AI-BOMs Introduced to Combat Shadow AI Threats in Enterprises
Article Content
- •AI-BOMs are designed to provide visibility into AI assets in enterprise environments.
- •The rise of shadow AI complicates security, as unsanctioned tools may expose sensitive data.
- •Cisco's open-source AI-BOM tool helps organizations identify and manage their AI components.
As AI applications proliferate in enterprise environments, traditional software bills of materials (SBOMs) are inadequate for tracking all components. The introduction of AI-BOMs aims to provide comprehensive visibility into AI assets, including models, datasets, and tools. This new approach addresses the challenges posed by 'shadow AI,' which encompasses unsanctioned tools and applications used by employees. Cisco has open-sourced its AI-BOM tool to help organizations identify AI assets and their interconnections. Additionally, Cisco released a Model Provenance Kit to track AI model origins and similarities. The urgency for organizations to understand their AI environments is underscored by the potential risks associated with unknown AI components. This shift highlights the need for enhanced security measures as enterprises increasingly rely on AI technologies.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Shai-hulud in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
UAC-0099 Uses GuardBreaker to Evade AI Malware Detection Russian-linked hackers from the group UAC-0099 have developed a new technique called GuardBreaker to evade AI-assisted malware analysis. This method involves embedding a nuclear weapon prompt in malicious VBS scripts, which distracts AI systems from analyzing the actual malware code. The script is designed to download…
Jade Sleet Targets Indian IT Firm with FLATROOF and ROOFDECK Backdoors North Korean threat actor Jade Sleet has been linked to the compromise of a small Indian IT services organization, focusing on developers to infiltrate networks. The attack utilized macOS backdoors known as FLATROOF and ROOFDECK, previously seen in Web3 sector attacks. The campaign involved social engineering tactics…