appsec.fyi

AI — A Practical Guide

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

AI: A Practical Guide

Curated and synthesized by . Last updated 2026-09-01. Synthesized from 608 of 608 curated resources. Browse all 608 AI resources →

Problem Framing: The Shifting Landscape of Application Security

The integration of AI into software development and operational environments introduces a paradigm shift for application security practitioners. This isn't merely about securing traditional web applications; it's about understanding and defending novel attack surfaces, behaviors, and vulnerabilities inherent to AI systems themselves. The traditional perimeter has dissolved, replaced by complex interactions between LLMs, agents, tools, and data stores. The speed at which AI agents operate and discover vulnerabilities necessitates a corresponding acceleration in our defensive capabilities.

The core challenge lies in the emergent properties of AI systems. Unlike deterministic software, AI behavior can be unpredictable, difficult to fully validate, and susceptible to manipulation through novel attack vectors. These systems are not static targets; they adapt, learn, and interact, creating a dynamic threat landscape that traditional security tools may overlook. The sheer volume of AI-generated code, the widespread adoption of AI assistants, and the increasing autonomy of AI agents all contribute to an expanding attack surface that requires specialized attention.

Core Mechanics: How AI Agents Interact and Create Risk

AI agents, often powered by Large Language Models (LLMs), function by receiving input, processing it, potentially interacting with external tools or data, and generating output. The critical risk vectors emerge from each of these stages.

Input Processing: LLMs are susceptible to prompt injection, where malicious instructions are embedded within user inputs or external data sources. This can range from direct prompts that override safety instructions to indirect methods where instructions are hidden within documents, images, or tool outputs. This manipulation can lead to the LLM performing unintended actions, leaking sensitive information, or bypassing safety guardrails [1][2][3][4][5].

Tool Use and Orchestration: AI agents often interact with external systems via tools or APIs. The Model Context Protocol (MCP) is a common pattern for enabling this interaction [6][7][8]. Vulnerabilities arise when these interactions are not strictly governed. This includes issues with tool metadata, authentication bypasses for API access, and the potential for AI agents to misuse or abuse provided tools. The "excessive agency" of an AI agent, granting it too much autonomy or overly broad permissions, significantly increases the blast radius of a compromise [9][10][11][12].

Data Handling and Memory: AI systems can interact with various data stores, including vector databases and long-term memory. Data poisoning attacks can corrupt training data or retrieval-augmented generation (RAG) knowledge bases, leading to biased or malicious outputs [13][14]. Moreover, information can be exfiltrated not only through direct prompts but also by tricking the AI into accessing controlled external resources or by exploiting flaws in how it handles conversation history or memory [15][16].

Output Generation: The output of an LLM can be used as executable code, prompts for other agents, or data that downstream systems process. Improper output handling can lead to code injection, command execution, or the generation of misinformation [1][17]. The potential for AI models to "hallucinate" or generate plausible but incorrect information also presents a risk [18][19].

Supply Chain: The AI supply chain extends beyond traditional software dependencies. It includes the models themselves, datasets used for training and fine-tuning, plugins, and external services. Compromised models, malicious datasets, or vulnerable AI skills integrated into agent workflows pose significant risks [20][21][22][23][24][25][26][27].

Notable Techniques: Exploiting and Defending AI Applications

The adversarial landscape for AI security is rapidly evolving, with attackers developing sophisticated techniques to exploit AI systems. Defenders are also innovating, creating new methods to detect and mitigate these threats.

Prompt Injection and Manipulation

Prompt injection remains a primary vector of attack. This can manifest in several ways:

Supply Chain Risks in AI

The AI supply chain is a critical attack vector:

Agentic Behavior Exploitation

The autonomy of AI agents creates unique vulnerabilities:

Data Exfiltration and Credential Theft

AI agents can be leveraged for sophisticated data exfiltration and credential theft:

Code Generation Vulnerabilities

Code generated by AI assistants, while accelerating development, can introduce vulnerabilities:

Infrastructure and Container Security

AI workloads often run in containerized environments, introducing specific risks:

Detection and Prevention Strategies

Addressing the security risks posed by AI requires a multi-layered approach that combines traditional security practices with AI-specific controls.

Shift-Left Security for AI

Integrating security early in the AI development lifecycle is crucial:

Runtime Controls and Monitoring

Observing and controlling AI agent behavior at runtime is essential:

Securing the AI Supply Chain

Mitigating risks from AI components and dependencies:

Identity and Access Management for AI

AI agents are becoming first-class identities, requiring robust IAM solutions:

Defensive Prompt Engineering

Actively designing prompts to prevent malicious AI behavior:

Tooling for AI Security

A growing ecosystem of tools is emerging to address the unique challenges of AI security:

Recent Developments

The field of AI security is experiencing rapid advancements. Several key developments are shaping the landscape:

Where to Go Deeper

To stay abreast of the rapidly evolving AI security landscape, consider the following resources and avenues:

Sources cited in this guide

  1. Reading the Signals in the OWASP LLM Top 10 2026 — blog.checkpoint.com
  2. Never Trust the Output: Data Pollution in AI Agents and MCP — blog.slonser.info
  3. What is Prompt Injection? How it Works and How to Prevent It — cloudsek.com
  4. Indirect Prompt Injection Is Now a Real-World AI Security Threat — techrepublic.com
  5. Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis — arxiv.org
  6. The risk hiding behind exposed MCP servers — wiz.io
  7. The 'by design' security flaw of Model Context Protocol (MCP) — bdtechtalks.substack.com
  8. A Timeline of Model Context Protocol (MCP) Security Breaches — authzed.com
  9. Agentic AI Security: Credentials and Permissions Define the Blast Radius — blog.gitguardian.com
  10. Beyond Prompt Injection: Hacking Apple's Private Cloud Compute — blog.sentry.security
  11. Wiz at Google Next: Machine-Speed Defense for Any Cloud, Any Platform, Any AI — wiz.io
  12. ServiceNow's Virtual Agent Vulnerability Shows Why AI Security Needs Traditional AppSec Foundations — snyk.io
  13. RAG and ruin: why your existing controls may miss AI poisoning attacks — intigriti.com
  14. OWASP Top 10 for LLMs 2025: Key Risks and Mitigation Strategies — invicti.com
  15. The Memory Heist - How I tricked Claude into leaking your deepest, darkest secrets — ayush.digital
  16. SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon — varonis.com
  17. An investigation into code injection vulnerabilities caused by generative AI — snyk.io
  18. Benchmarking 13 AI models on rediscovering known CVEs — aikido.dev
  19. Claude Mythos: Preparing for a World Where AI Finds and Exploits Vulnerabilities Faster Than Ever — wiz.io
  20. The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog — msecops.de
  21. Anthropic's Fever Dream: Claude's package that stole real keys — aikido.dev
  22. How to Control AI Assets Before They Become Shadow AI — jfrog.com
  23. How JFrog and NanoClaw are Bringing Software Supply Chain Security to the Age of Autonomous AI — jfrog.com
  24. What nearly 10,000 developer environments reveal about agentic development risk — snyk.io
  25. Ultralytics AI Pwn Request Supply Chain Attack — snyk.io
  26. 280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII — snyk.io
  27. How a Malicious Google Skill on ClawHub Tricks Users Into Installing Malware — snyk.io
  28. Indirect Prompt Injection remains a fundamental security challenge for AI — brave.com
  29. AI Agent Security in 2026: Prompt Injection and Memory Poisoning — swarmsignal.net
  30. Researchers hid a prompt injection inside a PNG and AI fell for it — digitaltrends.com
  31. Prompt injection protection: Detecting and blocking malicious AI instructions — acronis.com
  32. Indirect Prompt Injection Attacks: Hidden AI Risks — crowdstrike.com
  33. MCP Tool Poisoning — How It Works & How To Fight It — mcpmanager.ai
  34. MCP Security Vulnerabilities: Prompt Injection and Tool Poisoning — practical-devsecops.com
  35. Now defenders are embracing the prompt injection too — arstechnica.com
  36. "Context bombs" can frustrate AI-driven attacks researchers found — helpnetsecurity.com
  37. What Is LLM (Large Language Model) Security? — paloaltonetworks.com
  38. OWASP Top 10 for Agents 2026 — trydeepteam.com
  39. Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security Incident — snyk.io
  40. OWASP Top 10 for LLMs 2025 | DeepTeam Red Teaming Framework — trydeepteam.com
  41. PromptSnatcher: AdBlocker stealing Ai Chats - 90k installs — malext.io
  42. An AI Agent Breached Hugging Face. The Attack Playbook Was Older Than the Attacker — blog.gitguardian.com
