The Containment Era is here. →Explore

Executive Summary

In 2025, the enterprise risk landscape experienced a paradigm shift: the adoption of AI and LLMs officially becoming the primary driver of cloud risk. Today, almost 88% of organizations now leverage AI in at least one business function. With this level of integration, the risk of AI is now outpacing traditional security guardrails, culminating in a highly complex and interconnected attack surface. SentinelOne’s new AI and Cloud Verified Exploit Paths and Secrets Scanning Report examines this evolving threatscape and draws on telemetry from over 11,000 anonymized customer environments to offer deeper visibility into how threat actors are actively exploiting modern cloud and AI infrastructures. A primary finding of the 2026 report is the rising proliferation of AI-specific credentials. The data indicates that AI-related secrets — such as OpenAI API Keys, Azure OpenAI API Keys, and others — increased by approximately 140% in a span of one year. This growth correlates directly with the rapid embedding of AI technologies into customer support systems, internal tooling, financial platforms, and product experiences. Ubiquitous deployment has generated a widespread organizational pattern known as 'shadow AI' – the unsanctioned use of AI tools in an environment without formal IT approval or security oversight. In practice, this occurs when developers or internal teams utilize unmanaged or personal LLM keys to process corporate data outside of sanctioned IT or security channels. Since these AI integrations span numerous internal applications, the same API keys are frequently duplicated and stored within code repositories, SaaS configurations, and development scripts. Compounding this, these credentials are often implemented without proper access controls or routine rotation schedules. The sprawl of these credentials renders them difficult to track via standard secrets management protocols, establishing a requirement for more centralized governance over how AI keys are issued and utilized.

Why This Matters Now

The rapid integration of AI into business functions has outpaced traditional security measures, leading to a complex and interconnected attack surface. The proliferation of AI-specific credentials and the rise of 'shadow AI' underscore the urgent need for centralized governance and enhanced security protocols to mitigate emerging risks.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

'Shadow AI' refers to the unsanctioned use of AI tools within an organization without formal IT approval or security oversight, often involving unmanaged or personal LLM keys processing corporate data outside sanctioned channels.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it embeds security directly into the cloud fabric, likely reducing the attacker's ability to move laterally and exfiltrate data undetected.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to exploit misconfigured storage to access sensitive API keys would likely be constrained.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges using compromised API keys would likely be limited.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's lateral movement across cloud services would likely be constrained.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to establish and maintain command and control channels would likely be reduced.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate sensitive data to external servers would likely be limited.

Impact (Mitigations)

The attacker's ability to expose sensitive data and manipulate AI model behavior would likely be constrained.

Impact at a Glance

Affected Business Functions

  • Customer Support Systems
  • Internal Tooling
  • Financial Platforms
  • Product Development
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $15,000

Data Exposure

Unauthorized access to sensitive corporate conversations, proprietary datasets, and internal user prompts and outputs.

Recommended Actions

  • Implement Zero Trust Segmentation to enforce least-privilege access and prevent lateral movement.
  • Utilize Egress Security & Policy Enforcement to monitor and control outbound traffic, mitigating data exfiltration risks.
  • Deploy Multicloud Visibility & Control solutions to detect and respond to anomalous activities across cloud environments.
  • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.
  • Establish comprehensive governance of AI credentials, including regular rotation and monitoring for unauthorized usage.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image