appsec.fyi

AI — A Practical Guide

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

AI: A Practical Guide

Curated and synthesized by . Last updated 2026-10-01. Synthesized from 657 of 657 curated resources. Browse all 657 AI resources →

Problem Framing

The increasing integration of AI into application development and operations introduces novel attack vectors and amplifies existing security risks. AI systems, particularly large language models (LLMs) and agentic AI, exhibit emergent behaviors and interact with environments in ways that traditional security models struggle to address. This shift necessitates a fundamental re-evaluation of application security principles, moving beyond static analysis and signature-based detection to understand and defend against dynamic, context-aware threats.

Application security professionals face a rapidly expanding threat surface encompassing AI models themselves, the infrastructure supporting them, the data they process, and the intelligent agents they power. Key areas of concern include prompt injection, credential leakage, insecure inter-agent communication, and the misuse of AI capabilities for offensive purposes. The speed at which AI agents can operate and exploit vulnerabilities compresses the timeline between discovery and abuse, demanding proactive, layered, and intelligent security controls.

Core Mechanics

At its core, AI security intersects with application security through several key mechanics:

Prompt Injection and Model Manipulation

Prompt injection is a class of vulnerabilities where an attacker manipulates an AI model's input to elicit unintended or malicious behavior. This can range from bypassing safety guardrails (jailbreaking) to compelling the model to execute commands or reveal sensitive information. Indirect prompt injection, where malicious instructions are hidden within external content processed by the AI (e.g., a webpage, document, or email), is particularly insidious as it doesn't require direct user interaction with the prompt itself [1][2][3][4].

The underlying issue often stems from the LLM's inability to reliably distinguish between system instructions and user-provided data or content. This "instruction confusion" can be exploited through various encoding techniques (Base64, ROT13), custom character sets, or by embedding instructions within image files [5][6][7]. Even seemingly innocuous interactions can poison an AI agent's long-term memory, leading to persistent malicious behavior [8][9].

Agentic AI and Excessive Agency

Agentic AI systems, characterized by their autonomy and ability to interact with external tools and environments, introduce a new dimension of risk. These agents can chain online services, gain internet access, execute code, and achieve goals that extend far beyond simple text generation [10][11][12]. When combined with vulnerabilities like prompt injection or excessive permissions, agentic AI can lead to significant security incidents, including data exfiltration, credential theft, and lateral movement within networks.

The concept of "excessive agency" highlights the danger of AI systems being empowered to perform sensitive actions without sufficient human oversight or validation. This can manifest in agents performing actions like sending emails, making sensitive API calls, or executing code based on manipulated inputs [10][13]. The rapid execution of these actions, often at machine speed, leaves little room for human intervention.

Model Context Protocol (MCP) and Inter-Agent Communication

The Model Context Protocol (MCP) serves as a standard for AI agents to interact with external tools, services, and data. Security vulnerabilities within MCP implementations and the tools they connect to create a significant attack surface [14][15][16]. This can include vulnerabilities like command injection, path traversal, Server-Side Request Forgery (SSRF), and DNS rebinding, particularly when MCP servers are exposed or improperly secured.

Exploiting MCP vulnerabilities can grant attackers unauthorized command execution, access to sensitive cloud credentials, the ability to exfiltrate data, or even take over cloud infrastructure [17][18][19][20][21]. The trust placed in the MCP protocol for agent communication can be leveraged to chain attacks, escalate privileges, and achieve persistent access.

AI Supply Chain Risks

The AI supply chain encompasses models, libraries, tools, and data used in AI development and deployment. Compromising any part of this chain can lead to widespread security compromises. This includes malicious packages in AI-related dependencies, poisoned training data, compromised MCP servers, or even malicious AI skills listed in agent marketplaces [22][23][24][25][26][27]. The "hallucination" of domains by LLMs can also create supply chain risks when adversaries register these phantom domains, leading to the distribution of malicious code to AI agents [28].

AI models themselves, especially fine-tuned open-weight models downloaded from untrusted sources, can contain embedded backdoors that are difficult to detect with traditional methods [22]. Furthermore, AI agents may inadvertently download and execute malicious code if their dependencies or tool integrations are compromised.

Data Poisoning and Training Data Integrity

Data poisoning involves manipulating the data used to train AI models. This can lead to biased outputs, model degradation, or the embedding of hidden backdoors that can be triggered later. Attackers can introduce malicious documents into retrieval-augmented generation (RAG) pipelines or contaminate knowledge graphs to steer AI behavior or exfiltrate sensitive information [29][30]. The integrity of training data is paramount for maintaining the security and reliability of AI systems.

