Toggle light / dark theme

LLM Security Basics: The Full Threat Model

For contrast, consider a different case. For roughly $20 in API queries, a team extracted part of a production OpenAI model through its public interface. That sounds like the threat most teams should really fear.

In this article, we try to build a map of the full attack surface that threatens an LLM’s security. With it, a given LLM feature can be located, its exposure points identified, and new threats reasoned about as they appear.

So let’s start with the single most important property.

Bispecific Antibody Ivonescimab Added to Chemotherapy in EGFRVariant NonSmall Cell Lung Cancer: Research Summary JAMA Network

This website uses a security service to protect against malicious bots. This page is displayed while the website verifies you are not a bot.

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution.

The vulnerability, tracked as CVE-2026–48449, carries a severity score of 10.0 on the CVSS scoring system.

It has been described as a case of incorrect authorization that could result in arbitrary code execution in the context of the current user without requiring any user interaction.

OpenAI agent used exposed credentials at 4 services in Hugging Face breach

In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations.

One account was used as an outbound relay and staging server during the attack, while another was used for data storage. The remaining two accounts were accessed in a read-only manner and were not used to compromise Hugging Face further.

Overall, the agent assembled attack infrastructure similar to what human threat actors commonly use during intrusions to host tools and scripts, relay traffic, and route malicious activity through legitimate online services.

/* */