By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
AIModelKitAIModelKitAIModelKit
  • Home
  • News
    NewsShow More
    SpaceXAI’s Grok Tool Uploading Users’ Entire Codebase to Cloud Storage: What You Need to Know
    SpaceXAI’s Grok Tool Uploading Users’ Entire Codebase to Cloud Storage: What You Need to Know
    4 Min Read
    New York Leads the Way: First State to Enforce One-Year Moratorium on New AI Data Centers
    New York Leads the Way: First State to Enforce One-Year Moratorium on New AI Data Centers
    4 Min Read
    AI Replacing New York Nurses: Why Patients Should be Concerned About Quality of Care
    AI Replacing New York Nurses: Why Patients Should be Concerned About Quality of Care
    5 Min Read
    Navigating AI Agent Crawlers and Cloudflare’s New Rules: A Comprehensive Guide
    Navigating AI Agent Crawlers and Cloudflare’s New Rules: A Comprehensive Guide
    5 Min Read
    How Apple’s Self-Driving Car Program Paved the Way for Advanced AI Chip Technology
    How Apple’s Self-Driving Car Program Paved the Way for Advanced AI Chip Technology
    4 Min Read
  • Open-Source Models
    Open-Source ModelsShow More
    GlucoFM: Advanced Foundation Model for Continuous Glucose Monitoring Insights
    GlucoFM: Advanced Foundation Model for Continuous Glucose Monitoring Insights
    5 Min Read
    AgentHands: Creating Interactive Hand Gestures for Enhanced Conversations with Spatially Grounded Agents in XR
    AgentHands: Creating Interactive Hand Gestures for Enhanced Conversations with Spatially Grounded Agents in XR
    5 Min Read
    Exploring How Mobility Enhances Language Models’ Understanding of Location
    Exploring How Mobility Enhances Language Models’ Understanding of Location
    5 Min Read
    Optimize Candidate Biomarkers with Our AI Tool for Wearable Sensor Data Analysis
    Optimize Candidate Biomarkers with Our AI Tool for Wearable Sensor Data Analysis
    4 Min Read
    Beyond BMI: Assessing Cardiometabolic Risk Using Smartphone Images
    Beyond BMI: Assessing Cardiometabolic Risk Using Smartphone Images
    5 Min Read
  • Guides
    GuidesShow More
    Your Comprehensive Guide to Practical Constraint Decoding: Basics and Applications
    Your Comprehensive Guide to Practical Constraint Decoding: Basics and Applications
    6 Min Read
    KDnuggets Weekly Data Science News Roundup: Highlights from July 20, 2026
    KDnuggets Weekly Data Science News Roundup: Highlights from July 20, 2026
    4 Min Read
    Unlock Your AI Potential with Kaggle and Google’s Free 5-Day Agentic AI Course
    Unlock Your AI Potential with Kaggle and Google’s Free 5-Day Agentic AI Course
    6 Min Read
    Top 5 High-Performance MCP Servers for Optimal Agentic Development
    Top 5 High-Performance MCP Servers for Optimal Agentic Development
    6 Min Read
    Top 5 Free Resources for Understanding Agentic AI: Unlock Your Knowledge
    Top 5 Free Resources for Understanding Agentic AI: Unlock Your Knowledge
    6 Min Read
  • Tools
    ToolsShow More
    Unlock Agentic Coding: Experimenting with Qwen 3.8-Flash-Next on NVIDIA GB300 NVL72
    Unlock Agentic Coding: Experimenting with Qwen 3.8-Flash-Next on NVIDIA GB300 NVL72
    6 Min Read
    Unlock Agentic Coding: Experimenting with Qwen 3.8 Flash-Next 176B Model on NVIDIA GB300 NVL72
    Unlock Agentic Coding: Experimenting with Qwen 3.8 Flash-Next 176B Model on NVIDIA GB300 NVL72
    5 Min Read
    Optimizing LFM2.5 Q4_0 Checkpoints through Quantization-Aware Distillation Techniques
    Optimizing LFM2.5 Q4_0 Checkpoints through Quantization-Aware Distillation Techniques
    4 Min Read
    Deploy Qwen 3.8-2.4T-A95B: A Configurable 2.4T Parameter Model on NVIDIA GB300 NVL72 for Enhanced Reasoning
    Deploy Qwen 3.8-2.4T-A95B: A Configurable 2.4T Parameter Model on NVIDIA GB300 NVL72 for Enhanced Reasoning
    6 Min Read
    Optimize Your AI Models with Baseten on Hugging Face Inference Providers 🔥
    Optimize Your AI Models with Baseten on Hugging Face Inference Providers 🔥
    5 Min Read
