threat intelligence

What we're learning from inside production AI systems.

Briefings, dashboards, and sanitized engagement notes.

9 briefings

Jun 2026 · 10 minCRITICAL

Markdown Image Exfiltration: Your Chat UI Is the Side Channel

If your assistant renders markdown, a single injected image tag can exfiltrate the conversation — zero clicks, no tool access required. We found this in 11 of 14 audited chat deployments.

IPIOutput Handling
Read briefing →
May 2026 · 9 minHIGH

System Prompt Extraction Is an Economics Problem

Every system prompt we've been asked to protect, we've extracted — median time 41 minutes. The question isn't whether yours leaks. It's what the leak is worth to whoever pulls it.

ExtractionIPI
Read briefing →
Apr 2026 · 11 minHIGH

Tool Shadowing in MCP-Style Agent Stacks

One malicious tool description can redirect every tool call an agent makes — including calls to tools it doesn't own. The supply chain risk isn't the code. It's the metadata.

Tool HijackSupply Chain
Read briefing →
Mar 2026 · 12 minCRITICAL

Indirect Prompt Injection: The 2026 Attack Surface

Chained injection attacks against multi-agent systems have increased 312% in 12 months. Here's what changed and why standard guardrails fail.

IPIMulti-Agent
Read briefing →
Feb 2026 · 9 minHIGH

When Your RAG Doesn't Respect ACLs

67% of audited RAG systems return at least one document the requester shouldn't see. The root cause is almost never what you think.

RAGPermissions
Read briefing →
Feb 2026 · 8 minHIGH

Denial-of-Wallet: The Economics of LLM Abuse

A single recursive loop can drain a $50K monthly LLM budget in under 9 hours. Most systems have no circuit breaker.

DoWCost
Read briefing →
Jan 2026 · 11 minCRITICAL

Tool-Call Hijacking in Customer Support Agents

When an agent has tool access, injection attacks don't stop at text. We document three production compromises involving real tool execution.

Tool HijackAgent
Read briefing →
Jan 2026 · 7 minMEDIUM

Embedding Inversion Attacks on Production Vector DBs

Proprietary training data can be partially reconstructed from embedding endpoints. Here's the attack surface and what to close.

Model TheftEmbeddings
Read briefing →
Dec 2025 · 10 minHIGH

The Semantic Cache Poisoning Playbook

Semantic caches built for performance are trivially exploitable for injection persistence. One poisoned cache entry can affect thousands of users.

IPICache
Read briefing →