New preprint: AI_Bleeding β€” inference cost amplification via OOD linguistic payload

TL;DR: send queries in Grecanico or Farsi to an LLM endpoint β†’ TTFT +59.8%, compute cost +2.8%, statistically significant. No vuln, no volumetric signature, evades all standard detection.

Worst case: exposed unauthenticated Ollama instance with num_predict=4096 + keep_alive=300s β†’ Amplification Factor 17.56 Wh/KB. 3KB of attacker bandwidth β†’ enough energy to charge a phone 5%.

Especially nasty for:
- PA/judicial chatbots on fixed budgets
- Pay-per-use API deployments with client-side exposed keys
- PNRR-funded public sector AI with zero inference monitoring

Four scenarios: EDoS, browser JS distribution, Ollama open-proxy relay, frontier providers as involuntary relays.

All tests on self-hosted Ollama, no commercial endpoints touched.

Paper (CC BY 4.0): https://doi.org/10.13140/RG.2.2.26767.96166

#llmsecurity #infosec #threatmodeling #ollama #ood #AI #AIResearch #aisecurity

Does anyone here have experience with Indirect Prompt Injection / Prompt Honeypots?

I'm looking to hear your experiences or get pointed to some good material on the matter.

I'd like to know what possibilities there are, especially aimed towards docx and pdf files.

The goal is to make it harder (time consuming / inaccurate / impossible) to do inference on those types of documents.

I'd appreciate boosting to get better reach.

#AI #LLM #AIsecurity #PromptInjection #LLMsecurity #AISafety

What is the OWASP Top 10 Agentic AI

Explore OWASP’s 2025 Agentic AI Threats & Mitigations Guide. View the top risks of autonomous AI agent and strategies to secure multi-agent systems and safeguard data.

Graylog
OWASP dropped in 2026, the Top 10 for Agentic AI 🚨 The threat landscape for agentic systems goes way beyond prompt injection. Worth a read if you're building with AI agents. πŸ”— graylog.org/post/what-is... #AgenticAI #OWASP #CyberSecurity #AppSec #LLMSecurity

What is the OWASP Top 10 Agent...
What is the OWASP Top 10 Agentic AI

Explore OWASP’s 2025 Agentic AI Threats & Mitigations Guide. View the top risks of autonomous AI agent and strategies to secure multi-agent systems and safeguard data.

Graylog

⚑ Fresh Talk Alert for BSides Luxembourg 2026!

β€œπ—•π—˜π—¬π—’π—‘π—— π—§π—›π—˜ 𝗣π—₯𝗒𝗠𝗣𝗧: 𝗔 𝗙π—₯π—”π— π—˜π—ͺ𝗒π—₯π—ž 𝗙𝗒π—₯ π—”π—šπ—˜π—‘π—§π—œπ—– π—”π—œ π—”π—§π—§π—”π—–π—ž 𝗔𝗑𝗗 π——π—˜π—™π—˜π—‘π—¦π—˜ 𝗦𝗧π—₯π—”π—§π—˜π—šπ—œπ—˜π—¦β€ – π—π—˜π—₯π—˜π— π—¬ π—¦π—‘π—¬π——π—˜π—₯

As AI systems evolve into autonomous agents capable of executing code, calling APIs, and managing long-term memory, the attack surface extends far beyond prompt injection and jailbreaks. This AI Security Village session explores a full-stack approach to securing agentic AI systems.

Jeremy Snyder will break down how attackers target not just the LLM itself, but the broader agent architecture β€” including tools, memory, workflows, and cross-system integrations. The session introduces a practical framework for assessing agent attack surfaces, validating outputs, enforcing constraints during system handoffs, and building more resilient AI-driven applications.

Jeremy Snyder is the founder and CEO of FireTail, an AI security platform focused on securing modern AI applications and autonomous systems.

πŸ“… Conference Dates: 6–8 May 2026 | 09:00–18:00
πŸ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
πŸ“… Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026

#BSidesLuxembourg2026 #AISecurity #AgenticAI #LLMSecurity #CyberSecurity #AppSec #OWASP

⚑ Fresh Talk Alert for BSides Luxembourg 2026!

