Skip to content
Book a call

Home / Blog / AI and LLM Security

Category

AI and LLM Security

Prompt injection, AI agents with backend access, function calling without access control, and what an AI layer does to an existing attack surface.

AI and LLM Security

Somebody Wired the Darknet Into Your AI. What Could Go Wrong?

One MCP server packing 66 tools, feeding onion-site content straight into your model's context. The darknet is the most hostile input that exists, and a model cannot tell…

Read it

AI and LLM Security

Every Week Someone Asks Me When AI Will Replace Pentesters

Datadog released a scanner that sends your code to an LLM instead of matching patterns. After 20 years in this field: the engine was never the problem. What…

Read it

AI and LLM Security

Your AI Coding Tool Walks Straight Past Your Defences

A prompt injection hidden in a README, and the tool writes to your zshenv. Every new shell runs the attacker's code. And 40% of the dependencies it recommends…

Read it

AI and LLM Security

It Produced Harmful Output 80% of the Time Without Anyone Even Attacking It

An AI system broke Meta's model in 85% of attempts, in three hours, with no code. The part that should worry you more: just asking politely worked 80%…

Read it

AI and LLM Security

Exposed AI Agents Are the New Shadow IT – Except They Can Act

175,000 Ollama servers exposed to the internet, 8,000 MCP servers wide open, and 31% of those examined answering with no authentication at all. Same film, new cast -…

Read it

AI and LLM Security

Prompt Injection Is the SQL Injection of the AI Era

In 2005 everyone built websites and few asked what happens if someone injects code into a text field. Today everyone builds AI agents, and few ask what happens…

Read it

AI and LLM Security

AI Wrote the Code. The CVE Is Still Yours.

Researchers traced real CVEs back through git blame to the commit that introduced them, then checked whether AI wrote it. Code that arrives looking perfect is exactly the…

Read it

AI and LLM Security

Is Your AI Secure? The Dark Reality of LLM Vulnerabilities

Cyber attacks targeting large language model (LLM) based applications are increasing in both frequency and sophistication. Misconfigured chatbots, exposed APIs, and weak integrations with web, cloud, and mobile…

Read it

AI and LLM Security

AI-Driven Penetration Testing For Evolving Threats: A CISO Guide

Cyber threats don’t wait for next quarter’s test cycle. Verizon DBIR 2025 coverage shows attackers exploit vulnerabilities in about 5 days on average, while organizations take a median…

Read it

AI and LLM Security

The Attack Surface Used to Be Code. Now Part of It Is a Conversation.

A scanner for MCP servers sent me down a longer thought. We are used to an attack surface made of code, configuration and permissions. Some of it is…

Read it

Tell us what the system does and what worries you.

If a penetration test is not what you need yet, we will say so.

Book a scoping call See the test catalogue