  • Events
    EventsShow More
    Exploring the Future of EdTech: Highlights from the ‘Best of ISTE’ Virtual Playground
    Exploring the Future of EdTech: Highlights from the ‘Best of ISTE’ Virtual Playground
    4 Min Read
    Empowering Veteran Students: Effective Teaching Strategies in Technology and Learning
    Empowering Veteran Students: Effective Teaching Strategies in Technology and Learning
    4 Min Read
    NVIDIA Partners with NSF to Enhance AI Research and Education Through State and Regional AI Hubs Across the US
    NVIDIA Partners with NSF to Enhance AI Research and Education Through State and Regional AI Hubs Across the US
    5 Min Read
    South Korea Unveils AI Future at AI Summit with NVIDIA and Strategic Partners
    South Korea Unveils AI Future at AI Summit with NVIDIA and Strategic Partners
    5 Min Read
    NVIDIA Launches First Open-Source GPU-Accelerated Framework for Medical Physics Simulations
    NVIDIA Launches First Open-Source GPU-Accelerated Framework for Medical Physics Simulations
    5 Min Read
  • Ethics
    EthicsShow More
    AI Giants Warn: Impending Cybersecurity Crisis Looms in Just Months
    AI Giants Warn: Impending Cybersecurity Crisis Looms in Just Months
    6 Min Read
    Assessing the Environmental Impact of Data Centres: Are We Finally Acknowledging the Consequences?
    Assessing the Environmental Impact of Data Centres: Are We Finally Acknowledging the Consequences?
    5 Min Read
    Survey Reveals Surprising Impact of AI on Job Losses: Insights from Workers
    Survey Reveals Surprising Impact of AI on Job Losses: Insights from Workers
    6 Min Read
    Understanding DAO-to-DAO Voting: On-Chain and Off-Chain Mechanisms Explored
    Understanding DAO-to-DAO Voting: On-Chain and Off-Chain Mechanisms Explored
    5 Min Read
    Taiwan Prosecutes Nine Individuals for Smuggling Advanced AI Servers to China: A Tech Industry Update
    Taiwan Prosecutes Nine Individuals for Smuggling Advanced AI Servers to China: A Tech Industry Update
    4 Min Read
  • Comparisons
    ComparisonsShow More
    InternBootcamp: Enhancing LLM Reasoning Through Verifiable Task Scaling Techniques
    InternBootcamp: Enhancing LLM Reasoning Through Verifiable Task Scaling Techniques
    4 Min Read
    Enhancing Anomaly Detection in Collider Experiments through Contrastive Learning for Better Interpretability
    Enhancing Anomaly Detection in Collider Experiments through Contrastive Learning for Better Interpretability
    6 Min Read
    Exploring the Impact of Quantization on Self-Explanations in Large Language Models: Can LLMs Explain Themselves?
    Exploring the Impact of Quantization on Self-Explanations in Large Language Models: Can LLMs Explain Themselves?
    5 Min Read
    CytoNet: A Foundation Model for Understanding the Human Cerebral Cortex at Cellular Resolution
    CytoNet: A Foundation Model for Understanding the Human Cerebral Cortex at Cellular Resolution
    5 Min Read
    Optimizing Nonconvex-Nonconcave Min-Max Problems with a Limited Maximization Domain: Insights from [2110.03950]
    Optimizing Nonconvex-Nonconcave Min-Max Problems with a Limited Maximization Domain: Insights from [2110.03950]
    5 Min Read
Search
  • Privacy Policy
  • Terms of Service
  • Contact Us
  • FAQ / Help Center
  • Advertise With Us
  • Latest News
  • Model Comparisons
  • Tutorials & Guides
  • Open-Source Tools
  • Community Events
© 2025 AI Model Kit. All Rights Reserved.
Reading: Security Gaps Exposed in the Global AI Race: Addressing Critical Vulnerabilities
Share
Notification Show More
Font ResizerAa
AIModelKitAIModelKit
Font ResizerAa
  • 🏠
  • 🚀
  • 📰
  • 💡
  • 📚
  • ⭐
Search
  • Home
  • News
  • Models
  • Guides
  • Tools
  • Ethics
  • Events
  • Comparisons
Follow US
  • Latest News
  • Model Comparisons
  • Tutorials & Guides
  • Open-Source Tools
  • Community Events
© 2025 AI Model Kit. All Rights Reserved.
AIModelKit > News > Security Gaps Exposed in the Global AI Race: Addressing Critical Vulnerabilities
News

