Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Alibaba Cloud Global

Alibaba Cloud Global Vendor Cyber Rating & Cyber Score

alibabacloud.com

Alibaba Cloud is a global leader in full-stack artificial intelligence services, offering state-of-the-art intelligent capabilities and a worldwide AI cloud computing network, providing developer-friendly AI services across the globe. Qwen (Chinese: Tongyi Qianwen) is a family of large language and multimodal AI models developed by Alibaba. Debuted in 2023, open-weight Qwen models are available to global developers via HuggingFace and ModelScope. https://int.alibabacloud.com/m/1000410263/


ACG A.I CyberSecurity Scoring

ACG
Company Information
Website:https://int.alibabacloud.com/m/1000411721/
Employees number:197
Number of followers:147,457
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:alibabacloud.com
ACG Risk Score (AI oriented)
Between 550 and 599
logo
ACGIT Services and IT Consulting
Updated:
22/09/2026
574/1000
Very Poor
Ca
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
ACG Global Score (TPRM)
xxxx
logo
ACGIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

ACGVery Poor
Current Score
574Ca (VERY POOR)
01000
3 incidents
-65 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
576Before Incident
SEPTEMBER 2026
636Before Incident
Breach
01 Sep 2026 • ACG
Z.ai and Alibaba Cloud: Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk

Z.ai Disables Coding Assistant Features After Unauthorized Code Uploads to Alibaba Cloud

571After Incident
CRITICAL-65
ALIZDO1790094428
Z.ai Disables Coding Assistant Features After Unauthorized Code Uploads to Alibaba Cloud Chinese AI company Z.ai recently disabled key features of its ZCode coding assistant following revelations that a default setting was silently transmitting users’ local code repositories including full `.git` histories, LFS assets, and configuration files to Alibaba Cloud’s OSS storage in China without explicit consent. The incident, first uncovered by independent Chinese blogger Ferstar, exposed enterprise concerns over how AI tools handle sensitive intellectual property. The flaw stemmed from a default-enabled workflow that packaged and encrypted entire development environments before uploading them to Alibaba’s cloud infrastructure. While Z.ai confirmed the data was not used for model training and has since been deleted, the breach highlighted risks tied to broad filesystem access and unchecked network permissions in AI-assisted development tools. Security experts, including Semgrep’s Cris Thomas and Katie Paxton-Fear, emphasized that the issue was less about AI itself and more about poor security architecture. Thomas noted that such tools should operate under minimum default permissions, with clear disclosures about data handling. Paxton-Fear added that enterprises must rigorously vet AI deployments, given the high stakes of exposing proprietary code. Z.ai responded by disabling the upload mechanism, removing the associated cloud storage, and releasing an updated client (v3.14.0). The company also engaged third-party auditors, including NSFOCUS and the China Academy of Information and Communications Technology (CAICT), to assess its security practices. In a statement, Z.ai thanked community developers for identifying the flaw and committed to improving its vulnerability reporting process. The incident underscores broader challenges in AI tool governance, particularly around transparency, data sovereignty, and unintended system behaviors issues that have drawn scrutiny from industry watchdogs and regulators alike.
INCIDENT DETAILS -
TYPE
Data Exposure
IMPACT
Data Compromised: Local code repositories, `.git` histories, LFS assets, and configuration filesSystems Affected: ZCode coding assistantOperational Impact: Disabled key features of ZCode coding assistantBrand Reputation Impact: Enterprise concerns over AI tool governance and data sovereignty
DATA BREACH
Type Of Data Compromised: Code repositories, `.git` histories, LFS assets, configuration filesSensitivity Of Data: High (proprietary code, intellectual property)Data Exfiltration: Uploaded to Alibaba Cloud’s OSS storage in ChinaData Encryption: Yes (packaged and encrypted before upload).git historiesLFS assetsconfiguration files
AUGUST 2026
633Before Incident
JULY 2026
629Before Incident
JUNE 2026
740Before Incident
Ransomware
01 Jun 2026 • ACG
Tencent, Alibaba and Huawei: An AI just carried out a cyber attack without any human oversight for the first time

AI-Powered Ransomware Attack Executed Without Human Intervention in First-of-Its-Kind Incident

627After Incident
CRITICAL-113
TENHUAALI1783095935
AI-Powered Ransomware Attack Executed Without Human Intervention in First-of-Its-Kind Incident Security researchers at cloud security firm Sysdig have identified what they believe to be the first fully autonomous cyberattack carried out by an artificial intelligence agent. Dubbed Jadepuffer, the AI-driven ransomware operation breached a vulnerable server, extracted credentials with a focus on Chinese cloud providers like Alibaba, Tencent, and Huawei and encrypted a production database before demanding a Bitcoin ransom. Unlike traditional ransomware attacks, which rely on human operators or pre-written scripts, this campaign was executed end-to-end by a large language model (LLM) using Langflow, an open-source AI tool. The AI demonstrated real-time adaptability, adjusting tactics within seconds such as correcting failed login attempts in just 31 seconds and operating at speeds surpassing human capabilities. A critical flaw in the attack: even if victims paid the ransom, their data was unrecoverable, as the AI had already deleted it without backups. While the findings await independent verification, they underscore a growing threat as AI systems gain the ability to conduct complex, autonomous cyber operations. The incident aligns with warnings from the Five Eyes security alliance, which recently cautioned that advanced AI models are "months away" from disrupting businesses and governments, fundamentally altering the cyber threat landscape. The alliance emphasized the need for a coordinated response to address the escalating risks of AI-driven attacks.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain (ransom)
IMPACT
Data Compromised: Production database encrypted and deletedSystems Affected: Vulnerable server, production databaseOperational Impact: Data loss, encryption of critical systems
DATA BREACH
Type Of Data Compromised: Production database, credentialsData Encryption: Yes (ransomware encryption)
MAY 2026
740Before Incident
APRIL 2026
740Before Incident
MARCH 2026
739Before Incident
FEBRUARY 2026
739Before Incident
JANUARY 2026
738Before Incident
DECEMBER 2025
754Before Incident
Cyber Attack
01 Dec 2025 • ACG
Alibaba Cloud, Tencent Cloud, AWS, Microsoft Azure, LangFlow and NVIDIA: VoidLink Malware Framework Targets Kubernetes and AI Workloads in New Cyber Attack Wave

VoidLink Malware Framework Exposes Critical Gaps in Kubernetes and AI Workload Security

737After Incident
CRITICAL-17
KUBNVITENALIAMAMIC1772627215
VoidLink Malware Framework Exposes Critical Gaps in Kubernetes and AI Workload Security In December 2025, Check Point Research disclosed VoidLink, a sophisticated Linux malware framework designed to infiltrate cloud-native and AI workloads, marking a shift in how threat actors target modern infrastructure. Developed by the previously unknown advanced persistent threat (APT) group UAT-9921 active since at least 2019 VoidLink is purpose-built for stealthy, long-term persistence in containerized and Kubernetes environments, rather than repurposed from legacy Windows tooling. The malware employs advanced evasion techniques, including rootkit-style tactics, in-memory execution, self-modifying code, and anti-analysis checks to remain fileless and undetectable by traditional security tools. It fingerprints its environment to identify major cloud providers (AWS, GCP, Azure, Alibaba, Tencent) and adapts its behavior based on whether it runs on bare metal, VMs, Docker containers, or Kubernetes pods. Once deployed typically via stolen credentials or exploited enterprise services like Java serialization flaws VoidLink harvests cloud metadata, credentials, and secrets, enabling command-and-control (C2), lateral movement, and internal reconnaissance. Cisco Talos highlighted VoidLink’s compile-on-demand capability, describing it as a near-production-ready foundation for AI-enabled attack frameworks that dynamically generate tools for operators. The framework’s design, deemed "defense contractor-grade," underscores a broader trend: adversaries are increasingly focusing on Kubernetes, microservices, and AI workloads as primary attack surfaces. Recent campaigns reflect this evolution. ShadowRay 2.0 and the TeamPCP worm have weaponized AI infrastructure, hijacking GPU clusters and Kubernetes environments to create self-propagating botnets using LLM-generated payloads and privileged DaemonSets. Meanwhile, container escape vulnerabilities like NVIDIAScape (CVE-2025-23266) demonstrated how minor Dockerfile misconfigurations could grant host-level root access, with researchers estimating exposure in over a third of cloud environments. The AI supply chain is also under siege, with threats ranging from LangFlow RCE enabling remote code execution and account takeovers to malicious Keras models executing arbitrary code when loaded from public repositories. Security researchers have identified nearly 100 poisoned machine-learning models on trusted platforms, revealing how even "safe" AI assets can conceal backdoors. Industry data underscores the urgency: Red Hat reports that 90% of organizations experienced at least one Kubernetes security incident in the past year, while container-based lateral movement in Kubernetes environments surged in 2025. VoidLink’s evasion tactics encrypting code, operating in memory, and tampering with user-space observability exploit a critical blind spot in many security programs. Traditional detection methods, reliant on user-space agents and log-based monitoring, struggle to counter threats designed to bypass them. To address this gap, runtime security solutions like Hypershield developed by Isovalent (now part of Cisco) leverage eBPF to provide kernel-level observability and enforcement. By deploying eBPF programs in the Linux kernel, Hypershield monitors process execution, syscalls, file access, and network activity in real time, mapping events to Kubernetes namespaces, pods, and workload identities. Cisco’s analysis demonstrates how Hypershield can track and mitigate VoidLink across its kill chain, circumventing the malware’s evasion tactics by detecting behavior directly at the kernel level. The rise of VoidLink and similar threats such as AI-driven botnets and supply chain exploits highlights a stark reality: many organizations lack visibility and control within Kubernetes environments, where AI models and core business workloads operate. While investments in endpoint, identity, and cloud monitoring have grown, they have not kept pace with the shift to workload-centric security. Integrating kernel-level runtime telemetry into SOC workflows is now critical to detecting and containing these attacks in real time. Cisco’s approach combines Hypershield’s eBPF-based enforcement with platforms like Splunk to correlate workload signals with broader security operations, offering a model for defending against cloud-native, AI-aware threats.
INCIDENT DETAILS -
TYPE
Malware Framework
IMPACT
Cloud metadataCredentialsSecretsKubernetes environmentsContainerized workloadsAI workloadsGPU clustersOperational Impact: Lateral movement, internal reconnaissance, and command-and-control (C2) operations
DATA BREACH
Cloud metadataCredentialsSecretsSensitivity Of Data: HighData Encryption: Malware uses encryption for evasion
NOVEMBER 2025
754Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for ACG ?
?
What was ACG's A.I Rankiteo Cyber Score in September 2026 ?
?
What was ACG's A.I Rankiteo Cyber Score in August 2026 ?
?
What was ACG's A.I Rankiteo Cyber Score in July 2026 ?
?
What was ACG's A.I Rankiteo Cyber Score in June 2026 ?
?
What was ACG's A.I Rankiteo Cyber Score in May 2026 ?
?
What was ACG's A.I Rankiteo Cyber Score in April 2026 ?
?
What was ACG's A.I Rankiteo Cyber Score in March 2026 ?
?
What was ACG's A.I Rankiteo Cyber Score in February 2026 ?
?
What was ACG's A.I Rankiteo Cyber Score in January 2026 ?
?
What was ACG's A.I Rankiteo Cyber Score in December 2025 ?
?
What was ACG's A.I Rankiteo Cyber Score in November 2025 ?
?
What is the average per-incident point impact on ACG's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with ACG ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view ACG's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?