appsec.fyi

AI — A Practical Guide

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

AI: A Practical Guide

Curated and synthesized by . Last updated 2026-08-16. Synthesized from 564 of 564 curated resources. Browse all 564 AI resources →

Problem Framing

The integration of Artificial Intelligence (AI), particularly Large Language Models (LLMs) and autonomous agents, into application development and security workflows presents a paradigm shift, introducing novel attack vectors and exacerbating existing ones. Traditional security controls are often insufficient against these dynamic and context-aware systems, necessitating a re-evaluation of application security principles. AI's ability to reason, generate novel content, and automate complex tasks at machine speed creates significant risks, including the rapid discovery and exploitation of vulnerabilities, sophisticated social engineering, and the compromise of sensitive data. Understanding and mitigating these AI-specific threats is paramount for maintaining application security.

AI models, especially LLMs, are susceptible to prompt injection attacks, where crafted inputs can manipulate their behavior, bypass guardrails, or extract sensitive information [1][2]. This can range from simple requests to tricking the AI into revealing system prompts or executing arbitrary code. Furthermore, the trend towards AI agents with increased autonomy, tool access, and memory capabilities introduces a substantial attack surface. These agents, designed to perform tasks with minimal human intervention, can be manipulated to execute malicious commands, exfiltrate data, or cause unintended system disruptions [3][4]. The security of the AI development lifecycle itself is also a critical concern, with risks extending to data poisoning, model theft, and supply chain compromises of pre-trained models and AI frameworks [5][6].

The increasing reliance on AI-generated code also presents challenges. While AI can accelerate development, it can also introduce vulnerabilities at an alarming rate [7][8]. Security teams must contend with AI-assisted malware development, automated reconnaissance, and the potential for AI to chain together disparate vulnerabilities to achieve complex attack objectives, drastically reducing the time defenders have to respond [9][10]. The inherent unpredictability and "black box" nature of some AI systems also pose challenges for traditional security analysis and auditing.

Core Mechanics

The security implications of AI stem from its core mechanics: its ability to process vast amounts of data, generate human-like text and code, reason about complex logic, and interact with external systems.

LLMs operate by predicting the next most probable token based on their training data and the provided input. This probabilistic nature, combined with the vastness of their training datasets, makes them susceptible to manipulation.

Notable Techniques

The evolving threat landscape has seen the development of sophisticated techniques to exploit AI systems:

Detection & Prevention

Addressing AI-specific security risks requires a multi-layered approach focusing on understanding AI behavior, securing the infrastructure, and implementing specialized controls.

Tooling

A growing ecosystem of tools is emerging to address the unique security challenges posed by AI:

Recent Developments

The field of AI security is evolving at an unprecedented pace, with new threats and defenses emerging constantly.

Where to Go Deeper

For practitioners seeking to deepen their understanding and operationalize AI security, several avenues are recommended:

Sources cited in this guide

  1. What is Prompt Injection? How it Works and How to Prevent It — cloudsek.com
  2. Indirect Prompt Injection Attacks: Hidden AI Risks — crowdstrike.com
  3. AI Agent Security: 6 Risks to Address and How to Do It — wiz.io
  4. The AI Agent Security Surface: What Gets Exposed When You Add Tools and Memory — towardsdatascience.com
  5. Generative AI Security: Risks & Best Practices — wiz.io
  6. How JFrog and NanoClaw are Bringing Software Supply Chain Security to the Age of Autonomous AI — jfrog.com
  7. Top LLM security tools to protect AI applications — aikido.dev
  8. DevOpsDays Singapore 2024: Unmasking the security pitfalls in AI-generated code — snyk.io
  9. AI-powered breaches provide wake-up call for incident response — csoonline.com
  10. Introducing the AI Security Fabric: Empowering Software Builders in the Era of AI — snyk.io
  11. Q4 2025 AI Agent Security Trends — lakera.ai
  12. AI Agent Attacks in Q4 2025 Signal New Risks for 2026 — esecurityplanet.com
  13. Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild — unit42.paloaltonetworks.com
  14. RAG and ruin: why your existing controls may miss AI poisoning attacks — intigriti.com
  15. AI Agent Security in 2026: Prompt Injection and Memory Poisoning — swarmsignal.net
  16. The risk hiding behind exposed MCP servers — wiz.io
  17. The 'by design' security flaw of Model Context Protocol (MCP) — bdtechtalks.substack.com
  18. A Timeline of Model Context Protocol (MCP) Security Breaches — authzed.com
  19. Atlas: Wiz's autonomous AI Agent for vulnerability research, ranked #1 on CyberGym — wiz.io
  20. Can AI do novel security research? Meet the HTTP Terminator — portswigger.net
  21. Can AI do novel security research? Meet the HTTP Terminator — portswigger.net
  22. Claude Mythos: Preparing for a World Where AI Finds and Exploits Vulnerabilities Faster Than Ever — wiz.io
  23. What Is AI Pentesting and How Does It Works? — snyk.io
  24. Why You Need a Security Companion for AI-Generated Code — snyk.io
  25. Who was behind the attack? Possibly nobody — aikido.dev
  26. TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development — unit42.paloaltonetworks.com
  27. GhostSplice: Malicious MCP Servers Split Instructions to Make AI Coding Agents Exfiltrate Secrets (ASSET Research Group) — asset-group.github.io
  28. Stealing Reasoning Traces from Proprietary LLM APIs — stolen-thoughts.com
  29. "Context bombs" can frustrate AI-driven attacks researchers found — helpnetsecurity.com
  30. Person Hides Prompt Injection in Legal Filing Telling AI to Side with Them — 404media.co
  31. Ghostcommit attack hides malicious AI instructions in images — malwarebytes.com
  32. Agents hooked into GitHub can steal creds but Anthropic Google and Microsoft haven't warned users — theregister.com
  33. What Is Prompt Injection in AI? Examples & Prevention | EC-Council — eccouncil.org
  34. When AI Meets the Web: Prompt Injection Risks in Third-Party AI Chatbot Plugins — arxiv.org
  35. MCP Tool Poisoning — How It Works & How To Fight It — mcpmanager.ai
  36. MCP Security: Tool Poisoning Attacks - Invariant Labs — invariantlabs.ai
  37. MCP Auto-Execution: From Git Clone to Cloud Compromise in Amazon Q VS Code Extension — wiz.io
  38. The Vulnerable MCP Project: Comprehensive MCP Security Database — vulnerablemcp.info
  39. AI-Infra-Guard: Full-Stack AI Red Teaming Platform — github.com
  40. From Hugging Face to Fable: this summer shows AI control matters more than trust — aikido.dev
  41. Ultralytics AI Pwn Request Supply Chain Attack — snyk.io
  42. s1ngularity's Aftermath: AI, TTPs, and Impact in the Nx Supply Chain Attack — wiz.io
  43. How “Clinejection” Turned an AI Bot into a Supply Chain Attack — snyk.io
  44. HalluSquatting Turns AI Hallucinations Into Botnet Delivery Mechanism — securityweek.com
  45. Hackers can use 9 of the most popular AI tools to assemble massive botnets — arstechnica.com
  46. Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector — unit42.paloaltonetworks.com
  47. Your AI Agents Are Using Your Credentials — blog.gitguardian.com
  48. How to Control AI Assets Before They Become Shadow AI — jfrog.com
  49. Wiz Research Finds Critical NVIDIA AI Vulnerability Affecting Containers Using NVIDIA GPUs, Including Over 35% of Cloud Environments — wiz.io
  50. NVIDIAScape - Critical NVIDIA AI Vulnerability: A Three-Line Container Escape in NVIDIA Container Toolkit (CVE-2025-23266) — wiz.io
  51. Breaking NVIDIA Triton: CVE-2025-23319 - A Vulnerability Chain Leading to AI Server Takeover — wiz.io
  52. Agentic Browser Security: 2025 Year-End Review — wiz.io
  53. The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software — unit42.paloaltonetworks.com
  54. I found a WordPress RCEs with GPT5.6 and $25 — slcyber.io
  55. The emerging use of malware invoking AI — wiz.io
  56. Our AI pentesting engine talked a production AI agent's prompt-injection guardrail into handing over its entire system prompt on its second attempt. — escape.tech
  57. 7 AI Security Testing Tools for LLMs Agents and AI Pipelines (2026) — ox.security
  58. Beyond Prompt Injection — oreilly.com
  59. The Future of AI Agent Security Is Guardrails — snyk.io
  60. Trust No Skill: Integrity Verification for AI Agent Supply Chains — unit42.paloaltonetworks.com
  61. Identiverse 2026: The Challenges Of Solving Identity For AI Agents At Scale — blog.gitguardian.com
  62. F5 Integrates AI Guardrails with NVIDIA NeMo Guardrails to Strengthen Enterprise AI Security — thefastmode.com
  63. Secure at Inception: Introducing New Tools for Securing AI-Native Development — snyk.io
  64. Evo Adds CycloneDX Support to Give Full AI Visibility — snyk.io
  65. Stop Treating Coding Agent Plugins Like Settings: Introducing Agent Plugins Repositories — jfrog.com
  66. The Attacker Never Sleeps, Neither Can Your Testing — snyk.io
  67. 4 Advantages of using AI code review — snyk.io
  68. Essential AI Tools to Boost Developer Productivity and Security — snyk.io
  69. Find, auto-fix, and prioritize intelligently, with Snyk's AI-powered code security tools — snyk.io
  70. Introducing the Snyk AI Security Platform — snyk.io
  71. When Speed Meets Security: Snyk Studio for Kiro — snyk.io
  72. Secure by Design: The Future of Threat Modeling for AI-Native Applications — snyk.io
  73. The Mother of All AI Supply Chains: Critical Systemic Vulnerability at the Core of Anthropics MCP — ox.security
  74. AI Red Teaming Playground Labs (Microsoft) — github.com
  75. Introducing Wiz Agents & Workflows: Security at the Speed of AI — wiz.io
  76. The Rise of the AI Security Engineer: A New Discipline for an AI-Native World — snyk.io
  77. Auditing the Gatekeepers: Fuzzing "AI Judges" to Bypass Security Controls — unit42.paloaltonetworks.com
  78. Wiz Enhances AI-SPM Support for Amazon Bedrock — wiz.io
  79. Improve MTTR with Wiz’s AI-powered remediation guidance using Microsoft Azure OpenAI service — wiz.io
  80. SAPwned: SAP AI vulnerabilities expose customers’ cloud environments and private AI artifacts — wiz.io
  81. AI Security Solutions In 2026: Tools To Secure AI — wiz.io
  82. 7 AI Security Tools to Prepare You for Every Attack Phase — wiz.io
  83. Why We Built Evo — From My Heart — snyk.io
  84. Old AI Security vs Evo: Watch Agentic Security Replace Weeks of Manual Work — snyk.io
  85. AI Threat Readiness Pillar 3: Perform AI Code Analysis Natively in Wiz — wiz.io
  86. Securing AI Applications From Inception to Deployment — wiz.io
  87. Aikido and OWASP bring agentic Code Audit to the global AppSec community — owasp.org
  88. 5 security best practices for adopting generative AI code assistants like GitHub Copilot — snyk.io
  89. OrcaRouter Releases AI Threat Report 2026 and Makes Its Security Controls Free Amid Rise in Prompt-Injection Attacks — aninews.in
  90. LLM Red Teaming Guide (Open Source) - Promptfoo — promptfoo.dev
  91. LLM Security Guide: OWASP GenAI Top-10 Risks — github.com
  92. Building an Open-Source AI-Powered Auto-Exploiter with a 1.7B Parameter Model: No Paid APIs Required — mohitdabas.in
  93. DeepTeam: Open-Source Framework to Red Team LLMs and LLM Systems — github.com
  94. OWASP Top 10 for LLMs 2025 | DeepTeam Red Teaming Framework — trydeepteam.com
  95. MCP Safety Audit: LLMs with MCP Allow Major Security Exploits — arxiv.org
  96. MCP Tools: Attack Vectors and Defense Recommendations - Elastic Security Labs — elastic.co
  97. A Framework for AI Threat Readiness — wiz.io
  98. LLM01:2025 Prompt Injection | OWASP Gen AI Security — genai.owasp.org
  99. Practical LLM Security Advice from the NVIDIA AI Red Team — developer.nvidia.com
  100. Indirect Prompt Injection: The Hidden Threat — lakera.ai
  101. We Gave GPT 5.6 Sol a Real Business. It Lied, Spammed, and Lost $447 — bottlenecklabs.com
  102. AI’s Hacking Skills Are Approaching an ‘Inflection Point’ — wired.com
  103. OWASP Top 10 for LLMs 2025: Key Risks and Mitigation Strategies — invicti.com
  104. OWASP Top 10 for Agents 2026 — trydeepteam.com
  105. harishsg993010/crossbow-agent: world's first Opensource fully Autonomous AI Security Engineer — github.com
