Tenable Research Reveals Popular AI Tools Used in Cloud Environments are Highly Vulnerable
Summary
• AI training data is susceptible to data poisoning, threatening to skew model results: 14% of organizations using Amazon Bedrock do not explicitly block public access to at least one AI training bucket and 5% have at least one overly permissive bucket. • Amazon SageMaker notebook instances grant root access by default: As a result, 91% of Amazon SageMaker users have at least one notebook that, if compromised, could grant unauthorized access, which could result in the potential modification of all files on it. If a threat actor manipulates the data or AI model, there can be catastrophic long-term consequences, such as compromised data integrity, compromised security of critical systems and degradation of customer trust,” said Liat Hayun, VP of Research and Product Management, Cloud Security, Tenable. Tenable® is the exposure management company, exposing and closing the cybersecurity gaps that erode business value, reputation and trust. By protecting enterprises from security exposure, Tenable reduces business risk for approximately 44,000 customers around the globe.