MSSP, AI benefits/risks, Generative AI, Application security, DevSecOps, Attack surface management, Identity, Network Security, SOC

Palo Alto Partners with Google Cloud as AI-Fueled Threats Expand

The distributed nature of cloud computing and its continued adoption by enterprises have expanded the attack surface for many organizations and driven trends like alert fatigue among security teams. Cybersecurity teams are now seeing how AI, while enabling such security-friendly capabilities like real-time threat detection, automated response, and predictive risk analysis, is also adding new cyber risks to cloud environments and putting further pressure on security teams.

Palo Alto Networks, in its recently released State of Cloud Security Report 2025, laid out the threats that the rapid adoption of AI, which the vendor said is driving an “unprecedented surge” in cloud security risks and a “massive expansion” of the attack surface.

“We found that 99% of organizations experienced at least one attack on their AI systems within the past year, and the acceleration of GenAI-assisted coding is outstripping security teams’ capacity to keep pace,” Cody Queen, senior product marketing manager for Cortex, Palo Alto’s AI-powered, cloud-native SecOps platform, wrote in a blog post. “What’s missing isn't just visibility, it’s alignment.”

Days after the report was released, Palo Alto – which in October grew its security portfolio – made a move to help harden cloud security in the age of AI, expanding its partnership with Google Cloud in a reported $10 billion security services deal that will see the companies integrating security into how AI workloads are built and deployed.

That includes providing security for live AI workloads and data in Google Cloud tools such as Vertex AI and Agent Engine, secure developer tools like Agent Development Kit (ADK) using Prisma AIRS – Palo Alto’s AI runtime security platform – and more deeply integrating its VM-Series firewalls and Prisma SASE (secure access service edge) with Google Cloud.

"Every board is asking how to harness AI's power without exposing the business to new threats,” Palo Alto President BJ Jenkins said in a statement. “This partnership answers that question.”

Pressure on Enterprises, MSSPs

Such moves are important for enterprises, smaller businesses, and MSSPs as the use of AI in the cloud continues to grow, according to Jessica Davis, principal analyst with Omdia’s managed services practice.

“AI is expanding the cloud attack surface by increasing the speed, scale, and complexity of cloud activity, especially around identity, APIs, and ephemeral workloads,” Davis told MSSP Alert. “There’s more risk, and it’s moving faster than ever before.”

The challenge for MSSPs “is closing these gaps without increasing operational noise and cost,” she said. “That means making visibility into human and machine identities a top priority, and using automation to prioritize risk and enforce policy, rather than simply generating more alerts.”

AI and Cloud Security

Palo Alto’s report, based on a survey of more than 2,800 security executives and experts around the world, highlighted the rapid adoption of AI and the growing risks that it carries. About 75% of organizations said they are running AI in a production environment, a number Palo Alto’s Queen wrote is significant.

“It points to the growing adoption and use of AI as businesses are locked in what looks like a modern arms race to bring the latest capabilities and benefits to their organizations and customers,” he wrote, pointing to the 99% of organizations that reported at least one attack on their AI systems. “This number proves that AI needs human guardrails, as well as to be secured to contain the risk of critical data exposure by adversaries.”

Code development pipelines are facing the same stressors, he wrote, noting that 99% of respondents said they use generative AI-assisted coding – or vibe coding – which creates insecure code faster than security teams can review it. About 52% of teams are shipping code every week, but only 18% are able to fix vulnerabilities at such a pace. Security teams can’t adequately defend against threats with manual fix cycles and fragmented tools.

“As the pace of development increases, the disconnect between security assessment and remediation is becoming more apparent, too,” Queen wrote. “While teams are making progress by shifting away from outdated vulnerability prioritization methods, they still struggle to integrate security effectively into the development workflow.”

The result is 20% of organizations reporting that 37% of their high or critical issues reach production environments, and once in production, 82% said it’s taking more than a week to deploy code fixes. ... The traditional refrain toward implementing prevention that blocks risks from reaching production during rapid code development is still true today.”

Exploiting Foundational Layers

Palo Alto also highlighted trends showing how threat actors are exploiting foundation layers of the cloud, noting that the volume and autonomy that AI agents bring are accelerating the exploitation efforts. For example, attacks on APIs – key to agentic AI – jumped 41% over the past year, expanding the attack surface.

The report also notes that 53% of organizations said lenient identity and access management (IAM) practices are leading to more credential threats and data exfiltration, a number that rises to 57% for companies running more than six AppSec tools

The ongoing gap between the detection of threats and their resolution is helping to enable breaches, Queen wrote.

“Today the cloud and SOC [security operations center] divide is proving too slow in the face of machine-speed threats,” he wrote. “Structural fragmentation is clearly visible in response times, while 74% of organizations detect threats within 24 hours, 30% take more than a full day to resolve them. A delay like this is caused by disjointed workflows and isolated data sources between cloud and SOC teams, which stall incident response for 50% of organizations.”

Organizations are recognizing this, with 89% saying cloud security and security operations must fully merge, not just integrate, and 97% of respondents prioritizing consolidating their security footprint to address the chaos of tool sprawl.

Jeffrey Burt

Jeffrey Burt has been a journalist for almost 40 years, moving from general-circulation newspapers to IT news sites in 2000. He’s an expert analyst and writer on cybersecurity, data center infrastructure, AI, and a host of other subjects for a range of organizations, including CyberRisk Alliance, eWEEK, Techstrong Group, The Next Platform, and The Register.

You can skip this ad in 5 seconds