Llm security

GPT-Red: Can AI read teams stop prompt injections?

GPT-Red: Can AI read teams stop prompt injections?

This podcast explores AI's impact on cybersecurity, discussing OpenAI's GPT-Red for automated red-teaming against prompt injections, the open-source ScamBuster that uses AI to bait scammers for threat intelligence, and Bruce Schneier's insights on the widening gap between skill and ability in the AI era and its ethical implications for the field.

Through the AI Fog: The Architectural Decision Agentic Security Depends On — Manoj Nair, Snyk

Through the AI Fog: The Architectural Decision Agentic Security Depends On — Manoj Nair, Snyk

Manoj Nair of Snyk reveals alarming data on AI-driven security risks, emphasizing that generative AI and validation systems cannot be the same. He highlights issues like autonomous attacks, rampant vulnerabilities in AI-generated code and skills, and PII leakage. Snyk's solution, Evo, integrates deterministic prevention and remediation to secure the agentic development lifecycle.

Fable 5, GPT-5.6 and the high stakes of AI safeguards. Agentic ransomware, ClickFix reigns supreme

Fable 5, GPT-5.6 and the high stakes of AI safeguards. Agentic ransomware, ClickFix reigns supreme

This podcast explores the critical role of safeguards in frontier AI models like Anthropic's Fable 5 and OpenAI's GPT-5.6 Sol, analyzing the tension between powerful capabilities and misuse prevention. It also dissects the emergence and debate around agentic ransomware, specifically Jade Puffer, and covers the rise of ClickFix as a dominant social engineering attack targeting developers. Finally, it provides an in-depth analysis of UnregStealer, a credential-theft campaign impacting Latin American financial institutions, detailing its attack chain and mitigation strategies.

The Promptware Kill Chain: How Prompt Injection Becomes AI Malware

The Promptware Kill Chain: How Prompt Injection Becomes AI Malware

Promptware introduces a new class of AI malware leveraging prompt injections to exploit architectural flaws in LLMs. This summary details The Promptware Kill Chain, covering stages from initial access and jailbreaking to persistence, lateral movement, and real-world impact. It emphasizes the critical need for a Zero Trust approach, treating AI agents as hostile runtimes to defend against these sophisticated AI-native threats.

OWASP's Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed

OWASP's Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed

A detailed breakdown of the updated OWASP Top 10 vulnerabilities for Large Language Models (LLMs), explaining threats like prompt injection, data poisoning, and supply chain risks, along with practical defense strategies.

The #1 AI Agent on GitHub Was Never Read by Its Creator

The #1 AI Agent on GitHub Was Never Read by Its Creator

Jason Martin of HiddenLayer discusses the significant security vulnerabilities of OpenClaw, a viral open-source AI personal assistant. The analysis covers critical flaws like prompt injection, insecure defaults, and the potential for creating sophisticated botnets, offering key lessons for securing the next generation of autonomous AI agents.