Three AI Attack Surfaces Now Compound in Your Cloud

Veracode tested over 100 large language models on security-sensitive coding tasks and found that 45% of the code they produced introduced OWASP Top 10 vulnerabilities — a pass rate that did not improve across multiple testing cycles. That single number explains why AI in 2026 did not add one attack …

68% of Your AI Runs on Software You Never Approved

Sixty-eight percent of organizations running self-hosted AI ingest those models transitively through third-party software, according to Wiz’s State of AI in the Cloud 2026 report. The models your platform team approved are not the only models running in your environment — and those unattributed calls bypass your LLM gateway, evade …