Tenable:2026年云与 AI 安全风险报告:AI 身份权限过高、关键供应链暴露、“易受攻击” 工作负载及主动修复策略(英文版)(20页).pdf
1、ReportTenable Cloud and AI Security Risk Report 2026Overprivileged AI identities,critical supply chain exposure,“sitting duck”workloads and proactive remediation tacticsExecutive summary03Key findings04How AI services are expanding the cloud attack surface Tenable Research:Defining the AI attack sur
2、face 05 AIs new backbone:The MCP revolution 0705Supply chain attacks:The hidden risk of third-party code packages How we classify critical risk 09 Shai-Hulud and s1ngularity 0908Conclusion20Mitigation strategies18The least-privilege lapse:The risk of dormant,overprivileged identities12Methodology19T
3、able of contentsSupply chain attacks:The hidden risk of external access Terminology 1110“Ghost”secrets:When forgotten credentials meet overprivileged identities Terminology 1413Exposure management:Finding“sitting duck”cloud workloads React2Shell and the race for CVE remediation 1716Tenable Cloud and
4、 AI Security Risk Report 20262Executive summaryThe Tenable Cloud and AI Security Risk Report 2026 reveals a critical tension in modern infrastructure:engineering velocity is outpacing security governance and attackers are exploiting the gap.In this report,we explore how rapid architectural shifts in
5、cluding the adoption of AI and use of external service dependencies have intersected with persistent visibility blind spots to expand the cloud attack surface,creating direct paths to sensitive data.Specifically,we investigate the“bleeding edge”of AI risk,uncovering significant control issues from o
6、verprivileged identities that AI services can instantly assume(18%of organizations),to abandoned“ghost”roles and critical AI secrets hardcoded in configuration files.We quantify the hidden dangers of the supply chain,revealing that 86%of organizations have installed third-party code packages that ho





点击查看更多