MSManuela Schrittwieserinneuralstackms.tech·3d ago · 7 min readIdentity & Trust: The Foundation of Secure AI SystemsNeuralStack | MS — AI Security Every security control eventually reduces to two questions: who is acting, and how much should they be believed. Access control answers the first question. Trust calibra00
TSTech Skill Schoolintechskillschool.hashnode.dev·4d ago · 7 min readAI Agents Are Changing Cyber Attacks: What Security Professionals Need to KnowIn early 2026, a mid-sized financial firm experienced something unprecedented. What appeared as a coordinated ransomware attack unfolded in under one hour from initial access to domain-wide encryption00
HSHarshal Shahindelvingwithharshal.hashnode.dev·5d ago · 6 min readOWASP Top 10 for LLM Applications: Security Risks Every AI User Should KnowIntroduction Large Language Models (LLMs) such as ChatGPT, Gemini, Claude, and GitHub Copilot have revolutionized the way individuals and organizations interact with technology. From content creation 00
AGAkshit Gandotrainakshitg.hashnode.dev·Jul 4 · 5 min readThe Anatomy of an LLM Vulnerability: Analyzing the OWASP Top 10 for GenAIThis blog is a part of the #DataAndAI Series When we deploy traditional web applications, we know how to define boundary lines. We validate input formats, we sanitize database queries, and we construc00
AAAevris AIinaevris-mcp.hashnode.dev·Jun 29 · 16 min readAEVRIS and the OWASP LLM Top 10 (2025): An Honest Capability MapThe OWASP Top 10 for Large Language Model Applications (2025 edition) is the most widely referenced framework for understanding AI application security risks. It is the document security teams use to 10
JJebitokinsharonjebitok.com·Jun 26 · 61 min readToken City - AI Odyssey CTF (TryHackMe)Link to the section of the AI Odyssey CTF on TryHackMe: Token City. It covers challenges like: ML Sec: The Loan Arranger | AI Sec + DFIR: Rogue Commit | AI Sec + Web App Sec: Sealed Substation | Agent01S
VNVũ Nhật Lâminblog.fiscybersec.com·Jun 23 · 12 min readGemini's Secret Affair: Notification-Based Prompt Injection and the Fake Context Alignment TechniqueA single WhatsApp message from an unknown number is enough to turn the Gemini voice assistant into an attacker's tool — opening the smart windows in a victim's home, live-streaming their video over Zo00
MSManuela Schrittwieserinneuralstackms.tech·Jun 17 · 14 min readRAG Under Fire: Retrieval Pipeline Vulnerabilities & Indirect Prompt InjectionNeuralStack | MS Tech Blog – Databases & Data Engineering in AI Security Engineering, Part 3 of 4 The Retrieval Pipeline as a Trust Boundary Retrieval-Augmented Generation (RAG) is now the dominant a00
NDNAS Digitalinnasdigital.hashnode.dev·Jun 12 · 8 min readYour Semantic Kernel Agent Has a CVSS 10.0 Vulnerability — And the Patch Doesn't Fully Fix ItOn 7 May 2026, Microsoft disclosed two critical vulnerabilities in Semantic Kernel, the official .NET framework used to build AI agents and LLM-powered applications. One was assigned a CVSS score of 100
NPNarges Pourkamaliinsafeai.blog·Jun 8 · 8 min readPortSwigger's Insights: Understanding Web LLM AttacksPortSwigger has taken an important step towards understanding LLM attacks. I studied this topic and wrote down the key points to better understand it. 1. Fundamental Concepts Learn a little more about74LR