  43. [tl;dr sec] #337 - Harnessing Harnesses, Generate Decoy Environments, Bug Bounty Singularity — tldrsec.com
  44. You Patched LiteLLM, But Do You Know Your AI Blast Radius? — snyk.io
  45. Ghostcommit attack hides malicious AI instructions in images — malwarebytes.com
  46. Symlinks Are Still Scary (And Yes, You Can Commit Them to Git) — snyk.io
  47. GhostApproval: A Trust Boundary Gap in AI Coding Assistants — wiz.io
  48. Leaking Secrets in the Age of AI — wiz.io
  49. AMA with Black Hat Speakers Lidor B. & Elad Meged (Pre-Auth RCE in Enterprise Java, Hijacking AI Coding Agents) — pwnhackers.substack.com
  50. Identiverse 2026: The Challenges Of Solving Identity For AI Agents At Scale — blog.gitguardian.com
  51. Why You Need a Security Companion for AI-Generated Code — snyk.io
  52. How Snyk ensures safe adoption of AI — snyk.io
  53. Secure AI tool adoption: Perceptions and realities — snyk.io
  54. Rules Files for Safer Vibe Coding — wiz.io
  55. AI Is Building Your Attack Surface. Are You Testing It? — snyk.io
  56. Wiz Research Uncovers Critical Vulnerability in AI Vibe Coding platform Base44 Allowing Unauthorized Access to Private Applications — wiz.io
  57. 4 Advantages of using AI code review — snyk.io
  58. Foundations of trust: Securing the future of AI-generated code — snyk.io
  59. Wiz Research Finds Critical NVIDIA AI Vulnerability Affecting Containers Using NVIDIA GPUs, Including Over 35% of Cloud Environments — wiz.io
  60. NVIDIAScape - Critical NVIDIA AI Vulnerability: A Three-Line Container Escape in NVIDIA Container Toolkit (CVE-2025-23266) — wiz.io
  61. SAPwned: SAP AI vulnerabilities expose customers’ cloud environments and private AI artifacts — wiz.io
  62. Choosing an AI-SPM tool: The four questions every security organization needs to ask — wiz.io
  63. Wiz extends its AI-SPM offering to OpenAI platform — wiz.io
  64. Wiz Enhances AI-SPM Support for Amazon Bedrock — wiz.io
  65. Wiz AI-SPM extends support to Microsoft Azure OpenAI Service models — wiz.io
  66. Snyk and Continue Partner to Embed AI-Powered Security into Every Step of the Developer Workflow — snyk.io
  67. I ran a paid bug-bounty-style game against my own multimodal prompt firewall, it didn't make money, so here's the code, the model and 13k real bypass attempts — huggingface.co
  68. Beyond Automation: Securing Low-Code Agentic AI with MCP Guardrails — snyk.io
  69. The New Security Control Point: Governing AI Agents Inside the Execution Loop — snyk.io
  70. Trust No Skill: Integrity Verification for AI Agent Supply Chains — unit42.paloaltonetworks.com
  71. Introducing Wiz Agents & Workflows: Security at the Speed of AI — wiz.io
  72. AI Agent Threat Response: Why Pre-Runtime Controls Matter More Than Runtime Detection — blog.gitguardian.com
  73. OrcaRouter Releases AI Threat Report 2026 and Makes Its Security Controls Free Amid Rise in Prompt-Injection Attacks — aninews.in
  74. Protecting Against Indirect Prompt Injection Attacks in MCP — developer.microsoft.com
  75. The MCP Security Tool You Probably Need - MCP Snitch — adversis.io
  76. Wiz AI-SPM model scanning: Securely innovate with AI community models — wiz.io
  77. Wiz Code Week Recap: Securing AI Native Development — wiz.io
  78. Why We Built Evo — From My Heart — snyk.io
  79. AI Agent Authentication in 2026: Web Bot Auth, ARD & OAuth — webdecoy.com
  80. Hunting Account Takeovers in the Wild West of MCP OAuth Servers" — blog.sicks3c.io
  81. Show HN: OneCLI – OSS credential gateway that keeps secrets out of AI agents — github.com
  82. Secure at Inception: Introducing New Tools for Securing AI-Native Development — snyk.io
  83. Meeting the AI Mandates with Confidence: Why Federal Teams Trust Snyk — snyk.io
  84. Introducing the AI Security Fabric: Empowering Software Builders in the Era of AI — snyk.io
  85. You're Simulating the Wrong Attacker: Who Matters in AI Red Teaming — adversa.ai
  86. DeepTeam: Open-Source Framework to Red Team LLMs and LLM Systems — github.com
  87. AI-Infra-Guard: Full-Stack AI Red Teaming Platform — github.com
  88. Prompt injection turned Googles Antigravity file search into RCE — csoonline.com
  89. NVIDIA/garak: the LLM vulnerability scanner — github.com
  90. Introducing Agent Security — snyk.io
  91. fr0gger/proximity: Proximity is a MCP security scanner powered with NOVA — github.com
  92. Red Agent and Claude Opus: Securing Production Targets at Scale — wiz.io
  93. gadievron/raptor: Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents, and skills, and orchestrating security tool usage, we configure the agent for adversarial thinking, and perform research or attack/defense operations. — github.com