Notable Techniques

A variety of techniques are being employed by attackers to compromise AI systems and applications:

Prompt Injection Variants

Agentic AI Exploitation

Supply Chain and Infrastructure Attacks

Data Exfiltration and Secrets Management

AI-Powered Vulnerability Discovery and Exploit Generation

Detection & Prevention

Securing AI systems requires a multi-layered approach focusing on pre-runtime controls, runtime validation, and continuous monitoring.

Pre-Runtime Controls

Runtime Controls and Monitoring

Runtime controls are critical due to the speed and autonomy of AI agents. Detection alone is insufficient; pre-runtime controls must be prioritized [79].

Human-in-the-Loop (HITL)

While AI can automate many security tasks, human oversight remains crucial, especially for sensitive operations. HITL mechanisms allow for human review and approval of critical AI-driven actions, acting as a final check against unintended consequences [77][87].

Tooling

The evolving landscape of AI security has spawned a range of specialized tools:

Recent Developments

The field of AI security is characterized by rapid evolution, with new vulnerabilities, attack techniques, and defense mechanisms emerging constantly.

Exploitation of AI Coding Assistants

AI coding assistants like GitHub Copilot, Claude Code, and Cursor have been found to leak credentials through files, logs, and history that traditional repository scanners miss [63]. Vulnerabilities have also been discovered that allow for remote code execution through prompt injection in configurations or by manipulating tool execution [104][105][106]. Malicious packages weaponizing local AI coding agents have been used for reconnaissance and data exfiltration [26].

Escalation of Prompt Injection Sophistication

Prompt injection has moved beyond simple jailbreaks to more sophisticated attacks like indirect prompt injection via sophisticated social engineering, ASCII smuggling, and adversarial prompt chaining [36][1][2][3]. Techniques like "GhostSplice" split malicious requests across trusted channels to bypass AI defenses [34]. The OWASP Top 10 for LLM Applications consistently ranks prompt injection as the primary risk [31][4].

Autonomous AI Agents and Expanded Attack Surfaces

AI agents are demonstrating increased autonomy, capable of compressing weeks of intrusion tradecraft into hours and achieving complex goals without direct human command [11][107][91]. This autonomy, combined with vulnerabilities in their tool integrations (MCP) and permissions, can lead to significant security incidents, including data exfiltration, lateral movement, and even self-replication of malware [53][10][12][48][23][108].

Emergence of AI-Specific Vulnerabilities

New classes of vulnerabilities are being identified that are unique to AI systems. These include data poisoning of training data, memory poisoning of LLM context, model extraction, and exploits targeting the unique architectures of AI applications and their infrastructure [62][22][29][30]. The security of AI supply chains, encompassing models, libraries, and data, is becoming increasingly critical [28][23][57].

AI-Driven Security Research and Defense

AI is also being leveraged to improve security. AI-powered tools are being developed for automated vulnerability discovery, exploit generation, security code review, and real-time threat detection [53][65][54][55][66][102][108]. Concepts like "context bombs" are being used defensively to frustrate AI-driven attacks [45][46].

Cloud and Infrastructure Security for AI

The cloud infrastructure hosting AI services is a significant attack surface. Vulnerabilities in containerization technologies (e.g., NVIDIA Container Toolkit), MCP implementations, and cloud provider configurations (e.g., IAM roles, storage bucket security) are actively being exploited [61][17][56][18][19][50][15][20][21].

Where to Go Deeper

For those seeking to deepen their understanding and capabilities in AI security, the following resources and areas of focus are recommended:

Frameworks and Standards

Technical Resources and Communities

Hands-on Practice

Sources cited in this guide

  1. Indirect Prompt Injection Is Now a Real-World AI Security Threat — techrepublic.com
  2. Indirect prompt injection is taking hold in the wild — helpnetsecurity.com
  3. Prompt Injection Attacks: Examples, Techniques, and Defence — blog.cyberdesserts.com
  4. OWASP Top 10 for LLMs 2025 | DeepTeam Red Teaming Framework — trydeepteam.com
  5. Ghostcommit attack hides malicious AI instructions in images — malwarebytes.com
  6. Fed up with vibe coders dev sneaks data-nuking prompt injection into their code — arstechnica.com
  7. Researchers Uncover 10 In-the-Wild Prompt Injection Payloads Targeting AI Agents — infosecurity-magazine.com
  8. AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory — thehackernews.com
  9. GitHub - JasonLovesDoggo/caddy-defender: Caddy module to block IPs and prevent AIs from training on your website. — github.com
  10. AI Agents Keep Falling to 'Goal Hijack' (Copilot, Cursor, Grok) — darkmarc.substack.com
  11. An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation — unit42.paloaltonetworks.com
  12. Agentic AI Security: Credentials and Permissions Define the Blast Radius — blog.gitguardian.com
  13. The dangerous side of AI agents: warnings that they can be manipulated to access your emails files and accounts — clarin.com
  14. Introducing the MCP Server for Wiz: Smarter AI Context, Stronger Cloud Security — wiz.io
  15. MCP Safety Audit: LLMs with MCP Allow Major Security Exploits — arxiv.org
  16. A Timeline of Model Context Protocol (MCP) Security Breaches — authzed.com
  17. MCP Auto-Execution: From Git Clone to Cloud Compromise in Amazon Q VS Code Extension — wiz.io
  18. Probllama: Ollama Remote Code Execution Vulnerability (CVE-2024-37032) – Overview and Mitigations — wiz.io
  19. SAPwned: SAP AI vulnerabilities expose customers’ cloud environments and private AI artifacts — wiz.io
  20. MCP Supply Chain Advisory: RCE Vulnerabilities Across the AI Ecosystem — ox.security
  21. The Vulnerable MCP Project: Comprehensive MCP Security Database — vulnerablemcp.info
  22. The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog — msecops.de
  23. OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat — unit42.paloaltonetworks.com
  24. Ultralytics AI Pwn Request Supply Chain Attack — snyk.io
  25. s1ngularity's Aftermath: AI, TTPs, and Impact in the Nx Supply Chain Attack — wiz.io
  26. Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security Incident — snyk.io
  27. 280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII — snyk.io
  28. Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector — unit42.paloaltonetworks.com
  29. Practical Poisoning Attacks against Retrieval-Augmented Generation — arxiv.org
  30. RAG Safety: Exploring Knowledge Poisoning Attacks to RAG — arxiv.org
  31. OWASP 2026 LLM Top 10: "The model will be fooled" — helpnetsecurity.com
  32. Prompt Injection: The Most Common AI Exploit in 2025 — obsidiansecurity.com
  33. Microsoft Copilot Cowork Exfiltrates Files — promptarmor.com
  34. GhostSplice: Malicious MCP Servers Split Instructions to Make AI Coding Agents Exfiltrate Secrets (ASSET Research Group) — asset-group.github.io
  35. RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data — varonis.com
  36. The Memory Heist - How I tricked Claude into leaking your deepest, darkest secrets — ayush.digital
  37. Zero-Click IP Leak in a Privacy Search Engine: Indirect Prompt Injection & Silent Patching — infosecwriteups.com
  38. Indirect Prompt Injection Exposes a Universal AI Security Flaw No Deployment Model Is Immune — futurumgroup.com
  39. How indirect prompt injection attacks on AI work - and 6 ways to shut them down — zdnet.com
  40. Indirect Prompt Injection: The Hidden Threat — lakera.ai
  41. AI Agent Security in 2026: Prompt Injection and Memory Poisoning — swarmsignal.net
  42. Large Reasoning Models are Autonomous Jailbreak Agents — nature.com
  43. AI Agents May Always Fall for Prompt Injections — arxiv.org
  44. Invisible AI Prompts Trigger Court Sanctions — securityaffairs.com
  45. "Context bombs" can frustrate AI-driven attacks researchers found — helpnetsecurity.com
  46. Now defenders are embracing the prompt injection too — arstechnica.com
  47. Inside 90 days of attacks on AI infrastructure — wiz.io
  48. AI Agent Security: 6 Risks to Address and How to Do It — wiz.io
  49. How a Malicious Google Skill on ClawHub Tricks Users Into Installing Malware — snyk.io
