← All posts

Problem-Aware

202 posts on problem-aware.

Agentic AI Use Cases and the Security Profile Each One Carries

Agentic AI use cases get evaluated on business value and deployed on that basis, and the security profile is discovered afterwards. The profile is predictable from two variables: what data the agent can reach and what side effects it can cause. This walks six enterprise agent use cases (customer support, coding, procurement, IT operations, clinical documentation, financial reconciliation), the specific failure each carries, and the control that bounds it.

agentic-aiai-securityai-governancepolicy-enforcementllm-securitycompliance
Read post →

Agentic AI vs AI Agents: The Distinction That Changes Your Threat Model

An AI agent is a component: a model with tools and a loop. Agentic AI is a property of a system: the degree to which it selects its own next action from state it produced. The terms get used as synonyms, and treating them that way collapses a distinction that decides which controls you need. This walks the autonomy gradient, where each level's threat model changes, and the one control point that holds across all of them.

agentic-aiai-securityllm-securityarchitectureidentity-and-authorizationai-governance
Read post →

AI Model Poisoning: Why the Right Response Is to Stop Trusting the Model

Model poisoning covers three distinct attacks: corrupting pretraining data, planting a backdoor during fine-tuning, and poisoning the retrieval index an application queries at inference. The first two are largely undetectable from the deploying enterprise's position. That fact should reshape the control strategy rather than the detection strategy. This walks the taxonomy, states plainly which layers an enterprise can and cannot inspect, and makes the case for treating model output as untrusted input.

ai-securityllm-securityagentic-aipolicy-enforcementzero-trustai-governance
Read post →

Data Exfiltration via LLM: The Channel Your DLP Was Never Built to See

An LLM prompt is an HTTPS POST to a provider API carrying whatever the user or agent put in the context window. That makes it an egress channel with no size limit, no content inspection, and no identity correlation in most enterprises. This walks the four exfiltration paths through an LLM (deliberate paste, agent retrieval, injected instruction, response-side leakage), what each looks like on the wire, and the control that closes them.

ai-securitydata-loss-preventionshadow-aillm-securityinline-enforcementdlp
Read post →

LLM Application Security: The Five Layers and Which One Holds When the Others Fail

Securing an LLM application means securing five layers: the model, the prompt, the retrieval pipeline, the tool surface, and the request boundary. Four of them are inside the application's own process, which means an attacker who reaches the process owns those controls. This walks each layer, the specific attacks it faces, and why the request boundary is the only layer that produces enforceable decisions and independent evidence.

llm-securityai-securityarchitectureprompt-injectioninline-enforcementdevsecops
Read post →

LLM Cyber Security: Four Attacker Objectives and the Control Point That Answers Each One

Most LLM security guides organize around defense layers. Attackers organize around objectives: exfiltrate data, gain execution, abuse spend, corrupt output. This guide takes each objective in turn, traces the path it uses through an enterprise LLM deployment, names the 2026 CVEs that made each path real, and identifies which control point answers it. It also states plainly which objectives the AI request boundary cannot reach.

llm-securityai-securitycybersecurityarchitectureinline-enforcementzero-trust
Read post →

LLM Jailbreak Detection: The Four Signal Families and the Base-Rate Problem Nobody Budgets For

Jailbreak detection is a classification problem running against a hostile base rate. Four signal families are available: lexical patterns, semantic classifiers, response-side refusal analysis, and multi-turn escalation. Three of them are evaluated before the model responds and one after. This walks each family, the false-positive economics that decide whether the detector survives contact with production, and the record a detection has to write to be worth anything in an investigation.

llm-securityprompt-injectionai-securityinline-enforcementforensic-auditarchitecture
Read post →

The LLM Security Checklist: 34 Items With Pass Criteria You Can Actually Fail

Most LLM security checklists list topics. A checklist that changes a deployment decision states a pass criterion specific enough to fail. This one runs 34 items across seven sections: inventory, identity, prompt controls, response handling, tools and agents, evidence, and supply chain. Each item has a criterion, and the three that fail most often in real reviews are called out with the reason they fail.

llm-securityai-securityai-governancearchitecturecompliancedevsecops
Read post →

LLM Security Vulnerabilities: Five Classes of Real CVE in the 2026 AI Stack

OWASP's Top 10 catalogs LLM risks in the abstract. The CVEs filed against the LLM stack in 2026 are concrete, and they cluster into five classes: control-plane authentication bypass, multi-tenant isolation failure, pre-auth RCE in orchestration tooling, unsafe model file deserialization, and configuration-to-command execution by protocol design. This walks each class with its 2026 exemplars, the shared root cause, and which classes an enforcement layer can compensate for.

llm-securityai-securitycybersecurityarchitecturedevsecopsagentic-ai
Read post →

LLM Supply Chain Security: Nine Components, and the Only One You Can Enforce at Runtime

An LLM system has nine supply-chain components: base weights, fine-tunes and adapters, tokenizers, training and RAG corpora, inference servers, orchestration frameworks, tool and MCP servers, prompt templates, and the provider API itself. Eight of them are verified before deployment, through provenance, signing, and pinning. One is verified at runtime, on every call. This walks each component, the attack that hits it, and where the enterprise's enforceable control actually sits.

llm-securityai-securityarchitectureai-governanceagentic-aidevsecops
Read post →

MCP Server Supply Chain Security: The Install Path Nobody Reviews

An MCP server is installed with a line of configuration, runs with the privileges of the host process, updates on its own schedule, and ships a tool description that the model reads as instructions. That install path receives less scrutiny than an npm dependency, and the 2026 CVE record shows what it cost. This walks the five gates a third-party MCP server should pass, a ten-question review rubric, and the runtime controls that hold when the review was wrong.

agentic-aiai-securityllm-securitydevsecopsarchitecturecybersecurity
Read post →

Multi-Agent System Security: The Authorization Problem Nobody Solved Before Shipping

A2A version 1.0 shipped in April 2026 with signed Agent Cards and an explicit design rule: A2A payloads carry no user or client identity. MCP forbids token passthrough and mandates RFC 8707 resource indicators. Both protocols push identity to the HTTP layer and leave delegation chains without a protocol-native way to carry an originating principal across hops. This piece walks through the multi-agent threat model, the six failure modes that only appear when agents talk to each other, and the enforcement point that reconstructs who authorized what.

agentic-aiai-securityidentity-and-authorizationllm-securityarchitecturezero-trust
Read post →