logo
AI deployment creates new cybersecurity risks, warns report

AI deployment creates new cybersecurity risks, warns report

Techday NZ2 days ago
Trend Micro has published its latest State of AI Security Report, highlighting how the pace of artificial intelligence development is contributing to new cybersecurity vulnerabilities in critical infrastructure.
The report details a range of security challenges faced by organisations as they deploy AI technologies, including vulnerabilities in key components, accidental internet exposure, weaknesses in open-source software, and issues with container-based systems.
Critical vulnerabilities
The research identifies vulnerabilities and exploits in vital parts of AI infrastructure. Many AI applications rely on a blend of specialised software, some of which are susceptible to the same flaws as traditional software. The report notes the discovery of zero-day vulnerabilities in components such as ChromaDB, Redis, NVIDIA Triton, and NVIDIA Container Toolkit, posing significant risks if left unpatched.
In addition to these, the report draws attention to the exposure of servers hosting AI infrastructure to the public internet, often as a result of rapid deployment and inadequate security measures. According to Trend Micro, more than 200 ChromaDB servers, 2,000 Redis servers, and over 10,000 Ollama servers have been found exposed without authentication, leaving them open to malicious probing.
Open-source and container concerns
The reliance on open-source components in AI frameworks is another focus for security risks. Vulnerabilities may go unnoticed when they are integrated into production systems, as demonstrated at the recent Pwn2Own Berlin event. Researchers there identified an exploit in the Redis vector database, attributed to an outdated Lua component.
Continuing the theme of infrastructure risk, the report discusses the widespread use of containers in AI deployments. Containers, while commonly used to improve efficiency, are vulnerable to the same security issues that plague broader cloud and container environments. Pwn2Own researchers also discovered an exploit targeting the NVIDIA Container Toolkit, raising concerns about container management practices in the deployment of AI technologies.
Expert perspectives AI may represent the opportunity of the century for ANZ businesses. But those rushing in too fast without taking adequate security precautions may end up causing more harm than good. As our report reveals, too much global AI infrastructure is already being built from unsecured and/or unpatched components, creating an open door for threat actors.
This statement from Mick McCluney, Field CTO for ANZ at Trend Micro, underscores the importance of balancing innovation in AI with a robust approach to cybersecurity.
Stuart MacLellan, Chief Technology Officer at NHS SLAM, also shared perspectives on the organisational implications of these findings: There are still lots of questions around AI models and how they could and should be used. We now get much more information now than we ever did about the visibility of devices and what applications are being used. It's interesting to collate that data and get dynamic, risk-based alerts on people and what they're doing depending on policies and processes. That's going to really empower the decisions that are made organisationally around certain products.
Recommended actions
The report sets out several practical steps organisations can take to mitigate risk. These include enhanced patch management, regular vulnerability scanning, maintaining a comprehensive inventory of all software components, and adopting best practices for container management. The report also advises that configuration checks should be undertaken to ensure that critical AI infrastructure is not inadvertently exposed to the internet.
The findings highlight the need for the developer community and users of AI to better balance security with speed to market. Trend Micro recommends that organisations exercise due diligence, particularly as the adoption of AI continues to rise across various sectors.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Cost of living drags consumer confidence further down
Cost of living drags consumer confidence further down

RNZ News

time31 minutes ago

  • RNZ News

Cost of living drags consumer confidence further down

Inflation expectations lifted 0.2 points to 5.1 percent, the highest since April 2023. Photo: Unsplash/ Rupixen Consumer confidence continues to track down amid worries about the high cost of living. The ANZ-Roy Morgan Consumer Confidence Index (PDF) dropped four points to 94.7 last month, as the midwinter blues set in. Anything under 100 points indicates more pessimists than optimists. Inflation expectations lifted 0.2 points to 5.1 percent, the highest since April 2023. "That's well out of line with headline inflation of 2.7 percent , but some prominent necessities are increasing at a much higher rate than that, including food (4.2 percent), insurance, electricity and council rates," ANZ chief economist Sharon Zollner said. The proportion of households who thought it was a good time to buy a major household item remained weak with a one-point drop to -8, leaving the retail sector struggling to make sales. "At this stage of the business cycle, inflation in necessities is crowding out discretionary spending," Zollner said, noting annual food price inflation was 4.2 percent in June. However, she said there was light at the end of the tunnel with more people rolling onto lower mortgage rates, and high farmer incomes supporting the regions . "While inflation is clearly front of mind for households, we do expect things to ease on that front towards the end of the year." Sign up for Ngā Pitopito Kōrero, a daily newsletter curated by our editors and delivered straight to your inbox every weekday.