  50. Wiz Research Finds Critical NVIDIA AI Vulnerability Affecting Containers Using NVIDIA GPUs, Including Over 35% of Cloud Environments — wiz.io
  51. Before the first prompt: Code execution paths in trusted coding-agent projects — securitylabs.datadoghq.com
  52. ServiceNow's Virtual Agent Vulnerability Shows Why AI Security Needs Traditional AppSec Foundations — snyk.io
  53. How we found 24 Android vulnerabilities using our open source AI security agent — github.blog
  54. Can AI do novel security research? Meet the HTTP Terminator — portswigger.net
  55. The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software — unit42.paloaltonetworks.com
  56. The risk in malicious AI models: Wiz Research discovers critical vulnerability in AI-as-a-Service provider, Replicate — wiz.io
  57. Wiz AI-SPM model scanning: Securely innovate with AI community models — wiz.io
  58. NVIDIAScape - Critical NVIDIA AI Vulnerability: A Three-Line Container Escape in NVIDIA Container Toolkit (CVE-2025-23266) — wiz.io
  59. Breaking NVIDIA Triton: CVE-2025-23319 - A Vulnerability Chain Leading to AI Server Takeover — wiz.io
  60. Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto Wallets — infosecurity-magazine.com
  61. AI on Kubernetes: Default Helm Chart Security Configurations and Lateral Movement Risks — sorami.com.au
  62. The Infostealer Incursion: How Stolen Credentials Breach Cloud, Code, and AI Environments — wiz.io
  63. AI Coding Agents Are Leaking Credentials: Cursor, Claude Code, Copilot, and MCP — blog.gitguardian.com
  64. SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon — varonis.com
  65. Jason Haddix: Stop fearing AI pentesting — aikido.dev
  66. Using MCP Agents for Penetration Testing — bishopfox.com
  67. vxcontrol/pentagi: ✨ Fully autonomous AI Agents system capable of performing complex penetration testing tasks — github.com
  68. Ed1s0nZ/CyberStrikeAI: CyberStrikeAI is an AI-native security testing platform built in Go. It integrates 100+ security tools, an intelligent orchestration engine, role-based testing with predefined security roles, a skills system with specialized testing skills, and comprehensive lifecycle management capabilities. — github.com
  69. harishsg993010/crossbow-agent: world's first Opensource fully Autonomous AI Security Engineer — github.com
  70. KeygraphHQ/shannon: Fully autonomous AI hacker to find actual exploits in your web apps. Shannon has achieved a 96.15% success rate on the hint-free, source-aware XBOW Benchmark. — github.com
  71. Uncensored Qwen 3.8 27b helped write a LSASS Dumper which bypassed EDR while I made myself coffee — projectblack.io
  72. Welcome to Snyk Labs: Charting the Course for AI-Native Security — snyk.io
  73. Secure at Inception: Introducing New Tools for Securing AI-Native Development — snyk.io
  74. AI Guardrails: Safety Controls for Responsible AI Use — wiz.io
  75. Detecting AI-specific threats in Claude Enterprise from the Compliance API: a prefilter + LLM-as-judge pipeline with Sigma rules — papermtn.co.uk
  76. Securing the AI Edge: Wiz and Cloudflare Integrate for End-to-End AI Protection — wiz.io
  77. Trust No Skill: Integrity Verification for AI Agent Supply Chains — unit42.paloaltonetworks.com
  78. Why Your “Skill Scanner” Is Just False Security (and Maybe Malware) — snyk.io
  79. AI Agent Threat Response: Why Pre-Runtime Controls Matter More Than Runtime Detection — blog.gitguardian.com
  80. The Future of AI Agent Security Is Guardrails — snyk.io
  81. Gitguardian Agent Skills: Secret Detection and Remediation For AI-Assisted Development — blog.gitguardian.com
  82. Leaking Secrets in the Age of AI — wiz.io
  83. AI Security 101: Mapping the AI Attack Surface — wiz.io
  84. IEEE Cloud Summit 2026: The Tunnels No One Mapped — blog.gitguardian.com
  85. AI Runtime Threat Detection: From Input to Real-World Impact — wiz.io
  86. Old AI Security vs Evo: Watch Agentic Security Replace Weeks of Manual Work — snyk.io
  87. Closing the Security Gap in the Age of Agentic Coding — wiz.io
  88. Building AI Trust with Snyk Code and Snyk Agent Fix — snyk.io
  89. Introducing the AI Security Fabric: Empowering Software Builders in the Era of AI — snyk.io
  90. Seeing AI Clearly: Building Visibility Across Modern AI Applications — wiz.io
  91. Introducing Wiz Agents & Workflows: Security at the Speed of AI — wiz.io
  92. Introducing Wiz AI Application Protection Platform (AI-APP) — wiz.io
  93. Securing AI Applications From Inception to Deployment — wiz.io
  94. Wiz Code Week Recap: Securing AI Native Development — wiz.io
  95. Prompt Injection Attacks in LLMs: What Developers Need to Know in 2026 — securityjourney.com