β€œπ—˜π—©π—˜π—₯𝗬 π—šπ—¨π—”π—₯𝗗π—₯π—”π—œπ—Ÿ π—˜π—©π—˜π—₯𝗬π—ͺπ—›π—˜π—₯π—˜ π—”π—Ÿπ—Ÿ 𝗔𝗧 π—’π—‘π—–π—˜: π——π—˜π—¦π—œπ—šπ—‘π—œπ—‘π—š 𝗔𝗑𝗗 π—§π—˜π—¦π—§π—œπ—‘π—š π—šπ—¨π—”π—₯𝗗π—₯π—”π—œπ—Ÿπ—¦ 𝗙𝗒π—₯ π—Ÿπ—Ÿπ—  π—”π—£π—£π—Ÿπ—œπ—–π—”π—§π—œπ—’π—‘π—¦β€ – 𝗗𝗒𝗑𝗔𝗧𝗒 π—–π—”π—£π—œπ—§π—˜π—Ÿπ—Ÿπ—”

Modern GenAI applications are no longer simple chatbots β€” they involve complex chains of LLM calls, tools, and autonomous workflows. In this AI Security Village session, Donato Capitella explores why prompt-based guardrails alone are not enough and how security controls must be designed around the entire application workflow.

The talk focuses on practical strategies for designing and testing guardrails across multi-step LLM systems, including how data flows between chains, how permissions are enforced, and how applications can detect and respond to prompt attacks. Attendees will also see how these concepts can be tested in practice using spikee, an open-source tool built for testing LLM applications against prompt-based attacks.

Donato Capitella is a Principal Security Consultant at Reversec with extensive experience in offensive security and AI application testing. He is also the lead developer of the open-source project spikee.

πŸ“… Conference Dates: 6–8 May 2026 | 09:00–18:00
πŸ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
πŸ“… Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026

#BSidesLuxembourg2026 #AISecurity #LLMSecurity #PromptInjection #CyberSecurity #OWASP #OpenSource #AppSec

⚑ Fresh Talk Alert for BSides Luxembourg 2026!

β€œπ—¦π—˜π—–π—¨π—₯π—œπ—§π—¬ 𝗙𝗒π—₯ π—”π—œ: π—”π—œπ——π—₯ π—•π—”π—¦π—§π—œπ—’π—‘ 𝗔𝗦 π—’π—£π—˜π—‘ 𝗦𝗒𝗨π—₯π—–π—˜ π—Ÿπ—Ÿπ—  π—™π—œπ—₯π—˜π—ͺπ—”π—Ÿπ—Ÿ / π—”π—œ 𝗣π—₯𝗒𝗠𝗣𝗧𝗦 π—₯π—˜π—©π—˜π—₯π—¦π—˜ 𝗣π—₯𝗒𝗫𝗬” – Andrii Bezverkhyi

As AI adoption accelerates, so do the risks β€” from prompt injections to malicious AI agents and adversarial abuse. This AI Security Village session explores AIDR Bastion, an open-source GenAI protection system designed to secure AI workloads through layered detection and prompt filtering.

The talk covers how AIDR Bastion acts as an LLM firewall and reverse proxy for AI prompts, using Sigma and Roota rules to detect malicious behavior, harmful content, prompt injection attacks, and AI-assisted malware generation. Attendees will also see how the system integrates with MITRE ATLAS, OWASP LLM Top 10 guidance, and existing detection engineering workflows.

Andrii Bezverkhyi is the founder of SOC Prime and a long-time contributor to the threat detection and cybersecurity community, known for projects such as Uncoder and DetectFlow.

πŸ“… Conference Dates: 6–8 May 2026 | 09:00–18:00
πŸ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
πŸ“… Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026

#BSidesLuxembourg2026 #AISecurity #LLMSecurity #PromptInjection #OWASP #CyberSecurity #DetectionEngineering #OpenSource

⚑ Fresh Village Alert for BSides Luxembourg 2026!

π—”π—œ π—¦π—˜π—–π—¨π—₯π—œπ—§π—¬ π—©π—œπ—Ÿπ—Ÿπ—”π—šπ—˜ – π—’π—£π—˜π—‘ π—©π—œπ—Ÿπ—Ÿπ—”π—šπ—˜ / 𝗀&𝗔
🧠 Interactive AI Security Playground β€’ Live Demos β€’ Hands-on Attacks β€’ Real-Time Defense

Step into a live, open-floor AI Security Village dedicated to exploring the real-world security risks of Agentic AI, MCP architectures, LLM workflows, and autonomous systems. Unlike a traditional workshop or talk, this village is designed as a continuously running interactive environment where attendees can freely drop in, attack systems, observe defenses, and shape the direction of the sessions in real time.

