of concern regarding this limited visibility.

The widespread use of "shadow AI"—employees leveraging unapproved AI tools for productivity gains—exacerbates visibility issues. These tools can bypass existing security controls, obscuring AI usage and the data they access. This lack of visibility complicates problem detection, incident investigation, and overall AI system management.

The process of securing AI deployments is also extending implementation timelines. More than half of respondents indicate that network changes, including firewall rule updates and access control modifications, add one to two weeks to AI deployments, with an average delay of eight days. Each new AI model, API, or data connection necessitates security reviews, approvals, and implementation of changes, processes that become more time-consuming as AI environments expand. Risk and compliance reviews, along with cross-team coordination, are identified as significant obstacles to these necessary network modifications. As AI adoption grows and security requirements become more intricate, further increases in deployment timelines are anticipated, alongside stricter oversight and additional security reviews.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.

vulnerability

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Threat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek.

CVE-2026-58231critical

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek.

vulnerability

Police bust cybercrime ring accused of stealing €30 million in four-day spree

German and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria. Brazilian police named the operation “Klonen.” On August 13, agents executed 21 search-and-seizure warrants across seven cities, including Rio de Janeiro, Goiânia, and