Tenable Holdings Inc. Unveils Cloud AI Risk Report 2025: Highlighting Vulnerabilities in Popular AI Tools
1. Introduction
In a significant development for the cybersecurity industry, Tenable Holdings Inc., a leader in exposure management, has released its highly anticipated Cloud AI Risk Report for 2025. This report reveals alarming vulnerabilities in cloud-based AI tools that, while transformative for businesses, also present complex cyber risks. With findings that could impact organizations using major cloud providers like Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure, the report underscores the urgent need for enhanced security measures in the rapidly evolving landscape of artificial intelligence.
2. Key Findings of the Report
The Cloud AI Risk Report 2025 presents a series of critical insights into the vulnerabilities present in cloud AI workloads and services. Here are the standout findings:
Unremediated Vulnerabilities in Cloud AI Workloads
The report highlights that approximately 70% of cloud AI workloads contain at least one unremediated vulnerability. Notably, a critical vulnerability identified as CVE-2023-38545 was found in 30% of these workloads. This statistic raises serious concerns regarding the security posture of organizations leveraging AI in cloud environments.
Jenga®-Style Cloud Misconfigurations
Tenable’s innovative Jenga®-style concept points to a worrying trend in cloud security. The report reveals that 77% of organizations have misconfigured the default Compute Engine service account in Google Vertex AI Notebooks, leading to overprivileged access risks. This layer of misconfiguration could create a domino effect, leaving organizations vulnerable to exploitation.
Data Poisoning Risks in AI Training Data
As organizations increasingly rely on AI training data, the report finds that 14% of companies using Amazon Bedrock do not adequately restrict public access to at least one AI training bucket. Furthermore, 5% of these organizations have at least one overly permissive bucket, which poses a risk of data poisoning that could skew model results and ultimately affect business outcomes.
Root Access Vulnerabilities in Amazon SageMaker
The report further indicates that 91% of Amazon SageMaker users have at least one notebook instance that grants root access by default. If compromised, this access could lead to unauthorized alterations of all files within the instance, significantly heightening the risk of data breaches.
3. Expert Commentary
Liat Hayun, VP of Research and Product Management for Cloud Security at Tenable, emphasized the gravity of these findings: “When we talk about AI usage in the cloud, more than sensitive data is on the line. If a threat actor manipulates the data or AI model, there can be catastrophic long-term consequences, such as compromised data integrity, compromised security of critical systems, and degradation of customer trust.”
Hayun stressed the need for organizations to adapt their cloud security measures: “Cloud security measures must evolve to meet the new challenges of AI and find the delicate balance between protecting against complex attacks on AI data and enabling organizations to achieve responsible AI innovation.”
4. Conclusion
The Cloud AI Risk Report 2025 from Tenable Holdings Inc. serves as a crucial wake-up call for businesses operating in cloud environments. With the rapid integration of AI tools into various sectors, understanding and addressing these vulnerabilities is imperative. The report sheds light on the pressing need for enhanced security frameworks that evolve alongside technological advancements, ensuring that organizations can harness the power of AI without compromising their data integrity and security.
As Tenable continues to lead the charge in exposure management, its findings will undoubtedly inform best practices and strategies for safeguarding sensitive AI operations in the cloud.
For more information about Tenable and their offerings, visit their official website.