Posts

Showing posts from September, 2026

Gemini Spark: Being Security Conscious When AI Can Take Action?

💡 Introduction Without a doubt AI assistants are the new trend, the present. Modern AI systems can now interact with applications, access information, browse the web, and perform tasks without human intervention.  Google's Gemini Spark is an example of this latest trend toward more agentic AI. Instead of only generating a response, Spark can work on tasks in the background and interact with connected services under the user's guidance. This creates new opportunities for productivity, but it also introduces a different set of security responsibility. When an AI system can take actions, security is no longer only about protecting the model or the prompt. We need to be careful of what the AI can access, what actions it can perform, and what happens when it receives malicious instructions. 🤖 What is Gemini Spark? Gemini Spark is Google's personal AI agent designed to perform various day to day tasks and workflows on behalf of users. Unlike a traditional chat where the u...
Agentic AI Red-Team Test Case Generator // internal tooling Agentic AI Red-Team Tet Case Generator Ten test categories, one per entry in the OWASP Top 10 for Agentic Applications. Pick a category for a methodology-level test case. Source: OWASP GenAI Security Project - Agentic Security Initiative, Top 10 for Agentic Applications, Version 2026 (Dec 2025). genai.owasp.org/initiatives/agentic-security-initiative Select a category above to generate a test → Scope: For authorized testing of systems you own or have explicit permission to assess. Treat every finding as a defect report: what happened, why it matters, what to fix. Category names and IDs follow the OWASP Top 10 for Agentic Applications 2026. This tool is independent and not affiliated with or endorsed by OWASP.

Understand the Basics of OWASP Agentic Top 10

AI applications are evolving beyond simply getting a question answred or resolving an issue. AI agents can now plan tasks, use tools, access data, interact with other agents, and take variety of actions on behalf of users. This increased level of flexiblity also introduces new security risks. The OWASP Top 10 for Agentic Applications 2026 focuses on these risks and provides a practical guideline for securing agentic systems. Important: The Agentic Top 10 is not same as the OWASP Top 10 for LLM Applications. Agentic applications can still be affected by traditional LLM risks such as prompt injection, while adding risks related to autonomy, tools, identity, memory, and multi-agent communication. OWASP Top 10 for Agentic Applications The 2026 list contains top ten security risks identified: ID Risk ASI01 Agent Goal Hijack ASI02 Tool Misuse & Exploitation ASI03 Identity & Privilege Abuse ASI04 Agentic Supply Chain Vulnerabilities ASI05 Unexpected Code Exe...

🎯 OWASP LLM Top 10 Security Challenge

How well do you know the OWASP Top 10 for LLM  Applications ? Test your knowledge with these short AI security scenarios. How to play Read each scenario. Select the vulnerability you think applies. Get immediate feedback and an explanation. Question 1 / 10 Score: 0 Next 🏆 Challenge Complete Play Again Use this challenge as a quick way to test your understanding, then explore the individual OWASP categories in more detail. Educational content based on the OWASP Top 10 for LLM Applications. The scenarios are simplified for learning purposes.

Step up the security scanning in CI/CD pipeline with LLM

Security scanning has become an essential part of modern DevSecOps pipelines. Tools for SAST, SCA, DAST, container scanning, and infrastructure security can identify thousands of potential issues. However, finding a vulnerability is only the first step. Security teams and developers still need to understand the finding, determine its relevance, and decide how to remediate it. This is where Large Language Models (LLMs) are increasingly being integrated into security scanning workflows. Rather than replacing traditional security scanners, LLMs can act as an additional layer for understanding, triaging, and remediating security findings. Key Idea Traditional scanners find security issues. LLMs can help teams understand those findings, prioritize them, and work toward a fix. What Does LLM Integration Mean? In a traditional pipeline, a scanner analyzes the application and produces a security finding: Code -> Security Scanner -> Vulnerability Finding -> Developer/Se...

TryHackMe Walkthrough: Agent Evaluation

Task 1 - Introduction This section introduces the purpose of evaluating an AI security agent and explains why a correct final answer does not necessarily mean the investigation was performed correctly. The agent needs to be evaluated based on the evidence it retrieves, the decisions it makes, and whether changes improve its overall behaviour.

Amazon Bedrock Security: Prompt Injection & Abuse Detection

Image
Amazon Bedrock makes it easier to build generative AI applications using foundation models without managing the underlying model infrastructure. However, using a managed AI service does not remove application-level security risks. Two important areas to understand are prompt injection and abuse detection . 1. Prompt Injection Prompt injection occurs when untrusted instructions influence an AI model to behave in ways that were not intended by the application developer. These instructions can come directly from users or indirectly from content such as documents retrieved by a RAG application. Example: A user asks an AI assistant to summarize a document. The document contains hidden instructions telling the model to ignore its original task and reveal sensitive information. This is why prompt injection should be treated as an application security problem , not simply a model problem. Useful controls include: Validate and sanitize untrusted input. Use Amazon Bedroc...
AI Red-Team Test Case Generator // internal tooling AI Red-Team Test Case Generator: LLM Ten test categories, one per entry in the OWASP Top 10 for LLM Applications. Pick a category to get a methodology/a testing approach Source: OWASP GenAI Security Project - Top 10 for LLM Applications 2026, published Aug 4 2026. genai.owasp.org/llm-top-10 Select a category above to generate a test → Scope: For authorized testing of systems you own or have explicit permission to assess. Treat every finding as a defect report: what happened, why it matters, what to fix. Category names and IDs follow the OWASP Top 10 for LLM Applications 2026. This tool is independent and not affiliated with or endorsed by OWASP.

AI Security Architecture Review: Reviewing a Realistic Enterprise AI Assistant

AI assistants are increasingly moving beyond simple question-and-answer interfaces. Modern assistants can retrieve internal documents, query databases, call APIs, create tickets, send messages and perform actions on behalf of users. That changes the security problem significantly. The model is no longer simply generating text. It becomes one component inside a larger application that has identities, data stores, APIs, tools and business permissions. In this article, we will perform a security architecture review of a fictional enterprise AI assistant and identify where the design could fail. 1. The Scenario Imagine an organization has built an internal AI assistant called HelpDesk AI . Employees can use it to: Ask questions about company policies Search internal documentation Check the status of support tickets Create new support tickets Retrieve information about their assigned devices Ask the assistant to perform selected help-desk actions ...