AI Security
New vulnerabilities, exploit writeups, agent abuse patterns, jailbreaks, model theft, data leakage, and supply-chain risk.
3 signals
OWASP’s 2026 risk ranking elevates excessive agency
Open
CSO Online reports that prompt injection and sensitive information disclosure remain the leading LLM risks, while excessive agency rose to third place. The change reflects the security impact of systems that call APIs, execute code, and take actions beyond simple text generation.[1]
Why it matters
Security reviews should test agent permissions, tool boundaries, approval gates, and authorization independently of prompt filtering.
CSO Online
OWASP agentic risks include tool misuse and privilege abuse
Open
OWASP’s Agentic Applications material highlights agent behavior hijacking, tool misuse and exploitation, and identity and privilege abuse as agent-specific threats. The project presents these risks as part of a dedicated security framework for autonomous AI applications.[4]
Why it matters
Agent architectures need explicit identity, least-privilege, tool-validation, and inter-agent trust controls.
OWASP GenAI Security Project
OWASP 2026 list covers supply chain, poisoning, and embedding weaknesses
Open
The Cloud Security Alliance’s review of the OWASP 2026 ranking lists prompt injection, sensitive information disclosure, excessive agency, supply chain, data and model poisoning, unbounded consumption, hidden context exposure, vector and embedding weaknesses, and improper output handling among the ten risks. It also notes cross-references to NIST, MITRE ATLAS, and CWE.[6]
Why it matters
AI security programs should extend beyond jailbreak testing to dependency provenance, retrieval integrity, resource controls, and output validation.
Cloud Security Alliance