JJebitokinsharonjebitok.com·2d ago · 61 min readToken City - AI Odyssey CTF (TryHackMe)Link to the section of the AI Odyssey CTF on TryHackMe: Token City. It covers challenges like: ML Sec: The Loan Arranger | AI Sec + DFIR: Rogue Commit | AI Sec + Web App Sec: Sealed Substation | Agent00
VNVũ Nhật Lâminblog.fiscybersec.com·6d ago · 12 min readGemini's Secret Affair: Notification-Based Prompt Injection and the Fake Context Alignment TechniqueA single WhatsApp message from an unknown number is enough to turn the Gemini voice assistant into an attacker's tool — opening the smart windows in a victim's home, live-streaming their video over Zo00
MSManuela Schrittwieserinneuralstackms.tech·Jun 17 · 14 min readRAG Under Fire: Retrieval Pipeline Vulnerabilities & Indirect Prompt InjectionNeuralStack | MS Tech Blog – Databases & Data Engineering in AI Security Engineering, Part 3 of 4 The Retrieval Pipeline as a Trust Boundary Retrieval-Augmented Generation (RAG) is now the dominant a00
NDNAS Digitalinnasdigital.hashnode.dev·Jun 12 · 8 min readYour Semantic Kernel Agent Has a CVSS 10.0 Vulnerability — And the Patch Doesn't Fully Fix ItOn 7 May 2026, Microsoft disclosed two critical vulnerabilities in Semantic Kernel, the official .NET framework used to build AI agents and LLM-powered applications. One was assigned a CVSS score of 100
NPNarges Pourkamaliinsafeai.blog·Jun 8 · 8 min readPortSwigger's Insights: Understanding Web LLM AttacksPortSwigger has taken an important step towards understanding LLM attacks. I studied this topic and wrote down the key points to better understand it. 1. Fundamental Concepts Learn a little more about74LR
JAJoel A Pinzyberjoe.hashnode.dev·Jun 5 · 10 min readHow I Jailbroke an Autonomous AI Agent — Exposing 12 Tools, 23 API Actions, and Full Infrastructure Write AccessSeverity: P0 · Critical · ResolvedTechnique: Multi-turn contextual prompt chainingVulnerability Chain: Broken Access Control → Indirect Prompt Injection (RAG Poisoning) → Agentic Tool AbuseResult: Per20
AVAnvesh Vishwarajuinanveshtheaisocanalyst.hashnode.dev·Jun 3 · 10 min readWhy Single-Layer LLM Triage Is Dangerous in a SOC — And the Architecture I'm Building to Prevent ItPublished on Hashnode | Anvesh Raju Vishwaraju | June 2026 I came across an article recently that genuinely surprised me. Not because the topic was new to me — but because someone at the same educatio21A
OOmnithiuminomnithium.hashnode.dev·Jun 1 · 16 min readAI Agent Security: Defending Against Prompt Injection in ProductionPrompt injection is not a theoretical concern. It is the most consistently exploited vulnerability class in production AI agent systems today, and the attack surface grows in direct proportion to how 00
NPNarges Pourkamaliinsafeai.blog·May 29 · 2 min readAI Security is far more complex than just tricky prompts! 🚀Recently, I started reviewing an incredible document: the "AI Security Assessment Blueprint". It has truly opened a new window of knowledge for me, answering so many of my deepest questions about AI v00
NPNarges Pourkamaliinsafeai.blog·May 29 · 3 min readAgentic AI Security—How can autonomous agents be hijacked to steal data?You received a normal email. No malicious links. No suspicious attachments. But that single email was enough for your company's AI assistant to silently send all your confidential data to an attacker!00