Skip to main content
Tenable Holdings Inc (TENB)
Computer Software and Services Information Technology
Stock AI

Tenable Holdings Inc. Unveils Cloud AI Risk Report 2025: Highlighting Vulnerabilities in Popular AI Tools

Last updated: March 19, 2025
Taurigo

1. Introduction

In a significant development for the cybersecurity industry, Tenable Holdings Inc., a leader in exposure management, has released its highly anticipated Cloud AI Risk Report for 2025. This report reveals alarming vulnerabilities in cloud-based AI tools that, while transformative for businesses, also present complex cyber risks. With findings that could impact organizations using major cloud providers like Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure, the report underscores the urgent need for enhanced security measures in the rapidly evolving landscape of artificial intelligence.

2. Key Findings of the Report

The Cloud AI Risk Report 2025 presents a series of critical insights into the vulnerabilities present in cloud AI workloads and services. Here are the standout findings:

Unremediated Vulnerabilities in Cloud AI Workloads

The report highlights that approximately 70% of cloud AI workloads contain at least one unremediated vulnerability. Notably, a critical vulnerability identified as CVE-2023-38545 was found in 30% of these workloads. This statistic raises serious concerns regarding the security posture of organizations leveraging AI in cloud environments.

Jenga®-Style Cloud Misconfigurations

Tenable’s innovative Jenga®-style concept points to a worrying trend in cloud security. The report reveals that 77% of organizations have misconfigured the default Compute Engine service account in Google Vertex AI Notebooks, leading to overprivileged access risks. This layer of misconfiguration could create a domino effect, leaving organizations vulnerable to exploitation.

Data Poisoning Risks in AI Training Data

As organizations increasingly rely on AI training data, the report finds that 14% of companies using Amazon Bedrock do not adequately restrict public access to at least one AI training bucket. Furthermore, 5% of these organizations have at least one overly permissive bucket, which poses a risk of data poisoning that could skew model results and ultimately affect business outcomes.

Root Access Vulnerabilities in Amazon SageMaker

The report further indicates that 91% of Amazon SageMaker users have at least one notebook instance that grants root access by default. If compromised, this access could lead to unauthorized alterations of all files within the instance, significantly heightening the risk of data breaches.

3. Expert Commentary

Liat Hayun, VP of Research and Product Management for Cloud Security at Tenable, emphasized the gravity of these findings: “When we talk about AI usage in the cloud, more than sensitive data is on the line. If a threat actor manipulates the data or AI model, there can be catastrophic long-term consequences, such as compromised data integrity, compromised security of critical systems, and degradation of customer trust.”

Hayun stressed the need for organizations to adapt their cloud security measures: “Cloud security measures must evolve to meet the new challenges of AI and find the delicate balance between protecting against complex attacks on AI data and enabling organizations to achieve responsible AI innovation.”

4. Conclusion

The Cloud AI Risk Report 2025 from Tenable Holdings Inc. serves as a crucial wake-up call for businesses operating in cloud environments. With the rapid integration of AI tools into various sectors, understanding and addressing these vulnerabilities is imperative. The report sheds light on the pressing need for enhanced security frameworks that evolve alongside technological advancements, ensuring that organizations can harness the power of AI without compromising their data integrity and security.

As Tenable continues to lead the charge in exposure management, its findings will undoubtedly inform best practices and strategies for safeguarding sensitive AI operations in the cloud.

For more information about Tenable and their offerings, visit their official website.

You may also be interested in:
Copyright ©2026 Taurigo GmbH. All rights reserved.Taurigo GmbH provides no investment advice. Any analyses, research, ideas, prices, or other information contained on this website are provided as general market information for educational and entertainment purposes only, and do not constitute investment advice. We assume no responsibility for the accuracy, completeness or timeliness of any financial information contained on this site. In particular, we do not constitute an invitation to buy, sell or hold securities or other financial products. We shall not be liable for any loss or damage, including without limitation loss of profits, arising directly or indirectly from use of or reliance on the provided information. Before making any investment decision, you should consider whether it is suitable for your situation and obtain appropriate financial, tax and legal advice.