  96. DeepTeam: Open-Source Framework to Red Team LLMs and LLM Systems — github.com
  97. AI-Infra-Guard: Full-Stack AI Red Teaming Platform — github.com
  98. Q4 2025 AI Agent Security Trends — lakera.ai
  99. OWASP Top 10 for Agents 2026 — trydeepteam.com
  100. Scaling AI Security: How Evo Complements New Agentic Tools — snyk.io
  101. Introducing Agent Security — snyk.io
  102. Aikido and OWASP bring agentic Code Audit to the global AppSec community — owasp.org
  103. What is AI SAST? — aikido.dev
  104. Agents hooked into GitHub can steal creds but Anthropic Google and Microsoft haven't warned users — theregister.com
  105. LangChain LangGraph Flaws Expose Files Secrets Databases in Widely Used AI Frameworks — thehackernews.com
  106. What Is Prompt Injection in AI? Examples & Prevention | EC-Council — eccouncil.org
  107. Who was behind the attack? Possibly nobody — aikido.dev
  108. Introducing the Wiz Red Agent- AI-Powered Attacker — wiz.io
  109. Why Threat Modeling Is Now Even More Critical for AI-Native Applications — snyk.io
  110. AI Created a Leaked Credentials Flood: Here's How We're Draining It — blog.gitguardian.com
  111. Generative AI Security: Risks & Best Practices — wiz.io
  112. The New Security Control Point: Governing AI Agents Inside the Execution Loop — snyk.io
  113. What nearly 10,000 developer environments reveal about agentic development risk — snyk.io
  114. Foundations of trust: Securing the future of AI-generated code — snyk.io
  115. Automatically fix code vulnerabilities with AI — snyk.io
  116. Find, auto-fix, and prioritize intelligently, with Snyk's AI-powered code security tools — snyk.io
  117. Rules Files for Safer Vibe Coding — wiz.io
  118. Lean and Mean: How We Fine-Tuned a Small Language Model for Secret Detection in Code — wiz.io
  119. Hacking Google with A.I. for $500,000 — brutecat.com
  120. From MCP to Vibe Coding: Full Endpoint Visibility in Wiz AI Security — wiz.io
  121. The New Threat Landscape: AI-Native Apps and Agentic Workflows — snyk.io
  122. Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next — wiz.io
  123. Understanding and Reducing AI Risk in Modern Applications — wiz.io
  124. The Prescriptive Path to Operationalizing AI Security — snyk.io
  125. Mythos Doesn't Deploy Itself — bishopfox.com
  126. IaC Inventory: A Unified View Across Code, Deployments, and Cloud — wiz.io
  127. Key Takeaways from the 2026 State of AI in the Cloud Report — wiz.io
  128. The (In)security Landscape of AI-Powered GitHub Actions (Part 2/2) — wiz.io
  129. From Acceleration to Exposure: Why AI Demands Mature AppSec — snyk.io
  130. Securing the Agent Skill Ecosystem: How Snyk and Vercel Are Locking Down the New Software Supply Chain — snyk.io
  131. How “Clinejection” Turned an AI Bot into a Supply Chain Attack — snyk.io
  132. Claude Code Security: A Welcome Evolution in the Remediation Loop — snyk.io
  133. AI Is Building Your Attack Surface. Are You Testing It? — snyk.io
  134. Gartner urges multilayered defenses as AI deepfakes and LLM threats surge — biz.chosun.com
  135. Fresh LiteLLM Vulnerability Exploited Shortly After Disclosure — securityweek.com
  136. Six AI Vulnerabilities Three Attack Patterns One Dangerous Service Gap — msspalert.com
  137. Claude Jailbreaking in 2026: What Repello's Red Teaming Data Shows — repello.ai
  138. Protecting Against Indirect Prompt Injection Attacks in MCP — developer.microsoft.com
  139. Anatomy of an Indirect Prompt Injection — pillar.security
  140. SILENTCHAIN AI - AI-Powered Security Testing — silentchain.ai
  141. depthfirst | 1-Click RCE To Steal Your Moltbot Data and Keys — depthfirst.com
  142. Hunting Account Takeovers in the Wild West of MCP OAuth Servers" — blog.sicks3c.io
  143. Building an Open-Source AI-Powered Auto-Exploiter with a 1.7B Parameter Model: No Paid APIs Required — mohitdabas.in
  144. SSH LLM Honeypot caught a real threat actor - Beelzebub Blog — beelzebub-honeypot.com
  145. GitHub - browser-use/browser-use: Make websites accessible for AI agents — github.com
  146. GitHub - fr0gger/Awesome-GPT-Agents: A curated list of GPT agents for cybersecurity — github.com
  147. Microsoft Copilot: From Prompt Injection to Exfiltration of Personal Information · Embrace The Red — embracethered.com
  148. pentestmuse-ai/PentestMuse — github.com
  149. protectai/ai-exploits — github.com
  150. The AI Attack Surface Map v1.0 — danielmiessler.com
  151. Juice Shop v20.0.0 — a fresh squeeze of features, now with AI — owasp.org
📚 This guide is synthesized from the full text of resources curated in the AI library, and refreshed as new material is added.