  106. KeygraphHQ/shannon: Fully autonomous AI hacker to find actual exploits in your web apps. Shannon has achieved a 96.15% success rate on the hint-free, source-aware XBOW Benchmark. — github.com
  107. Protestware by open source maintainer to hinder agentic coding: The jqwik 1.10.0 Prompt Injection — snyk.io
  108. What Is LLM (Large Language Model) Security? — paloaltonetworks.com
  109. AI QA vs AI Security Testing: Why LLM Apps Need Both Before They Scale — mexc.com
  110. RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data — varonis.com
  111. GhostApproval: A Trust Boundary Gap in AI Coding Assistants — wiz.io
  112. The risk in malicious AI models: Wiz Research discovers critical vulnerability in AI-as-a-Service provider, Replicate — wiz.io
  113. Probllama: Ollama Remote Code Execution Vulnerability (CVE-2024-37032) – Overview and Mitigations — wiz.io
  114. Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE — unit42.paloaltonetworks.com
  115. SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon — varonis.com
  116. AI Security 101: Mapping the AI Attack Surface — wiz.io
  117. Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security Incident — snyk.io
  118. Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs — wiz.io
  119. What an 'Aha' Moment with an Org Admin Token Taught One DevSecCon Speaker About AI Security — snyk.io
  120. Run AutoMCP To Supercharge Your AI Agent with Libraries MCP Servers — snyk.io
  121. ServiceNow's Virtual Agent Vulnerability Shows Why AI Security Needs Traditional AppSec Foundations — snyk.io
  122. Live From Davos: The End of Human-Speed Security — snyk.io
  123. How a Malicious Google Skill on ClawHub Tricks Users Into Installing Malware — snyk.io
  124. The Meta hack shows theres more to AI security than Mythos — technologyreview.com
  125. Building AI Security with Our Customers: 5 Lessons from Evo’s Design Partner Program — snyk.io
  126. You Patched LiteLLM, But Do You Know Your AI Blast Radius? — snyk.io
  127. Governing Security in the Age of Infinite Signal – From Discovery to Control — snyk.io
  128. Securing CI/CD in an agentic world: Claude Code Github action case — microsoft.com
  129. This article outlines some of the potential security risks through the lens of real-world AI and LLM applications assessed by Krolls Offensive Security team. Read more. — kroll.com
  130. Indirect Prompt Injection Is Now a Real-World AI Security Threat — techrepublic.com
  131. 7 Serious AI Security Risks and How to Mitigate Them — wiz.io
  132. Researchers Uncover 10 In-the-Wild Prompt Injection Payloads Targeting AI Agents — infosecurity-magazine.com
  133. Six AI Vulnerabilities Three Attack Patterns One Dangerous Service Gap — msspalert.com
  134. Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis — arxiv.org
  135. Prompt Injection 2.0: Hybrid AI Threats — arxiv.org
  136. Prompt injection turned Googles Antigravity file search into RCE — csoonline.com
  137. Protecting Against Indirect Prompt Injection Attacks in MCP — developer.microsoft.com
  138. Prompt Injection Attacks: Examples, Techniques, and Defence — blog.cyberdesserts.com
  139. Prompt Injection: The Most Common AI Exploit in 2025 — obsidiansecurity.com
  140. AI Prompt Injection Attacks: How They Work (2026) — theboard.world
  141. LLM Security Risks in 2026: Prompt Injection, RAG, and Shadow AI — sombrainc.com
  142. Best AI Security Tools in 2026 — repello.ai
  143. Prompt Injection Attacks in LLMs: What Developers Need to Know in 2026 — securityjourney.com
  144. LangChain LangGraph Flaws Expose Files Secrets Databases in Widely Used AI Frameworks — thehackernews.com
  145. Detecting and analyzing prompt abuse in AI tools — microsoft.com
  146. Red Teaming the Mind of the Machine: Evaluation of Prompt Injection and Jailbreak Vulnerabilities — arxiv.org
  147. Microsoft says bug causes Copilot to summarize confidential emails — bleepingcomputer.com
  148. Claude Opus 4.6 Finds 500+ High-Severity Flaws Across Major Open-Source Libraries — thehackernews.com
  149. Model Context Protocol (MCP): Understanding security risks and controls — redhat.com
  150. GitHub - JasonLovesDoggo/caddy-defender: Caddy module to block IPs and prevent AIs from training on your website. — github.com
  151. SSH LLM Honeypot caught a real threat actor - Beelzebub Blog — beelzebub-honeypot.com
  152. Microsoft Copilot: From Prompt Injection to Exfiltration of Personal Information · Embrace The Red — embracethered.com
  153. protectai/ai-exploits — github.com
📚 This guide is synthesized from the full text of resources curated in the AI library, and refreshed as new material is added.