Security Gaps Exposed in the Global AI Race: Addressing Critical Vulnerabilities

aimodelkit
Last updated: November 11, 2025 9:14 pm
aimodelkit
Share
Security Gaps Exposed in the Global AI Race: Addressing Critical Vulnerabilities
SHARE

The Urgent Need for Enhanced Security Practices in the AI Sector

As the race among AI companies heats up, a concerning trend has emerged: many organizations are ignoring foundational cybersecurity hygiene, leading to significant vulnerabilities. A recent report by Wiz highlights that 65% of the top 50 AI firms analyzed have leaked verified secrets via platforms like GitHub. This situation poses severe risks, with potentially damaging ramifications for companies and their clients.

Contents
  • Exposed Secrets: A Growing Concern
  • Supply Chain Security Risks
  • Inadequacies of Traditional Security Scanning
    • Depth
    • Perimeter
    • Coverage
  • Security Maturity Gaps
  • Immediate Action Items for AI Firms

Exposed Secrets: A Growing Concern

Among the types of sensitive information at risk, API keys, tokens, and credentials have been found hidden within code repositories—often overlooked by standard security tools. Glyn Morgan, Country Manager for UK&I at Salt Security, aptly describes these lapses as preventable errors that clearly demonstrate a lack of effective governance and security configurations. According to Morgan, accidentally exposing API keys presents "a glaring avoidable security failure" that invites attackers to exploit otherwise secured systems.

Supply Chain Security Risks

Wiz’s report sheds light on the expanding complexities of supply chain security risks in the AI landscape. Given the increasing collaboration between established enterprises and innovative AI startups, companies may inadvertently adopt the security flaws of their partners. The leaks discovered could potentially expose organizational structures, proprietary training data, and even proprietary AI models.

The financial stakes for these firms are substantial, with a combined valuation exceeding $400 billion. Examples of significant hackers’ targets include:

  • LangChain, which exposed multiple Langsmith API keys, some granting access to manage the organization and list its members.
  • An enterprise-tier API key for ElevenLabs was discovered simply sitting in a plaintext file, creating a significant vulnerability.
  • An unnamed AI 50 company had a HuggingFace token exposed in a deleted code fork, allowing access to around 1,000 private models. This same company also leaked keys for WeightsAndBiases, putting training data at risk.

Inadequacies of Traditional Security Scanning

Wiz’s findings emphasize that conventional security scanning techniques are no longer sufficient. The report criticizes the reliance on basic scans of a company’s main GitHub repositories as a "commoditized approach," which fails to uncover critical risks.

More Read

Pickle Robot Appoints Former Tesla Executive as First CFO to Drive Financial Strategy
Pickle Robot Appoints Former Tesla Executive as First CFO to Drive Financial Strategy
Nvidia CEO Jensen Huang Highlights Powerful Processor in Upcoming Nintendo Switch 2
OpenAI Aims to Develop a Best-in-Class ‘Open’ AI Model for Enhanced Performance
Apple Considers Integrating Perplexity and Other AI-Powered Search Engines into Safari
Nvidia’s AI Chips Banned in China: Impacts and Implications

Researchers liken the situation to an iceberg, where the most visible issues represent only a fraction of the actual risks. To effectively identify hidden threats, Wiz implemented a unique three-dimensional scanning methodology known as Depth, Perimeter, and Coverage:

Depth

The depth scan scrutinizes the entire commit history, including forks, deleted code, and workflow logs—areas typically ignored by standard scanners.

Perimeter

The perimeter scanning encompasses not only the primary company organization but also its members and contributors. Individual contributors may inadvertently expose company-related secrets in their own public repositories. Wiz’s team utilized techniques to trace code contributors and identify related accounts on platforms like HuggingFace and npm.

Coverage

Finally, the coverage aspect of the scan focuses on identifying new AI-related secret types often overlooked by conventional detection methods, such as keys for services like WeightsAndBiases, Groq, and Perplexity.

