AI and LLM Security
When the AI Builds Your API Call: IDOR and SSRF, One Layer Up
A document-management system let its internal AI engine turn free text into internal API calls. The result was IDOR - except the input came from a model, not…
Read itAI and LLM Security
The Chatbot That Called Our Admin API: LLM Function Calls Without Access Control
A support chatbot was wired straight into the backend with no access-control layer between them. Asking it politely for a little extra produced a call to /api/admin/exportAllUsers.
Read itAI and LLM Security
Prompt Injection to Account Takeover: A Real Chain Through an AI Feature
A breach that chained three small weaknesses: blind use of an LLM, SSRF through prompt injection, and a weak JWT. Individually minor; together, full system access.
Read itAI and LLM Security
“But We Asked the AI for Secure Code”: Five Minutes, Three Vulnerabilities
A development manager told me proudly they now build five times faster with AI. I asked about security. Five minutes later I had found three vulnerabilities in the…
Read itAI and LLM Security
How Prompt Injection Actually Works, in Two Requests
User input gets planted inside a prompt the server sends to the model. From there the road to prompt injection is very short - and MathGPT's API key…
Read itTell us what the system does and what worries you.
If a penetration test is not what you need yet, we will say so.