VNVũ Nhật Lâminblog.fiscybersec.com·Aug 6 · 20 min readAgent Data Injection: Fooling AI Agents With the Data They Already TrustRisk Summary You ask a web agent to summarize the reviews on a product page. A fake review planted by an attacker makes it click "Buy Now" instead, and an order goes through. No malware, no phishing, 00
VNVũ Nhật Lâminblog.fiscybersec.com·Jun 23 · 12 min readGemini's Secret Affair: Notification-Based Prompt Injection and the Fake Context Alignment TechniqueA single WhatsApp message from an unknown number is enough to turn the Gemini voice assistant into an attacker's tool — opening the smart windows in a victim's home, live-streaming their video over Zo00
JJebitokinsharonjebitok.com·May 9 · 13 min readRAG Security Fundamentals (TryHackMe)Introduction Retrieval-Augmented Generation (RAG) allows language models to use external documents when answering questions. Instead of relying solely on training data, a RAG system retrieves relevant00
JJebitokinsharonjebitok.com·May 8 · 10 min readSecuring AI Systems (TryHackMe)Introduction TryTrainMe's engineering team has built TryAssist, an AI-powered code review assistant that analyses pull requests, queries internal documentation, and connects to the CI/CD pipeline. Bef00
TPTatiane Pimenta Lealintatianepimentaleal.hashnode.dev·Mar 1 · 5 min readMITRE ATLAS and OWASP | API Security in the Age of LLMArtificial Intelligence, or AI, is an inevitable topic nowadays, not only for its formidable growth in speed, features, capabilities, and general use, but also for its flaws and ethical concerns. In t00