Amazon profits surge 35% as AI investments drive growth
Amazon profits surge 35% as AI investments drive growth

RNZ News

time2 hours ago

  • RNZ News

Amazon profits surge 35% as AI investments drive growth

By AFP Despite the stellar results, investors seemed worried about Amazon's big cash outlays to pursue its AI ambitions. Photo: 123RF Amazon has reported a 35 percent jump in quarterly profits as the e-commerce giant says major investments in artificial intelligence has been paying off. The Seattle-based company posted net profit of $18.2 billion (NZ$30.9 billion) for the second quarter that ended June 30, compared with $13.5 billion (NZ$22.9 billion) in the same period last year. Net sales climbed 13 percent to $167.7 billion (NZ$284.7 billion), beating analyst expectations and signalling that the global company was surviving the impacts of the high-tariff trade policy under US President Donald Trump. "Our conviction that AI will change every customer experience is starting to play out," chief executive Andy Jassy said, pointing to the company's expanded Alexa+ service and new AI shopping agents. Amazon Web Services (AWS), the company's world leading cloud computing division, led the charge with sales jumping 17.5 percent to $30.9 billion (NZ$52.45 billion). The unit's operating profit rose to $10.2 billion (NZ$17.3 billion) from $9.3 billion (NZ$15.8 billion) a year earlier. The strong AWS performance reflects surging demand for cloud infrastructure to power AI applications, a trend that has benefited major cloud providers as companies race to adopt generative AI technologies. Despite the stellar results, investors seemed worried about Amazon's big cash outlays to pursue its AI ambitions, sending its share price more than three percent lower in after-hours trading. The company's free cash flow declined sharply to $18.2 billion (NZ$30.9 billion) for the trailing 12 months, down from $53 billion (NZ$90 billion) in the same period last year, as Amazon ramped up capital spending on AI infrastructure and logistics. The company spent $32.2 billion (NZ$54.7 billion) on property and equipment in the quarter, nearly double the $17.6 billion (NZ$29.9 billion) spent a year earlier, reflecting massive investments in data centres and backroom capabilities. Amazon has pledged to spend up to $100 billion (NZ$169.8 billion) this year, largely on AI-related investments for AWS. For the current quarter, Amazon forecast net sales between $174.0 billion (NZ$295 billion) and $179.5 billion (NZ$304.8 billion), representing solid growth of 10-13 percent compared with the third quarter of 2024. Operating profit was expected to range from $15.5 billion (NZ$26.3 billion) to $20.5 billion (NZ$34.8 billion) in the current third quarter, which was lower than some had hoped for and likely also a factor in investor disappointment. - AFP

'Think before you click', cybersecurity expert says as New Zealanders fall victim to online shopping scams
'Think before you click', cybersecurity expert says as New Zealanders fall victim to online shopping scams

RNZ News

time3 hours ago

  • RNZ News

'Think before you click', cybersecurity expert says as New Zealanders fall victim to online shopping scams

People were getting duped by misleading offers when shopping online, a cybersecurity expert says. Photo: 123RF A cybersecurity expert is advising people to think before they click, with more New Zealanders falling victim to online shopping scams. A national survey by Trend Micro, of over 500 people revealed two-thirds had been targeted by online scams. Of those targeted, one in three had fallen victim to the scam. Trend Micro director of consumer education Ashley Millar told Morning Report , more people were getting duped by misleading offers when shopping online. "Our local trend marker research has found that scamming is definitely up in New Zealand. "One of the main ways that people are falling victim is by seeing a promoted item on a social media market place or a retail website that has looked legitimate but unfortunately that hasn't been the case." He said in most cases, people did not receive a product they paid for. He said if an ad looked too good to be true, it most likely was. Sign up for Ngā Pitopito Kōrero , a daily newsletter curated by our editors and delivered straight to your inbox every weekday.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store