Field notes on the AI attack surface — shadow LLMs and agents, prompt injection, MCP supply-chain risk, and the regulation that's about to demand you have answers. Written by the team building AI Security Posture Management.
Practical, vendor-neutral writing for security teams putting AI into production — or discovering, too late, that their organisation already has. No hype, no lorem ipsum: each piece is meant to leave you with something you can act on this week.
Unsanctioned LLMs, agents, and MCP servers are already in your fleet — here's why discovery has to come first.
Direct vs. indirect injection, real-world examples, and why OWASP ranks it as the number-one LLM risk.
The adversarial-testing duty, the evidence you'll be asked for, and the timelines that are already live.
Over-broad tool scope, typosquatting, and tool poisoning — plus a hardening checklist you can run today.