Executive Summary
In 2025, the enterprise risk landscape experienced a paradigm shift: the adoption of AI and LLMs officially becoming the primary driver of cloud risk. Today, almost 88% of organizations now leverage AI in at least one business function. With this level of integration, the risk of AI is now outpacing traditional security guardrails, culminating in a highly complex and interconnected attack surface. SentinelOne’s new AI and Cloud Verified Exploit Paths and Secrets Scanning Report examines this evolving threatscape and draws on telemetry from over 11,000 anonymized customer environments to offer deeper visibility into how threat actors are actively exploiting modern cloud and AI infrastructures. A primary finding of the 2026 report is the rising proliferation of AI-specific credentials. The data indicates that AI-related secrets — such as OpenAI API Keys, Azure OpenAI API Keys, and others — increased by approximately 140% in a span of one year. This growth correlates directly with the rapid embedding of AI technologies into customer support systems, internal tooling, financial platforms, and product experiences. Ubiquitous deployment has generated a widespread organizational pattern known as 'shadow AI' – the unsanctioned use of AI tools in an environment without formal IT approval or security oversight. In practice, this occurs when developers or internal teams utilize unmanaged or personal LLM keys to process corporate data outside of sanctioned IT or security channels. Since these AI integrations span numerous internal applications, the same API keys are frequently duplicated and stored within code repositories, SaaS configurations, and development scripts. Compounding this, these credentials are often implemented without proper access controls or routine rotation schedules. The sprawl of these credentials renders them difficult to track via standard secrets management protocols, establishing a requirement for more centralized governance over how AI keys are issued and utilized.
Why This Matters Now
The rapid integration of AI into business functions has outpaced traditional security measures, leading to a complex and interconnected attack surface. The proliferation of AI-specific credentials and the rise of 'shadow AI' underscore the urgent need for centralized governance and enhanced security protocols to mitigate emerging risks.
Attack Path Analysis
An attacker exploited misconfigured cloud storage to access AI-related API keys, escalating privileges by leveraging these keys to interact with various enterprise systems. They moved laterally across cloud services, establishing command and control channels, and exfiltrated sensitive data processed by AI models. The attack culminated in data exposure and potential manipulation of AI model behavior.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited misconfigured cloud storage to access AI-related API keys.
Related CVEs
CVE-2014-6271
CVSS 9.8GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, allowing remote attackers to execute arbitrary code via a crafted environment.
Affected Products:
GNU Bash – <= 4.3
Exploit Status:
exploited in the wildCVE-2018-13379
CVSS 9.8An improper limitation of a pathname to a restricted directory in Fortinet FortiOS and FortiProxy SSL VPN web portal allows an unauthenticated attacker to download system files via crafted HTTP resource requests.
Affected Products:
Fortinet FortiOS – 5.6.3 to 5.6.7, 6.0.0 to 6.0.4
Fortinet FortiProxy – 1.0.0 to 1.0.7, 1.1.0 to 1.1.6, 1.2.0 to 1.2.8, 2.0.0
Exploit Status:
exploited in the wildCVE-2019-11510
CVSS 10An arbitrary file read vulnerability in Pulse Secure Pulse Connect Secure allows an unauthenticated remote attacker to send a specially crafted URI to perform an arbitrary file reading vulnerability.
Affected Products:
Pulse Secure Pulse Connect Secure – <= 9.0R3.4
Exploit Status:
exploited in the wildCVE-2019-15107
CVSS 9.8Webmin through 1.920 allows remote code execution via crafted HTTP requests.
Affected Products:
Webmin Webmin – <= 1.920
Exploit Status:
exploited in the wildCVE-2023-1698
CVSS 9.8A zero-day backdoor vulnerability in Barracuda ESG allows remote attackers to execute arbitrary code.
Affected Products:
Barracuda Email Security Gateway – 5.1.3.001 to 9.2.0.006
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Unsecured Credentials: Credentials in Files
Valid Accounts
Exploit Public-Facing Application
Application Layer Protocol: Web Protocols
Phishing: Spearphishing Attachment
Resource Hijacking
Virtualization/Sandbox Evasion: System Checks
Impair Defenses: Disable or Modify Tools
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Secure Software Development Practices
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
AI credential exposure threatens payment systems, customer data, and regulatory compliance with exponential secrets proliferation enabling account takeovers and financial fraud.
Computer Software/Engineering
Shadow AI deployment and CI/CD token exposure create supply chain vulnerabilities, enabling source code access and deployment pipeline manipulation through repository compromises.
Health Care / Life Sciences
Unmanaged AI keys processing patient data violate HIPAA compliance while legacy CVEs enable unauthorized access to sensitive healthcare information systems.
Banking/Mortgage
Payment gateway key exposure combined with AI credential sprawl threatens transaction integrity, customer PII, and enables large-scale financial system manipulation attacks.
Sources
- The Convergence of Cloud Secrets & AI Riskhttps://www.sentinelone.com/blog/the-convergence-of-cloud-secrets-and-ai-risk/Verified
- When AI Secrets Go Public: The Rising Risk of Exposed ChatGPT API Keyshttps://news.backbox.org/2026/02/12/when-ai-secrets-go-public-the-rising-risk-of-exposed-chatgpt-api-keys/Verified
- API Key Best Practices: Keeping Your Keys Safe and Securehttps://support.anthropic.com/en/articles/9767949-api-key-best-practices-keeping-your-keys-safe-and-secureVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it embeds security directly into the cloud fabric, likely reducing the attacker's ability to move laterally and exfiltrate data undetected.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit misconfigured storage to access sensitive API keys would likely be constrained.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges using compromised API keys would likely be limited.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement across cloud services would likely be constrained.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish and maintain command and control channels would likely be reduced.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data to external servers would likely be limited.
The attacker's ability to expose sensitive data and manipulate AI model behavior would likely be constrained.
Impact at a Glance
Affected Business Functions
- Customer Support Systems
- Internal Tooling
- Financial Platforms
- Product Development
Estimated downtime: 7 days
Estimated loss: $15,000
Unauthorized access to sensitive corporate conversations, proprietary datasets, and internal user prompts and outputs.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least-privilege access and prevent lateral movement.
- • Utilize Egress Security & Policy Enforcement to monitor and control outbound traffic, mitigating data exfiltration risks.
- • Deploy Multicloud Visibility & Control solutions to detect and respond to anomalous activities across cloud environments.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.
- • Establish comprehensive governance of AI credentials, including regular rotation and monitoring for unauthorized usage.



