Skip to content
AppSec Labs logo
  • Penetration Testing Services
    • Web Applications
    • SaaS & Multi-Tenant
    • APIs
    • Mobile Apps
    • AI & LLM
  • Our Methodology
    • Attacks & Tests
    • Testing modes
  • About
    • Alumni
    • The Book
  • Careers
  • Blog
  • Contact
  • עברית

Contact us

Have a question or comment? Submit your message through our contact form and a member of our team will get back to you within 24 hours.

    AI and LLM Security

    • Home
    • Blog
    • AI and LLM Security
    AI and LLM Security

    Somebody Wired the Darknet Into Your AI. What Could Go Wrong?

    July 24, 2026 No comments yet

    One MCP server packing 66 tools, feeding onion-site content straight into your model’s context. The darknet is the most hostile input that exists, and a model cannot tell data from instructions.

    AI and LLM Security

    Every Week Someone Asks Me When AI Will Replace Pentesters

    July 18, 2026 No comments yet

    Datadog released a scanner that sends your code to an LLM instead of matching patterns. After 20 years in this field: the engine was never the problem. What they cannot see is.

    AI and LLM Security

    Your AI Coding Tool Walks Straight Past Your Defences

    June 23, 2026 No comments yet

    A prompt injection hidden in a README, and the tool writes to your zshenv. Every new shell runs the attacker’s code. And 40% of the dependencies it recommends carry known vulnerabilities.

    AI and LLM Security

    It Produced Harmful Output 80% of the Time Without Anyone Even Attacking It

    May 27, 2026 No comments yet

    An AI system broke Meta’s model in 85% of attempts, in three hours, with no code. The part that should worry you more: just asking politely worked 80% of the time.

    AI and LLM Security

    Exposed AI Agents Are the New Shadow IT – Except They Can Act

    May 17, 2026 No comments yet

    175,000 Ollama servers exposed to the internet, 8,000 MCP servers wide open, and 31% of those examined answering with no authentication at all. Same film, new cast – with one twist.

    AI and LLM Security

    AI Wrote the Code. The CVE Is Still Yours.

    April 20, 2026 No comments yet

    Researchers traced real CVEs back through git blame to the commit that introduced them, then checked whether AI wrote it. Code that arrives looking perfect is exactly the code we find holes in.

    AI and LLM Security

    Is Your AI Secure? The Dark Reality of LLM Vulnerabilities

    February 23, 2026 AppSec Labs No comments yet

    Cyber attacks targeting large language model (LLM) based applications are increasing in both frequency and sophistication. Misconfigured chatbots, exposed APIs, and weak integrations with web, cloud, and mobile systems can quickly lead to data breaches, ransomware incidents, or service disruptions. To prevent these issues, organizations need focused cyber security services that understand how AI behaves […]

    AI and LLM Security

    AI-Driven Penetration Testing For Evolving Threats: A CISO Guide

    January 11, 2026 AppSec Labs No comments yet

    Cyber threats don’t wait for next quarter’s test cycle. Verizon DBIR 2025 coverage shows attackers exploit vulnerabilities in about 5 days on average, while organizations take a median of 32 days to fully remediate key edge and VPN issues, which leaves a dangerous exposure gap. AI-Driven Penetration Testing blends smart automation with expert validation, and […]

    AI and LLM Security

    The Attack Surface Used to Be Code. Now Part of It Is a Conversation.

    December 7, 2025 No comments yet

    A scanner for MCP servers sent me down a longer thought. We are used to an attack surface made of code, configuration and permissions. Some of it is now text, context and intent.

    AI and LLM Security

    When the AI Builds Your API Call: IDOR and SSRF, One Layer Up

    October 21, 2025 No comments yet

    A document-management system let its internal AI engine turn free text into internal API calls. The result was IDOR – except the input came from a model, not from a user.

    Posts pagination

    1 2 Next

    Search

    Categories

    • AI and LLM Security (26)
    • API Security (7)
    • Application Security (18)
    • Authorization and Access Control (11)
    • Black Box Testing (3)
    • Brute Force (1)
    • Cloud Security (13)
    • Engagements and Process (10)
    • Hacking (4)
    • Mobile Security (4)
    • Supply Chain (15)
    • White Box Testing (1)

    Recent posts

    • Somebody Wired the Darknet Into Your AI. What Could Go Wrong?
    • Configured Is Not Enforced
    • Every Week Someone Asks Me When AI Will Replace Pentesters
    AppSec Labs logo

    AppSec Labs offer rapid, modern security penetration testing, utilizing smart solutions to protect against evolving cyber threats.

    Features
    • Home
    Resources
    • Blog
    Company
    • About us
    Get in touch
    • info@appsec-labs.com
    • +972 52-433-9393

    © AppSec Labs 2026. All Rights Reserved.

    • Terms & Conditions
    • Privacy Policy