Posts

Featured

OWASP Top 10 for LLM Applications 2026 - What Changed?

What is the OWASP LLM Top 10? The OWASP Top 10 for LLM Applications is a security awareness and risk framework for applications that use large language models. The 2026 edition continues that work but significantly changes the ranking and scope of several categories. One important change is how OWASP approached the ranking. The 2026 project compared practitioner opinion with evidence from 7,714 real incidents , with 6,639 incidents containing enough information to classify. Practitioner voting still carried most of the weight, while incident data contributed the remaining quarter. Why this matters: OWASP found that what security practitioners fear and what appears in public incident data do not always match. Prompt Injection remained #1 despite not appearing in the incident-data top 10, while Misinformation moved upward because the evidence showed it occurring more frequently than practitioners expected. Source: OWASP Top 10 for LLM Applications 2026. 2026 ...

TryHackMe Walkthrough: AI System Reconnaissance

TryHackMe Walkthrough: AI Reconnaissance AI systems are becoming part of modern infrastructure, but finding them is not always as straightforward as scanning for traditional services. AI platforms introduce new ports, APIs, protocols, model-serving endpoints, experiment trackers, vector databases, and supporting services that may not be correctly identified by standard security tools. This TryHackMe room focuses on AI reconnaissance,  finding, identifying, and enumerating AI infrastructure exposed within a network. Instead of starting with exploitation, the focus is on understanding what is actually deployed. Task 1 - Introduction This task introduces the concept of AI reconnaissance and explains how AI infrastructure differs from a traditional network. What is AI Reconnaissance? AI reconnaissance is the process of discovering AI and ML components in an environment, identifying what technologies they use, and determining what information or functionality they expos...

Gemini Spark: Being Security Conscious When AI Can Take Action?

💡 Introduction Without a doubt AI assistants are the new trend, the present. Modern AI systems can now interact with applications, access information, browse the web, and perform tasks without human intervention.  Google's Gemini Spark is an example of this latest trend toward more agentic AI. Instead of only generating a response, Spark can work on tasks in the background and interact with connected services under the user's guidance. This creates new opportunities for productivity, but it also introduces a different set of security responsibility. When an AI system can take actions, security is no longer only about protecting the model or the prompt. We need to be careful of what the AI can access, what actions it can perform, and what happens when it receives malicious instructions. 🤖 What is Gemini Spark? Gemini Spark is Google's personal AI agent designed to perform various day to day tasks and workflows on behalf of users. Unlike a traditional chat where the u...
Agentic AI Red-Team Test Case Generator // internal tooling Agentic AI Red-Team Tet Case Generator Ten test categories, one per entry in the OWASP Top 10 for Agentic Applications. Pick a category for a methodology-level test case. Source: OWASP GenAI Security Project - Agentic Security Initiative, Top 10 for Agentic Applications, Version 2026 (Dec 2025). genai.owasp.org/initiatives/agentic-security-initiative Select a category above to generate a test → Scope: For authorized testing of systems you own or have explicit permission to assess. Treat every finding as a defect report: what happened, why it matters, what to fix. Category names and IDs follow the OWASP Top 10 for Agentic Applications 2026. This tool is independent and not affiliated with or endorsed by OWASP.

Understand the Basics of OWASP Agentic Top 10

AI applications are evolving beyond simply getting a question answred or resolving an issue. AI agents can now plan tasks, use tools, access data, interact with other agents, and take variety of actions on behalf of users. This increased level of flexiblity also introduces new security risks. The OWASP Top 10 for Agentic Applications 2026 focuses on these risks and provides a practical guideline for securing agentic systems. Important: The Agentic Top 10 is not same as the OWASP Top 10 for LLM Applications. Agentic applications can still be affected by traditional LLM risks such as prompt injection, while adding risks related to autonomy, tools, identity, memory, and multi-agent communication. OWASP Top 10 for Agentic Applications The 2026 list contains top ten security risks identified: ID Risk ASI01 Agent Goal Hijack ASI02 Tool Misuse & Exploitation ASI03 Identity & Privilege Abuse ASI04 Agentic Supply Chain Vulnerabilities ASI05 Unexpected Code Exe...

🎯 OWASP LLM Top 10 Security Challenge

How well do you know the OWASP Top 10 for LLM  Applications ? Test your knowledge with these short AI security scenarios. How to play Read each scenario. Select the vulnerability you think applies. Get immediate feedback and an explanation. Question 1 / 10 Score: 0 Next 🏆 Challenge Complete Play Again Use this challenge as a quick way to test your understanding, then explore the individual OWASP categories in more detail. Educational content based on the OWASP Top 10 for LLM Applications. The scenarios are simplified for learning purposes.

Step up the security scanning in CI/CD pipeline with LLM

Security scanning has become an essential part of modern DevSecOps pipelines. Tools for SAST, SCA, DAST, container scanning, and infrastructure security can identify thousands of potential issues. However, finding a vulnerability is only the first step. Security teams and developers still need to understand the finding, determine its relevance, and decide how to remediate it. This is where Large Language Models (LLMs) are increasingly being integrated into security scanning workflows. Rather than replacing traditional security scanners, LLMs can act as an additional layer for understanding, triaging, and remediating security findings. Key Idea Traditional scanners find security issues. LLMs can help teams understand those findings, prioritize them, and work toward a fix. What Does LLM Integration Mean? In a traditional pipeline, a scanner analyzes the application and produces a security finding: Code -> Security Scanner -> Vulnerability Finding -> Developer/Se...

TryHackMe Walkthrough: Agent Evaluation

Task 1 - Introduction This section introduces the purpose of evaluating an AI security agent and explains why a correct final answer does not necessarily mean the investigation was performed correctly. The agent needs to be evaluated based on the evidence it retrieves, the decisions it makes, and whether changes improve its overall behaviour.