TGViewer
Cult Of Wire Cult Of Wire @cultofwire · 949 subscribers
Post #1293 398
OWASP Top 10 for Large Language Model Applications

Итак, OWASP Top 10 добрался до LLM и уже существует в версии 1.1.0
Среди примеров уязвимостей - инъекции, утечка данных, неадекватная "песочница", несанкционированное выполнение кода и другие.

Что же у нас в топе:
- LLM01: Prompt Injection
- LLM02: Insecure Output Handling
- LLM03: Training Data Poisoning
- LLM04: Model Denial of Service
- LLM05: Supply Chain Vulnerabilities
- LLM06: Sensitive Information Disclosure
- LLM07: Insecure Plugin Design
- LLM08: Excessive Agency
- LLM09: Overreliance
- LLM10: Model Theft

Почитать можно в PDF:
OWASP Top 10 for LLM Applications
Security & Governance Checklist

В дополнении ко всему OWASP запустили отдельный сайт - genai.owasp.org, где будет актуальная информация и переводы.
www.lasso.security OWASP Top 10 LLM Vulnerabilities & Security Checklist Discover the top 10 LLM vulnerabilities identified by OWASP, along with mitigation strategies and a security checklist to enhance your LLM app security.
  • 👍 2
More from @cultofwire
  1. Mar 20, 2026https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise Trivy в GitHub…
  2. Mar 20, 2026Это настолько плохо, что даже хорошо. Хорошей пятницы.
  3. Feb 12, 2026ClawdBot Skills Just Ganked Your Crypto Немного прослоупочил и пропустил важную веху в эре…
  4. Feb 4, 2026One-Click RCE + unauth API keys leak в OpenClaw/Clawdbot/Moltbot (CVE‑2026‑25253) Исследов…
  5. Feb 3, 2026Раз уж начали неделю c AI, то продолжим небольшим курсом от Aiteera. Сам курс небольшой и…
  6. Feb 3, 2026VoidLink: Evidence That the Era of Advanced AI-Generated Malware Has Begun Нейрослоп тепер…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →