AI

Who should worry about prompt injections?

Prompt injection is a very new subject in security. If you, like me, don’t have all the time to dedicate to it, it’s quite hard to grasp all the possible insecure scenarios. But luckily, rez0, probably the most active AI hacker, published Prompt Injection Primer for...

LLM OWASP TOP 10

I think OWASP TOP 10 lists are great resources for developers. They have a single resource that can give them sufficient amount of information to be at least somewhat aware of what risks are present. It’s also good when you are just getting familiar with a new area of...

AI Canaries

When I was creating the transcript of my latest video, I asked chatGPT to add some interpunction and change the capitalization of the text, without modifying the content. But in the middle of the text, chat stopped rewriting the transcript and started to explain to me...

The AI Attack Surface Map

AI is a new and emerging area and so is its cybersecurity. One of the very first comprehensive resources about potential attack vectors is this AI Attack surface map by Daniel Miessler. Use it as a starting point whenever you are auditing AI-based solutions....

Where to start AI hacking?

I’ll admit that I have a strange feeling of relief because of the current AI hype. I wanted to learn something new for a long time now. There was Web3 for a while but it didn’t convince me as a user. I saw the huge bounties, I saw the success of Gary V and I thought...