MCP & AI Agent Attacks
The Model Context Protocol is "USB-C for AI" — it lets agents plug into tools, and it ships a brand-new attack surface most teams …
AI/LLM Security → All AI/LLM Security articles
The Model Context Protocol is "USB-C for AI" — it lets agents plug into tools, and it ships a brand-new attack surface most teams …
Companies bolt an LLM chatbot onto their product and nobody pen-tests it — "it is just the AI feature." But the AI is a new untrus…
Three seconds of audio clones a voice. One photo drives a live face-swap on a video call. The $25M Arup wire fraud ran on a fully …
The AI pair-programmer reads your code, suggests new code, and increasingly edits files and runs commands — and each is a security…
Every attack in this track meets the same answer: defense-in-depth, because no single control holds. Safety gets baked into the we…
Turn the model around and it becomes the attacker's tool — a copilot that parses recon and drafts payloads, or an autonomous agent…
Once a model can read images and hear audio, the picture and the sound become instruction channels — and the safety layer is usual…
A backdoored model is correct on everything you test — and wrong exactly when the attacker wants. A secret trigger, a pixel patch …
Downloading a model is running a stranger's code and data. You pull weights from a hub by name, often automatically at runtime, an…
The model sees system prompt, retrieved docs, and user input as one flat token stream — no seam. To exploit that you need to under…