The year of AI came with promises of huge productivity gains for businesses, but the rush to adopt new tools and services has also opened up new avenues of attack in business environments. Here are some of the top security threats to the AI ecosystem uncovered by security researchers this year, either in real-world settings or as attacks demonstrated by researchers.
See also: NIST – MITRE: Collaboration on AI Centers for Manufacturing and Cybersecurity

**Shady AI and Vulnerable AI Tools** Freely using AI tools by employees to automate business processes may seem like a good idea that could uncover creative solutions. But it can quickly get out of hand if not done under strict policy and monitoring. A recent survey of 2,000 employees from companies in the US and UK revealed that 49% are using AI tools that have not been approved by their employers, and that more than half do not understand how their inputs from these tools are stored and analyzed.
The deployment of all AI-related tools and services, whether on-premises or in the cloud, must involve the security team to identify insecure configurations or known vulnerabilities.
In its 2025 State of Cloud Security report,Orca Security reported that 84% of organizations now use AI-related tools in the cloud and that 62% had at least one vulnerable AI package in their environment. A separate report from the Cloud Security Alliance reported that a third of organizations experienced a cloud data breach involving an AI workload, with 21% of these incidents caused by vulnerabilities, 16% by insecure security settings, and 15% by compromised credentials or weak authentication.
**Poisoning the AI Supply Chain** Companies that develop software with AI-related libraries and frameworks should be aware that their developers may be targeted. Evaluating the source of AI models and development packages is crucial. Earlier this year, security researchers from ReversingLabs found malware hidden in AI models hosted on Hugging Face, the largest online hosting database for open source models and other machine learning assets.
See also: OpenAI strengthens security to prevent malicious uses of AI

**AI Credential Theft** Attackers are also adopting AI for their businesses, and they prefer to do so without paying for it and in the name of others. The theft of credentials that can be used to access LLMs through official APIs or services like Amazon Bedrock is now widespread and has even been given a name: LLMjacking. This year, Microsoft filed a lawsuit against a gang that specializes in stealing LLM credentials and using them to build paid services for other cybercriminals to create content that bypasses the usual built-in ethical safeguards.
Large volumes of API calls to LLMs can accrue significant costs for the owners of the stolen credentials, with researchers estimating potential costs of over $100,000 per day when querying cutting-edge models.
**Prompt injections** AI tools also come with entirely new types of security vulnerabilities, the most common of which is known as Prompt injection and arises from the fact that it is very difficult to control what LLMs interpret as commands to execute or as passive data to analyze. By their nature there is no distinction, as LLMs do not interpret language and intent like humans.
This leads to scenarios where data passed to an LLM from a third source — for example in the form of a document, an incoming email, a web page, etc. — could contain text that the LLM will execute as a prompt.
Prompt injections are a risk to all custom AI agents created by organizations that pass third-party data to an LLM, and mitigating them requires a multi-layered approach as no defense is perfect.
See also: New prompt injection attack against AI browsers and browser assistants

**Malicious and Vulnerable MCP Servers** The Model Context Protocol (MCP) has become a standard for how LLMs interact with external data sources and applications to enhance their context for reasoning. The protocol has seen rapid adoption and is a key component in the development of AI agents, with tens of thousands of MCP servers now published online.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
