XSS Meets AI: The Invisible Attack the Victim Never Sees

- Posted in Threat Analyze by
Background: Nowadays, AI-powered features have become increasingly common. With just one click, users can summarize the content of an entire page, making these features extremely time-saving and [...] Read more

Incident Forensics: Validating Generative AI Voice as a Component of the Attack

- Posted in Incident Response by
Background: As AI capabilities continue to evolve, threat actors have also started leveraging generative AI tools as part of their attacks. One well known scenario that comes to mind is the use of [...] Read more

The Wall Was Just a Filter: Data Segregation Failure in Shared Stores

- Posted in Other by
Background: Data isolation is one of the most important concerns when you're working in a multi-tenant environment. But things change when we take the same approach into the context of an AI agent [...] Read more

The Model Is Fine. The Author Is Gone.

- Posted in Threat Analyze by
Background: The threat landscape with introduction AI has changed, and at this moment we also need to focus on an additional threat: LLM supply-chain attacks that abuse its name and capabilities. [...] Read more

Weaponizing Victim GPUs: Exploiting Local LLM Deployments for Unauthorized Model Inference in Kuberentes

- Posted in Threat Analyze by
Background: Kubernetes has become a massive system in enterprise environments, which means continuous monitoring is essential to detect abuse of that space. For this reason, it is an attractive [...] Read more

Operational Challenges and Security Threats in Modern AI Training Ecosystems

- Posted in Threat Analyze by
Background: When training machine learning models, the underlying compute, orchestration, and storage pipelines are often far more vulnerable than the mathematical model itself. Because tools like [...] Read more

The Incident Cost of Integrating AI into Products

- Posted in Threat Analyze by
Background: Nowadays, a lot of products are integrating AI into customer support and other inner circles of their product. But have you ever thought about one challenge with this integration? Instead [...] Read more

Hallucinations, Overreliance, and the Hidden Cost of Trusting LLM Outputs

- Posted in Other by
Background: As we are using generative AI, the information it provides is not always correct. The root causes can be: Model-intrinsic causes (the accidental path) System and design causes Adversarial [...] Read more

From Detection to Prediction: Applying EPSS matrix in Incident Response Post-Mortem Analysis

- Posted in Incident Response by
Background: EPSS (Exploit Prediction Scoring System) is a specialized model and scoring framework that predicts the likelihood of real-world exploitation based on observed exploitation activity, [...] Read more

Securing AI RAG: How to Mitigate Vector and Embedding Weaknesses

- Posted in Other by
Background: Before deep dive into the section lets define what is RAG in AI scope . R – Retrieval: Before processing a prompt, the system searches and retrieves relevant data from internal knowledge [...] Read more
Page 1 of 12