AI models expose new attack surfaces through misconfiguration
Fri, 21st Aug 2026 (Today)
Volume, variety and velocity were the catchcry of the big data age. But the same three words describe the threat landscape organisations face today. Criminals, nation-states and opportunists armed with AI can launch more attacks faster than ever before.
When a security update is released, AI enables attackers to reverse engineer the patch and weaponise an attack tool in under an hour. And the days of poorly written phishing and smishing emails are behind us as the same AI tools that help us summarise reports and conduct research are used to craft messages designed to fool us into visiting dodgy websites or download malicious payloads.
Arie Zilberstein, the VP of Threat Detection and Response at Wiz, said there are two big trends to watch.
"Attackers use AI frontier models to accelerate penetration and find vulnerabilities. It's not a new attack. It's happening at a faster pace than we've experienced before. The other aspect is that as more companies are using AI as infrastructure, they are introducing a new attack surface. Attackers are targeting these models because, often, they're not configured properly."
Securing AI within organisations is not just about ensuring malicious parties try to exploit internal systems. Recent revelations by OpenAI, Meta and Anthropic revealed that AI models are able to run and 'escape' so-called closed environments. And while the news was sensational, Zilberstein saw a positive.
"Coming from an instant response background. I think disclosure is not always easy, and many companies try to avoid it. What I've seen in recent months is more disclosure and that gives me an optimistic view."
Wiz's recent State of Cloud Risk report revealed the continued risk to supply chains. Zilberstein said that supply chain attacks are now reaching "pandemic levels", much like ransomware. He said attackers are compromising packages that result in the eventual poisoning of CICD (Continuous Integration and Continuous Delivery) pipelines which can lead to larger scale compromise within organisations.
Another major trend in the research was the continued growth in identity-based attacks.
"Companies are using and deploying models in cloud infrastructure in a way that introduces misconfiguration. Often, these models are publicly exposed and create a new attack surface. Identity-based attacks on these new services can lead to compromise of a cloud service," he said.
The risk he sees is a model that is external facing but is exposed to internal, sensitive data. That could eventually lead to AI-enabled data exfiltration.
With the volume of security alerts growing, it's not surprising that many alerts and indicators of compromise are not being investigated. Some research suggests the average organisation receives more than 3000 alerts with almost two-thirds not investigated. This is why Zilberstein says the only way to fight the rising tide of AI-powered attacks is with AI – something his team does at Wiz.
Mimicking the traditional approach of having red and blue teams attack and defend respectively, Wiz has red and blue agents. The red agents look for potential vulnerabilities with the blue agents conducting triage.
"These agents help us get to the questions of context and visibility. They help us map our cloud to all the identities we have into a table or graph. Then we map the runtime events into these resources for context," he explained.
While the AI agents are important, Zilberstein said they are an addition to the security team, not a replacement. The blue agents provide the first triage and then an analyst reviews to determine whether the verdict is right or wrong. Then enables the analysts to focus on the more pressing alerts which, he said, helps with their professional development.
"The blue agent is like an analyst in the SOC team that can do a lot of the triage work so the analyst can focus on reviewing, validating, responding to things that would eventually become malicious," said Zilberstein.
A third agent, dubbed the green agent, supports remediation. It looks a list of issues and provides the process of automating a fix and finding the owners by using the breadth of context that Wiz has collected with the other agents.
A significant part of Wiz's efforts to secure organisations by using AI is Project Atlas. This is Wiz's autonomous AI system for advanced vulnerability research and code-to-cloud security analysis. Atlas uses a multi-agent framework that maps attack surfaces, finds multi-step vulnerabilities, challenges findings to reduce false positives, and develops working exploits.
"Project Atlas is not a commercial product yet," noted Zilberstein. "It's a research project that, so far, has been tested and generated good results. We've been working with many major technology companies to identify zero days in their code base. Eventually, it will be part of Wiz Code, which is the product that focuses on identifying issues, problems and vulnerabilities like zero days in code."
As companies adopt AI, they must first understand how it is being used, assess the risks, and close exposures to support fast but safe deployment. Security leaders should treat AI models as tools available to both attackers and defenders and move quickly to adopt AI themselves through context-driven internal and external scanning. If AI penetration testing is not already in use, it should be a near-term priority. But organisations should not let the hype distract from the basics of protecting identities, fixing misconfigurations, and securing code before it reaches production.