  94. KeygraphHQ/shannon: Fully autonomous AI hacker to find actual exploits in your web apps. Shannon has achieved a 96.15% success rate on the hint-free, source-aware XBOW Benchmark. — github.com
  95. Nightfall AI and Snyk unite to deliver AI-powered secrets scanning for developers — snyk.io
  96. Lean and Mean: How We Fine-Tuned a Small Language Model for Secret Detection in Code — wiz.io
  97. Welcome-to-The New Era of AI-Driven Development — snyk.io
  98. OWASP GenAI Top 10 Risks and Mitigations for Agentic AI Security — genai.owasp.org
  99. The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software — unit42.paloaltonetworks.com
  100. AI-powered breaches provide wake-up call for incident response — csoonline.com
  101. Bridging the Gap to Autonomous Fixes: Snyk and Atlassian Unveil Intelligent Remediation for Jira — snyk.io
  102. Hackers can use 9 of the most popular AI tools to assemble massive botnets — arstechnica.com
  103. Inside 90 days of attacks on AI infrastructure — wiz.io
  104. From Hugging Face to Fable: this summer shows AI control matters more than trust — aikido.dev
  105. NVD in the AI Era: The Case for Multi-Source Vulnerability Intelligence — snyk.io
  106. [tl;dr sec] #333 - Perplexity's Bumblebee, Evading Cloud Logging, AI Vuln Hunting Spec — tldrsec.com
  107. Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE — unit42.paloaltonetworks.com
  108. The emerging use of malware invoking AI — wiz.io
  109. AI Security 101: Mapping the AI Attack Surface — wiz.io
  110. Agentic Browser Security: 2025 Year-End Review — wiz.io
  111. Why Threat Modeling Is Now Even More Critical for AI-Native Applications — snyk.io
  112. Scaling AI Security: How Evo Complements New Agentic Tools — snyk.io
  113. Live From Davos: The End of Human-Speed Security — snyk.io
  114. The Next Era of AppSec: Why AI-Generated Code Needs Offensive Dynamic Testing — snyk.io
  115. The Meta hack shows theres more to AI security than Mythos — technologyreview.com
  116. Introducing the New Agentic Architecture for Snyk Agent Fix: Faster, Smarter, and More Secure — snyk.io
  117. The New Security Risks of the Agentic Development Lifecycle — snyk.io
  118. What is AI SAST? — aikido.dev
  119. Sparkplug B Protocol Fuzzing with AI Assistance — bishopfox.com
  120. AI agents building security tests – architecture and prompts — labs.detectify.com
  121. Hack the AI agent: Build agentic AI security skills with the GitHub Secure Code Game — github.blog
  122. The sorry state of skill distribution — blog.trailofbits.com
  123. https://github.com/Armur-Ai/Pentest-Swarm-AI — github.com
  124. The AI Agent Security Surface: What Gets Exposed When You Add Tools and Memory — towardsdatascience.com
  125. Claude Jailbreaking in 2026: What Repello's Red Teaming Data Shows — repello.ai
  126. Q4 2025 AI Agent Security Trends — lakera.ai
  127. Google Workspace's Continuous Approach to Mitigating Prompt Injection — security.googleblog.com
  128. LangChain LangGraph Flaws Expose Files Secrets Databases in Widely Used AI Frameworks — thehackernews.com
  129. Detecting and analyzing prompt abuse in AI tools — microsoft.com
  130. Auditing the Gatekeepers: Fuzzing "AI Judges" to Bypass Security Controls — unit42.paloaltonetworks.com
  131. depthfirst | 1-Click RCE To Steal Your Moltbot Data and Keys — depthfirst.com
  132. Prompt Injection Toolkit: 25 Payloads & Techniques for Mastering AI Pentesting — medium.verylazytech.com
  133. insaaniManav/prompt-forge: AI prompt engineering workbench for crafting, testing, and systematically evaluating prompts with powerful analysis tools. — github.com
  134. harishsg993010/crossbow-agent: world's first Opensource fully Autonomous AI Security Engineer — github.com
  135. Building an Open-Source AI-Powered Auto-Exploiter with a 1.7B Parameter Model: No Paid APIs Required — mohitdabas.in
  136. The AI Attack Surface Map v1.0 — danielmiessler.com
  137. How I Automate BugBounty Using Chatgpt — medium.com
  138. aress31/burpgpt — github.com
  139. SecGPT transforms cybersecurity through AI-driven insights. — medium.com
  140. I Used GPT-3 to Find 213 Security Vulnerabilities in a Single Codebase — medium.com
  141. HackGPT — kaneofthrones.medium.com
  142. Microsoft Security Copilot is a new GPT-4 AI assistant for cybersecurity — theverge.com
  143. Favorite tweet by @LeaKissner — twitter.com
📚 This guide is synthesized from the full text of resources curated in the AI library, and refreshed as new material is added.