THR-01
The concrete attacks that hit LLM apps and agents: prompt injection, jailbreaks, indirect injection through retrieval, model extraction, data poisoning, MCP tool poisoning, agent goal hijacking, confused-deputy abuse, supply-chain model attacks, and more.
- Severity ranked · OWASP-aligned
- Attack flow + example for each
- Filterable by surface & category
INC-02
What actually broke in the wild. The ChatGPT session leak, Samsung's source-code spill, the Biden deepfake robocall, the Air Canada chatbot liability case, plugin RCE, and how each one happened — and what we learned (or didn't).
- Timeline · impact · root cause
- Lessons, not just news ticker
- Sort by year, surface, severity
DEF-03
Defense in depth for AI systems: input guards, prompt isolation, structured output, tool permissioning, sandboxing, red teaming, evaluation harnesses, monitoring, and human-in-the-loop. With code patterns you can borrow from.
- Layered, not silver bullets
- Concrete config & prompt patterns
- Trade-offs called out honestly
STD-04
The actual rules of the road: OWASP Top 10 for LLM Apps (2025), NIST AI RMF 1.0 & Generative AI Profile, ISO/IEC 42001, EU AI Act phases, the UK/US AI Safety Institutes, vendor RSPs (Anthropic, OpenAI, Google). What binds whom, and when.
- Side-by-side comparison
- Enforcement timelines
- What applies to your product
LEX-05
Plain-language definitions for the words that get waved around in AI security docs: "indirect prompt injection", "many-shot jailbreak", "RAG poisoning", "tool injection", "MCP rug-pull", "capability scaling", "evals", "sleepered model", "C2PA provenance" — and what each term actually means.
- Searchable + alphabetical
- See-also links between terms
- One-screen, one definition
TLN-06
A decade of AI security in order: Microsoft Tay (2016), the original Cambridge Analytica blowback, Deepfake inception (2017), the ChatGPT launch (Nov 2022), the ChatGPT session leak (Mar 2023), o1 / EU AI Act passage (2024) … through mid-2026. See how the field actually got here.
- Color-coded by severity
- Milestones, winters, incidents
- Linked to incident pages