Our engineers set up and run your first chatbot / LLM security scan. Get in touch

AI Security Research Blog

AI-SPM research and engineering wiki.

20 practitioner articles on AI-SPM, LLM security testing, MCP security, RAG security, and AI compliance. Written by the engineering, security research, and compliance teams.

20 articles, newest first. Click a category in the left sidebar to narrow the list; the column headers below are static labels.

Article Category Read Published
RAG Security Testing - The Retrieval Pipeline Attack Surface How to test a RAG system for security - the four surfaces of the retrieval pipeline, the probes for each, and the evidence an auditor accepts. Penaxtra Security Research ragvector-storeowasp-llm08testing Attacks and defence 10 min
How DSPs Use AI, From Bid Models to Copilots A CTO's field guide to the AI inside demand-side platforms: bid models, pacing, creative generation, brand safety, and the new copilot layer - plus the part nobody budgets for, securing it. Penaxtra Security Research adtechdspai-biddingagentic-aiindustry Industry deep-dives 9 min
The EU AI Act High-Risk Deadline Is Moving to 2027. The Work Did Not. The Digital Omnibus is set to push the EU AI Act high-risk deadline from August 2026 to December 2027 - politically agreed, not yet law. The obligations did not change, only the clock. What a security team still has to build. Penaxtra Team eu-ai-actcompliancehigh-riskaudit-evidence Compliance and regulation 8 min
MCP Tool Poisoning, and the RCE You Inherited - Reading the June 2026 Disclosures MCP tool poisoning is trending for a reason. A June 16 2026 disclosure put a remote-code-execution default in the official MCP SDKs, on top of a year of poisoned tool descriptions and rug pulls. Here are the numbers, the timeline, and what to check in your own stack. Penaxtra Security Research mcpagentsprompt-injectionsupply-chainowasp-agentic Attacks and defence 9 min
Your Model Was Never the Weak Point - The LiteLLM and LangGraph CVEs of June 2026 In one week, LiteLLM, LangGraph, and a wave of exposed MCP servers all got hit. None of it was about the model. Here is what actually broke, with the CVE numbers, and what to test before your next LLM feature ships. Penaxtra Security Research ai-gatewayllm-agentcvemcpsupply-chain Attacks and defence 9 min
The Q1 2026 GenAI Exploit Round-up: Eight Incidents, One CVE A read-through of the quarter's eight notable GenAI security incidents, why only one of them carried a CVE, and what that gap means for how you track AI risk. Penaxtra Security Research ai-security-2026agentic-aimcp-securityprompt-injectionai-spm Attacks and defence 8 min
The First Autonomous AI-Agent Intrusion: What It Means for Defenders An LLM agent reportedly ran a full intrusion, from RCE to database exfiltration, in under an hour with no operator. What changed, and where you catch it. Penaxtra Security Research ai-agentsautonomous-attacksruntimemitre-atlas Attacks and defence 7 min
The Self-Propagating AI Worm: Separating the Signal From the Panic Researchers demonstrated an open-weight LLM driving a self-propagating worm across a simulated network. Here is what actually changed for defenders, and what did not. Penaxtra Security Research ai-wormsautonomous-attacksattack-surfaceruntime Attacks and defence 7 min
AI Security in the First Half of 2026: The Breaches That Ended the Debate H1 2026 AI security review: the breaches that turned theory into incident queues, why posture management is now essential, and the H2 outlook. Penaxtra Security Research ai-security-2026agentic-aimcp-securityprompt-injectionai-spm Attacks and defence 11 min
Frontier Agents Cut Both Ways - Opus 4.8, Dynamic Workflows, and the First In-the-Wild LLM-Agent Intrusion The week frontier models learned to run a thousand parallel subagents is the same week someone pointed one at a network and dumped a database in under an hour. Notes for anyone shipping agents to production. Penaxtra Security Research agentic-aillm-agentattack-surfaceowasp-agenticsupply-chain Attacks and defence 10 min
MCP Tool Poisoning - How the Attack Works and How to Stop It MCP tool poisoning explained: line jumping, rug pulls, and the malicious tool descriptions that hijack AI agents, with byte-level payloads and the seven runtime controls that actually held. Penaxtra Security Research mcpagentsprompt-injectionowasp-agenticsupply-chain Attacks and defence 13 min
EU AI Act Cybersecurity Requirements for High-Risk AI Systems A practitioner's guide to Article 15 cybersecurity, Article 9 risk management, and Article 17 quality management for high-risk AI providers. What auditors will actually ask in 2026. Penaxtra Compliance Engineering eu-ai-actcompliancehigh-risk Compliance and regulation 8 min
MCP Security Checklist - Securing Model Context Protocol Servers in Enterprise AI Systems Practical checklist for security teams reviewing MCP server deployments. Covers tool surface, permission scoping, indirect injection, confused deputy, and runtime enforcement. Penaxtra Security Research mcpagentsowasp-agentic Attacks and defence 6 min
Prompt Injection Testing for Enterprise LLM Apps How to test enterprise LLM applications against prompt injection in a way that produces auditor-acceptable evidence. Covers direct injection, indirect injection via RAG, tool-output injection, and judge bias. Penaxtra Security Research prompt-injectionowasp-llm01testing Attacks and defence 7 min
AI-SPM vs LLM Security - What is the Difference? AI-SPM and LLM Security are complementary disciplines, not substitutes. LLM Security is the focused layer; AI-SPM is the broader programme. Here is what each covers. Penaxtra Engineering ai-spmllm-securitycategories AI-SPM fundamentals 6 min
What is AI Security Posture Management? AI Security Posture Management (AI-SPM) is the continuous process of discovering, assessing, securing, and proving the compliance posture of AI systems. Here is what it covers and why it matters. Penaxtra Engineering ai-spmfundamentalsai-asset-inventory AI-SPM fundamentals 7 min
How to Build an AI Asset Inventory That Survives the First Audit Building an AI asset inventory looks easy until the first auditor asks for it. Eight categories, two failure modes, and the practical script that worked for us. Penaxtra Engineering ai-asset-inventoryai-bomdiscovery AI-SPM fundamentals 6 min
OWASP Agentic Top 10 Walkthrough - What Actually Matters in Production A practitioner's reading of the OWASP Agentic Top 10 T1-T15 list. Which entries we see exploited in the wild, which are still mostly theoretical, and the controls that work. Penaxtra Security Research owasp-agenticagentsmcp Attacks and defence 6 min
NIST AI 600-1 Profile in 20 Minutes - What Auditors Care About A practitioner's reading of NIST AI 600-1, the Generative AI Profile under the NIST AI RMF. Which functions matter most, the three controls auditors ask about every time, and how to map them to live evidence. Penaxtra Compliance Engineering nist-ai-600-1nistcompliance Compliance and regulation 6 min
Vector Database Tenant Isolation - The Quiet Failure Mode We Keep Finding A walkthrough of the cross-tenant retrieval failure mode in production vector stores, why namespace separation alone is not enough, and the test that catches it. Penaxtra Platform Engineering vector-storeragtenant-isolationincident Architecture and operations 5 min