{"id":151591,"date":"2025-06-23T12:34:03","date_gmt":"2025-06-23T12:34:03","guid":{"rendered":"https:\/\/teknomers.com\/en\/the-jenga-effect-and-the-toxic-combination-why-we-need-to-ensure-cloud-ai-security-from-the-ground-up\/"},"modified":"2025-06-23T12:34:05","modified_gmt":"2025-06-23T12:34:05","slug":"the-jenga-effect-and-the-toxic-combination-why-we-need-to-ensure-cloud-ai-security-from-the-ground-up","status":"publish","type":"post","link":"https:\/\/teknomers.com\/en\/the-jenga-effect-and-the-toxic-combination-why-we-need-to-ensure-cloud-ai-security-from-the-ground-up\/","title":{"rendered":"The &#8220;Jenga Effect&#8221; and the toxic combination: why we need to ensure cloud AI security from the ground up."},"content":{"rendered":"\n<h2>The Dual Nature of Artificial Intelligence: Opportunities and Risks<\/h2>\n<div class=\"visual__image image-initial-width\">\n    <picture><source  media=\"(min-width: 1000px)\"\/><source  media=\"(min-width: 768px)\"\/><source  media=\"(min-width: 580px)\"\/><source  media=\"(min-width: 350px)\"\/><source  media=\"(min-width: 80px)\"\/><\/picture><figcaption class=\"article-figcaption-img\">The complexity and speed of innovation in AI demand robust and automated solutions (Illustrative Image &#8211; Infobae)<\/figcaption><\/div>\n<p>Artificial Intelligence (AI) is undeniably powerful, offering remarkable opportunities for \u00a0business transformation\u00a0. However, the rapid integration of AI technologies also introduces significant \u00a0risks\u00a0 that organizations must address. The accelerated adoption of these solutions leads to the emergence of new vulnerabilities, creating a precarious balance between leveraging AI&#8217;s benefits and safeguarding against potential attacks.<\/p>\n<p>At the core of these risks lies a \u201c\u00a0toxic combination\u00a0\u201d formed by four key factors.<\/p>\n<h2>Understanding the Threat Landscape<\/h2>\n<p>The first factor is \u00a0critical vulnerabilities\u00a0. Systems built on Unix, which are often employed for AI workloads, contain numerous libraries that may not always be audited or updated regularly. Research indicates that cloud workloads incorporating AI display a vulnerability rate of \u00a070%\u00a0, compared to approximately \u00a050%\u00a0 for non-AI workloads.<\/p>\n<div class=\"blockquote\">\n<blockquote class=\"color_figcaption\"><p>Cloud workloads involving AI show a higher vulnerability rate (70%) than those that do not include this technology.<\/p><\/blockquote>\n<\/div>\n<p>The second element of concern is \u00a0exposed public access\u00a0. For instance, 14% of data storage on platforms like Amazon Bedrock has public access blocking disabled, which paves the way for potential attackers to exploit these openings.<\/p>\n<p>Next, we have \u00a0excessive privileges\u00a0. Data shows that \u00a077%\u00a0 of organizations utilizing Vertex AI Workbench on Google Cloud have at least one instance configured with the default Compute Engine service account set to &#8220;editor.&#8221; This setting allows full access to the project, thereby exposing sensitive information and critical resources.<\/p>\n<p>Finally, there are \u00a0dangerous default configurations\u00a0. A startling \u00a090.5%\u00a0 of SageMaker notebooks enable root access by default. Such configurations allow any user with access to compromise the environment with administrative privileges.<\/p>\n<h2>The Jenga Effect in Cloud Systems<\/h2>\n<p>The coexistence of these four elements amplifies the risk of attack while complicating the detection and control of adverse impacts. In the realm of AI, where models process sensitive data or make critical decisions, the repercussions can be catastrophic\u2014ranging from the manipulation of predictions to the unauthorized disclosure of personal information.<\/p>\n<p>This issue encapsulates what we refer to as the \u201c\u00a0Jenga effect\u00a0.\u201d Cloud service providers typically build new services on top of existing ones, thus inheriting default characteristics that may not align with \u00a0best security practices\u00a0. A default configuration in an underlying component like a virtual machine or a service account can jeopardize the entire stack of services layered above it, including machine learning tools such as notebooks, training pipelines, or inference APIs.<\/p>\n<div class=\"blockquote\">\n<blockquote class=\"color_figcaption\"><p>The most alarming aspect is that these issues often remain &#8220;behind the scenes,&#8221; going unnoticed by security and development teams.<\/p><\/blockquote>\n<\/div>\n<p>The silent nature of these vulnerabilities means that security and development teams frequently rely on automated cloud management systems, inadvertently overlooking the potential risks lurking in their environments. As such, adopting a robust exposure management strategy is vital for navigating the nuanced landscape of AI.<\/p>\n<h2>Building a Safe AI Environment<\/h2>\n<p>Given this complex and rapidly evolving scenario, companies must embrace a \u00a0fortified and automated solution\u00a0 for risk management. Doing so will transform the lofty ambitions surrounding AI into tangible and secure business benefits. It will ensure that the soaring aspirations of innovation rest on solid foundations rather than precarious ones that could easily collapse.<\/p>\n<p><i><b>The author is the Director of Security Engineering for Tenable Latin America and the Caribbean.<\/b><\/i><\/p>\n<p><br \/>\n<br \/><a href=\"https:\/\/teknomers.com\/category\/general\/\" rel=\"dofollow\">General News &#8211; 2<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Dual Nature of Artificial Intelligence: Opportunities and Risks The complexity and speed of innovation in AI demand robust and automated solutions (Illustrative Image &#8211; Infobae) Artificial Intelligence (AI) is undeniably powerful, offering remarkable opportunities for \u00a0business transformation\u00a0. However, the rapid integration of AI technologies also introduces significant \u00a0risks\u00a0 that organizations must address. The accelerated [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":151592,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[7193,13193,2093,4138,913,37461,2648,4123],"class_list":["post-151591","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-mazagine","tag-cloud","tag-combination","tag-effect","tag-ensure","tag-ground","tag-jenga","tag-security","tag-toxic"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/posts\/151591","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/comments?post=151591"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/posts\/151591\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/media\/151592"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/media?parent=151591"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/categories?post=151591"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/en\/wp-json\/wp\/v2\/tags?post=151591"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}