Security Maturity Gaps

The expanded attack surface showcased in the report raises alarms, particularly given the evident lack of security maturity in numerous fast-evolving companies. Alarmingly, when efforts were made to disclose the leaks, nearly half of the notifications went unanswered or failed to reach the intended recipients. Many firms lack official disclosure channels, indicating poor responsiveness to security issues.

Immediate Action Items for AI Firms

Wiz offers critical recommendations for enterprise technology executives to bolster their security infrastructures amid emerging risks. These include:

  1. Incorporating Security Awareness During Onboarding

    • Security leaders should treat employees as integral to their organization’s attack surface. A well-defined Version Control System (VCS) member policy should be established during onboarding. This policy must include mandatory practices such as multi-factor authentication for personal accounts and a strict separation between personal and official activities on platforms like GitHub.
  2. Evolving Internal Secret Scanning

    • Companies need to move beyond basic repository checks for internal secret scanning. It is crucial to adopt the Depth, Perimeter, and Coverage approach to uncover hidden threats to safeguard the organization effectively.
  3. Extending Scrutiny to the AI Supply Chain
    • When evaluating potential tools from AI vendors, Chief Information Security Officers (CISOs) must inquire about the vendors’ secret management and vulnerability disclosure practices. The report notes a trend among AI service providers leaking their own API keys, calling for prioritized detection of their specific secret types.

The current landscape underscores a critical reality: the tools and technologies driving the next generation of innovation are often developing at a pace that outstrips security governance. For leaders within AI sectors, it’s imperative to realize that speed must not compromise security; for the enterprises relying on this rapid progression, the same cautionary principle holds true.

By addressing gaps in security practices and enhancing governance measures, the AI community can better protect its assets and maintain trust with its users and partners.

Inspired by: Source

Discover Facebook’s New Feature: AI Can Now Analyze Photos Before You Upload!
Elon Musk Considers Potential Merger of SpaceX with Tesla or xAI: What It Means for the Future
AI Toys Trending in China Now Making Their Debut on US Store Shelves
OpenAI Launches GPT-5.6 Amid Ongoing US AI Regulation Controversies
AI and the Pentagon: Analyzing Killer Robots, Mass Surveillance, and Ethical Boundaries

Sign Up For Daily Newsletter

Get AI news first! Join our newsletter for fresh updates on open-source models.

By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Copy Link Print
Previous Article Using Sentence Space Embedding for Enhanced Classification of Fake News Data Streams Using Sentence Space Embedding for Enhanced Classification of Fake News Data Streams
Next Article Essential Metrics for Evaluating Compositional Text-to-Image Generation Models Essential Metrics for Evaluating Compositional Text-to-Image Generation Models

Stay Connected

XFollow
PinterestPin
TelegramFollow
LinkedInFollow

							banner							
							banner
Explore Top AI Tools Instantly
Discover, compare, and choose the best AI tools in one place. Easy search, real-time updates, and expert-picked solutions.
Browse AI Tools

Latest News

AI Giants Warn: Impending Cybersecurity Crisis Looms in Just Months
AI Giants Warn: Impending Cybersecurity Crisis Looms in Just Months
Ethics
Assessing the Environmental Impact of Data Centres: Are We Finally Acknowledging the Consequences?
Assessing the Environmental Impact of Data Centres: Are We Finally Acknowledging the Consequences?
Ethics
Exploring the Future of EdTech: Highlights from the ‘Best of ISTE’ Virtual Playground
Exploring the Future of EdTech: Highlights from the ‘Best of ISTE’ Virtual Playground
Events
Survey Reveals Surprising Impact of AI on Job Losses: Insights from Workers
Survey Reveals Surprising Impact of AI on Job Losses: Insights from Workers
Ethics
//

Leading global tech insights for 20M+ innovators

Quick Link

  • Latest News
  • Model Comparisons
  • Tutorials & Guides
  • Open-Source Tools
  • Community Events

Support

  • Privacy Policy
  • Terms of Service
  • Contact Us
  • FAQ / Help Center
  • Advertise With Us

Sign Up for Our Newsletter

Get AI news first! Join our newsletter for fresh updates on open-source models.

AIModelKitAIModelKit
Follow US
© 2025 AI Model Kit. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?