Securing AI & LLM Systems
Large language models and AI agents introduce a security surface that doesn't map cleanly onto traditional web application risks: prompt injection instead of SQL injection, model poisoning instead of supply chain tampering, excessive agency instead of privilege escalation. This hub collects everything on FixTheVuln for defending against it — the OWASP LLM Top 10 broken down technique by technique, deep dives on specific attack classes, career guidance for the emerging AI security field, and ongoing research coverage.
AI Security Guides
OWASP LLM Top 10
All 10 risk categories for LLM applications with attack scenarios and mitigations
💉Prompt Injection
Direct vs indirect injection attacks, taxonomy, and defense strategies with code examples
☠️AI Model Poisoning
Data poisoning, backdoor attacks, detection methods, and prevention strategies
🔬MLSecOps Pipeline
Secure ML pipeline architecture, data/model/inference security, and maturity model
🕵️AI Agent Security
How AI coding agents become insider threats — rules file poisoning, MCP exploitation, and defense strategies
🔌AI Agent Security Threats
Threat taxonomy for AI agent plugins and skills — injection, exfiltration, tool poisoning, and supply chain attacks
🎯AI Security Careers
AI red team, ML security engineer, and AI governance roles with skills matrix and cert pathways
🗄️GenAI Data Security (OWASP)
21 data-layer risks for GenAI systems — vector stores, context windows, agent credentials, and AI-DSPM framework
OWASP LLM Top 10 Technique Library
Each risk category from the OWASP LLM Top 10, broken out into its own reference page with a risk rating, attack example, and mitigation checklist.
LLM01: Prompt Injection
Critical
●LLM02: Sensitive Information Disclosure
Critical
●LLM03: Supply Chain Vulnerabilities
High
●LLM04: Data and Model Poisoning
High
●LLM05: Improper Output Handling
Critical
●LLM06: Excessive Agency
Critical
●LLM07: System Prompt Leakage
High
●LLM08: Vector and Embedding Weaknesses
High
●LLM09: Misinformation
Medium
●LLM10: Unbounded Consumption
High
AI Security Practice Quizzes
AI Security Practice Quiz
30 questions covering LLM and AI application security fundamentals
📝CompTIA SecAI+ Practice Quiz
CY0-001 exam objectives practice questions
📝Azure AI Engineer (AI-102)
Practice questions for the Azure AI Engineer Associate exam
📝Azure AI Fundamentals (AI-900)
Practice questions for the Azure AI Fundamentals exam
Featured AI Security Reading
Agentic AI: the #1 Threat in 2026
How agentic AI risk maps to the Security+ exam objectives
📰37 Vulnerabilities in AI Coding Tools
Zero-click RCE disclosed across 15+ AI IDE vendors
📰AI Agent Supply Chain Attacks
How compromised agent tooling becomes a supply chain risk
📰Your AI Notetaker Is a Security Risk
Excessive agency in everyday productivity AI tools
📰AI Incident Response
12x more findings in 1/7th the time — what changed
📰AI Vulnerability Discovery at 61 Cents Each
What automated vulnerability discovery means for security teams
📰5 GenAI Data Risks Teams Are Ignoring
OWASP's 2026 GenAI data security guidance, summarized
📅Weekly AI Security Roundup
New AI security news and research, aggregated every Friday
Stay Updated
Get weekly AI security research, technique breakdowns, and vulnerability alerts.
No spam. Unsubscribe anytime.
Building AI Security Skills?
Track your AI security learning alongside every other certification and skill on your plate:
Build Your Portfolio on CyberFolio →FixTheVuln Store
Get Your Certification Study Planner
Fillable PDF study planners with domain trackers, weekly schedules, and progress tracking. Available in Standard, ADHD-Friendly, Dark Mode, and 4-Format Bundle.
Browse Planners60+ certifications available — from $5.99