Skip to content
AppSec Labs logo
  • Penetration Testing Services
    • Web Applications
    • SaaS & Multi-Tenant
    • APIs
    • Mobile Apps
    • AI & LLM
  • Our Methodology
    • Attacks & Tests
    • Testing modes
  • About
    • Alumni
    • The Book
  • Careers
  • Blog
  • Contact
  • עברית

Contact us

Have a question or comment? Submit your message through our contact form and a member of our team will get back to you within 24 hours.

    AI and LLM Security

    • Home
    • Blog
    • AI and LLM Security
    • Page 2
    AI and LLM Security

    When the AI Builds Your API Call: IDOR and SSRF, One Layer Up

    October 21, 2025 No comments yet

    A document-management system let its internal AI engine turn free text into internal API calls. The result was IDOR – except the input came from a model, not from a user.

    AI and LLM Security

    The Chatbot That Called Our Admin API: LLM Function Calls Without Access Control

    September 29, 2025 No comments yet

    A support chatbot was wired straight into the backend with no access-control layer between them. Asking it politely for a little extra produced a call to /api/admin/exportAllUsers.

    AI and LLM Security

    Prompt Injection to Account Takeover: A Real Chain Through an AI Feature

    September 23, 2025 No comments yet

    A breach that chained three small weaknesses: blind use of an LLM, SSRF through prompt injection, and a weak JWT. Individually minor; together, full system access.

    AI and LLM Security

    “But We Asked the AI for Secure Code”: Five Minutes, Three Vulnerabilities

    August 11, 2025 No comments yet

    A development manager told me proudly they now build five times faster with AI. I asked about security. Five minutes later I had found three vulnerabilities in the AI’s code.

    AI and LLM Security

    How Prompt Injection Actually Works, in Two Requests

    January 8, 2025 No comments yet

    User input gets planted inside a prompt the server sends to the model. From there the road to prompt injection is very short – and MathGPT’s API key is what it looks like when someone walks down it.

    Posts pagination

    Previous 1 2

    Search

    Categories

    • AI and LLM Security (28)
    • API Security (9)
    • Application Security (18)
    • Authorization and Access Control (11)
    • Black Box Testing (3)
    • Brute Force (1)
    • Cloud Security (17)
    • Engagements and Process (12)
    • Hacking (4)
    • Mobile Security (4)
    • Supply Chain (19)
    • White Box Testing (1)

    Recent posts

    • Somebody Wired the Darknet Into Your AI. What Could Go Wrong?
    • Configured Is Not Enforced
    • Every Week Someone Asks Me When AI Will Replace Pentesters
    AppSec Labs logo

    AppSec Labs offer rapid, modern security penetration testing, utilizing smart solutions to protect against evolving cyber threats.

    Features
    • Home
    Resources
    • Blog
    Company
    • About us
    Get in touch
    • info@appsec-labs.com
    • +972 52-433-9393

    © AppSec Labs 2026. All Rights Reserved.

    • Terms & Conditions
    • Privacy Policy