Topics
Browse posts by category and tag — every topic we cover, with the latest pieces under each.
Tags
- #ai-security-news 12
- #weekly-digest 12
- #policy 5
- #supply-chain 4
- #cve 3
- #agent-security 2
- #ai-security 2
- #atlas 2
- #jailbreak 2
- #owasp 2
- #rag-security 2
- #2025 1
- #certification 1
- #incidents 1
- #litellm 1
- #llm-security 1
- #llm-top-10 1
- #meta 1
- #model-extraction 1
- #model-unlearning 1
- #multimodal 1
- #nist 1
- #offensive-ai 1
- #phishing 1
- #practitioner 1
- #prompt-injection 1
- #regulatory 1
- #retrospective 1
- #risk-management 1
- #threat-intel 1
- #threat-intelligence 1
- #trends 1
- #vllm 1
- #year-in-review 1
Categories
digest 11 posts
- AI Security Week: May 22, 2026Google says it caught attackers using an LLM to find a zero-day, peer-reviewed research shows reasoning models can autonomously jailbreak other models, and a look back at the month's AI-infrastructure CVEs. Verify all specifics against primary sources.
- AI Security Week: May 18, 2026A self-propagating npm/PyPI worm sweeps up AI SDKs including Mistral AI and Guardrails AI, two critical RCE classes in the vLLM inference server, and the U.S. CAISI signs frontier-model pre-deployment testing agreements. Verify all specifics against primary sources.
- AI Security Week: May 13, 2026A critical pre-auth SQL injection in LiteLLM lands in CISA's KEV catalog, the EU reaches a provisional deal to delay and reshape the AI Act, and Microsoft details how prompt injection becomes RCE in agent frameworks. Verify all specifics against primary sources.
- AI Security Week: May 10, 2026Analysis and commentary: training-data poisoning as a durable class, ATLAS as a finding taxonomy, red-teaming through the data channel, and the EU AI Act's staged timeline. Verify all specifics against primary sources.
- AI Security Week: May 9, 2026Analysis and commentary: RAG retrieval as an injection channel, insecure output handling as the under-built control, the OWASP LLM Top 10 as an application checklist, and excessive agency in agent designs. Verify all specifics against primary sources.
- AI Security Week: May 8, 2026Analysis and commentary: the NIST AI RMF and its Generative AI Profile as a control map, the model/data supply-chain compromise class, why model extraction is a real business risk, and a defender's reading of safetensors. Verify all specifics against primary sources.
analysis 2 posts
- Understanding the OWASP LLM Top 10: What Matters MostOWASP published the LLM Top 10 in 2023 and updated it in 2025. The list is useful but requires interpretation. Here's which items are operationally relevant vs. theoretically important, and what to prioritize.
- AI Security Year in Review: 2025The five most consequential AI security developments of 2025: the shift from theoretical to operational attacks, the supply chain compromise wave, regulatory enforcement reaching AI, and what actually improved.