// llm security

All signals tagged with this topic

LLMs Are Becoming a New Vector for API Attacks

As applications pile permissions and rely on chain-of-command API calls, large language models have reduced the technical barrier for crafting sophisticated exploits—attackers no longer need deep API knowledge to discover and chain together vulnerabilities. Prompt engineering is now a viable hacking methodology. Defenders face attackers who can operate at human-like speed across distributed systems without traditional coding skills. Organizations betting on "secure by default" architectures will outpace those still managing sprawling permission models designed for monolithic applications.

Toronto researchers build AI-powered worm that customizes attacks per system

A team at the University of Toronto has demonstrated that open-source language models can autonomously discover and exploit known vulnerabilities, then adapt their approach to individual targets. What was previously labor-intensive manual work is now scalable and self-directed. Researchers built a working prototype using publicly available tools, meaning defenders now face an adversary that doesn't tire and can iterate faster than human operators. The security industry will need to move beyond patching individual holes toward systemic resilience. The constraint preventing widespread AI-driven attacks has shifted from capability to incentive.