Across two days, participants will interact with intentionally vulnerable AI systems, RAG pipelines, MCP servers, and autonomous agents while exploring attack paths such as prompt injection, goal hijacking, instruction manipulation, tool abuse, and trust boundary failures β€” all aligned with the OWASP LLM Top 10 and AI Security Exchange guidance.

The village includes:
πŸ”Ή Live exploitation of LLM and Agentic AI systems
πŸ”Ή Interactive walkthroughs from organizers
πŸ”Ή Real-time defensive patching and mitigation demos
πŸ”Ή Hands-on labs with Dreadnode Crucible, Lakera Gandalf, and Agent Breaker
πŸ”Ή Beginner-to-advanced learning paths running in parallel
πŸ”Ή Community-driven Q&A and collaborative defense discussions

Parth Shukla is a Senior Security Researcher specializing in AI Security and Adversarial Machine Learning, focusing on the security architecture of Agentic Systems and LLMs. Joining him is Nagarjun Rallapalli, who focuses on automating security and building β€” and breaking β€” AI agents to test their limits.

πŸ“… Conference Dates: 6–8 May 2026 | 09:00–18:00
πŸ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
πŸ“… Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026

#BSidesLuxembourg2026 #AISecurity #LLMSecurity #AgenticAI #OWASP #RedTeam #CyberSecurity #PromptInjection #MCP #AIVillage

⚑ Fresh Talk Alert for BSides Luxembourg 2026!

π—•π—¨π—œπ—Ÿπ——π—œπ—‘π—š π—§π—›π—˜ π—¨π—Ÿπ—§π—œπ— π—”π—§π—˜ π—”π—œ π—™π—œπ—₯π—˜π—ͺπ—”π—Ÿπ—Ÿ: π—œπ—‘π—¦π—œπ——π—˜ π—¦π—’π—©π—˜π—₯π—˜π—œπ—šπ—‘π—¦π—›π—œπ—˜π—Ÿπ——, π—œπ—‘π—§π—˜π—‘π—§π—¦π—›π—œπ—˜π—Ÿπ——, 𝗔𝗑𝗗 π—Ÿπ—’π—šπ—œπ—–π—¦π—›π—œπ—˜π—Ÿπ—— – Mattijs Moens

As AI agents evolve into autonomous systems capable of executing code and interacting with APIs, traditional security controls are struggling to keep up. This AI Security Village session dives into the architecture behind the SovereignShield ecosystem β€” a multi-layered framework built to secure modern AI applications against prompt injection, malicious actions, and data exfiltration.

The talk explores how LogicShield enforces semantic boundaries to stop jailbreaks and prompt attacks, how IntentShield audits outbound AI actions before execution, and how the unified SovereignShield Firewall combines both layers into a deterministic defense model for production AI systems.

Mattijs Moens is an AI security researcher and founder of SovereignShield, focused on building semantic firewalls for AI systems. He also contributes to the OWASP AI Security and Privacy Guide (AISVS).

πŸ“… Conference Dates: 6–8 May 2026 | 09:00–18:00
πŸ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
🎟️ Tickets: https://2026.bsides.lu/tickets/
πŸ“… Schedule: https://hackertracker.app/schedule?conf=BSIDESLUX2026

#BSidesLuxembourg2026 #AISecurity #LLMSecurity #PromptInjection #OWASP #CyberSecurity #AIAgents

Releasing AgentGuard: architectural safety layer for AI agents.

Not prompt engineering. Code.

@protect
def delete_db(): ...

The LLM cannot call this. Ever. No prompt bypasses a raise.

Blocks: irreversible tool calls, prompt injection, context dilution, cross-agent contamination.

Rust core + pure Python fallback. 31/31 e2e tests with real Ollama.

https://github.com/psychomad/AgentGuard

"Don't blame the knife. Fix the architecture."

#InfoSec #LLMSecurity #AIAgents #PromptInjection #OpenSource #Rust

GitHub - psychomad/AgentGuard: Architectural safety layer for AI agents. Not prompt engineering β€” code.

Architectural safety layer for AI agents. Not prompt engineering β€” code. - psychomad/AgentGuard

GitHub