Hong Kong: AI infrastructure security risks are becoming a growing concern, according to global cybsecurity company Trend Micro’s new study. The report urges AI engineers and IT leaders to adopt best practices when developing and deploying AI systems, warning that failure to do so could lead to data theft, system poisoning, ransom demands and other cyber threats.
The findings highlight a sharp rise in AI infrastructure security risks, especially due to unsecured and unpatched components used across various stages of development.
“AI may represent the opportunity of the century for global businesses. But those rushing in too fast without taking adequate security precautions may end up causing more harm than good,” said Rachel Jin, Trend Micro’s Chief Enterprise Platform Officer.
“Too much AI infrastructure is already being built from unsecured and/or unpatched components, creating an open door for threat actors,” added Jin.
The report identifies four major security challenges affecting current AI systems:
Vulnerabilities in critical components
AI applications often rely on multiple software frameworks that may carry the same types of vulnerabilities as standard software. Trend’s research discovered zero-day exploits in key components including ChromaDB, Redis, NVIDIA Triton and NVIDIA Container Toolkit.
Accidental internet exposure
AI systems are being accidently exposed online to vulnerabilities from poorly, managed timelines and rushed deployments. More than 200 ChromaDB servers, 2,000 Redis servers and over 10,000 Ollama servers were found accessible on the internet without authentication, the report revealed.
Open-source component vulnerabilities
While widely used in AI development, open-source libraries often include undetected flaws. At the recent Pwn2Own Berlin competition, one exploit was traced to an outdated Lua component within a Redis vector database.
Container-based weaknesses
As AI systems frequently run on container platforms, they inherit the same security issues found in cloud environments. Pwn2Own researchers successfully demonstrated an exploit targeting the NVIDIA Container Toolkit, further emphasising the need for strict input sanitisation and runtime monitoring.
“There are still lots of questions around AI models and how they could and should be used,” NHS SLAM CTO Stuart MacLellan commented on the implications for enterprises.
“We now get much more information than we ever did about the visibility of devices and what applications are being used. It’s interesting to collate that data and get dynamic, risk-based alerts on people and what they’re doing depending on policies and processes. That’s going to really empower the decisions that are made organisationally around certain products,” said MacLellan
