
Tomaz Silva/Agência Brasil Decisão do STF, de 2023, determinou a oferta gratuita de transporte coletivo

Roberto Jayme/Ascom/TSE Assédio eleitoral pode acontecer tanto no setor privado quanto no público Pela segunda

Depositphotos Devedores poderão invocar condição de vulnerabilidade especial em processos de renegociação de dívidas O

Marcello Casal Jr/Agência Brasil Instagram é a rede social mais usada pelos candidatos, seguida do

Curso de pizzas do Sebrae-SP transforma aprendizado em oportunidade de negócio em Apiaí A capacitação

Ação contou com 21 participantes e teve o objetivo de incentivar a geração de novos

A CISO who sees a low CVE count and deprioritizes prompt injection is reading the scoreboard wrong. Prompt injection has held the No. 1 spot on the OWASP Top 10 for LLM Applications for three consecutive years. When two leaders of that list checked it against 6,639 labeled real-world incidents, it came back at No. 12. The drop measures visibility rather than danger, because the attack operates where a vulnerability scanner cannot see it. That finding belongs to Kyriakos “Rock” Lambros and Steve Wilson, two leaders of the OWASP Top 10 for LLM Applications project, who published it on arXiv on August 18 with the disclaimer attached. The analysis is exploratory, not peer reviewed, and not the official OWASP release, and the authors state it does not supersede the official list or its process. The machinery behind it is real: 7,714 LLM security incidents from CVE, GitHub Security Advisories, OSV, and the AIAAIC AI-harm database, 6,639 of them labeled against a 20-entry taxonomy, and a Bayesian model that corrects each count for classifier error before setting the data-driven ranking beside the expert vote. The comparison found no statistically detectable agreement between expert judgment and the public incident record. Cohen’s kappa comes in at 0.20 with a 90% interval running from negative 0.16 to 0.57. “The interval crosses zero, so we cannot rule out that the two rankings agree only by chance,” they write. “The honest bottom line: weak agreement, not confirmation.” Lambros, co-lead of the OWASP GenAI Security Project Top 10 for LLM Applications and director of AI standards and governance at Zenity, put the finding in evidentiary terms in written answers to VentureBeat. “We had two ways of measuring the same risk, expert judgment and the public incident record, and they disagree with each other. Neither one is the truth,” Lambros said. “Two witnesses are contradicting each other, and we can’t tell you which one is lying.” The attack chain a scanner never logs The gap is structural. Prompt injection hides instructions inside the content a model reads, anything from a log entry to a support ticket to a document pulled back by retrieval. The agent then makes the tool call the attacker wanted, using credentials it legitimately holds. Nothing in that chain is a product defect, so the attack leaves no CVE behind for a scanner to find. The defenses that catch it are adversarial tests against the deployed system and hard caps on what the agent can reach, so a fooled model cannot touch anything expensive. The same logic argues for funding agent memory and MCP tool boundaries now, on architecture, rather than waiting for advisory volume that will always arrive a cycle late. The first control Wilson would deploy Wilson, Chief AI and Product Officer at Exabeam and project co-lead for the OWASP Top 10 for LLM Applications, named the control he would deploy first against exactly that chain, an agent that reads an attacker’s payload in a log file, treats it as an instruction, and rewrites DNS with a valid credential, in written responses to VentureBeat. “The first thing I’d do is put an authorization gate outside the model: the agent can propose the exact DNS change, but it cannot grant itself the authority to make it,” Wilson said. “Security rules written inside prompts may shape the model’s behavior, but they are still suggestions to the model, not enforceable security controls.” The gate has a price, and Wilson states it plainly. “The tradeoff is that the agent loses the ability to improvise arbitrary, high-impact infrastructure changes on its own, while retaining autonomous investigation and routine, bounded remediation,” he said. Why the No. 1 risk looks small in the record “Prompt injection is the best-understood LLM attack, and deployed systems defend against it actively,” the authors write, and they compress the whole divergence into one sentence. “Experts rank it first because the attack surface stays enormous even when the defenses mostly hold; the data sees the successes that got through.” Wilson has watched the gap from both sides of it. “Incident data is incredibly valuable, but it is inherently backward-looking and notoriously tricky to interpret,” he said. “It tells us what was observed, recognized, classified, and reported. It does not necessarily tell us what is most dangerous in the systems people are building right now.” He compares prompt injection to “death and taxes” and, increasingly, to “a law of physics for LLM systems,” because one model is being asked to interpret trusted instructions and untrusted content at the same time. Better defenses have not closed the case. “A control that works 99% of the time is not sufficient when the failure case gives an attacker meaningful access. And, frankly, I don’t think we are at 99%,” Wilson said. “The durable answer is not believing we can perfectly screen prompt injection out of existence. It is designing systems with the assumption that prompt injection will occur, understanding why it works, and limiting what an attacker can accomplish when it does.” A low advisory count can mean the defenses are working. It can just as easily mean nobody has looked, and the public record cannot tell a security team which one it is. The attempt volume is documented. CrowdStrike’s 2026 Global Threat Report found adversaries injected malicious prompts into legitimate GenAI tools at more than 90 organizations in 2025, stealing credentials and cryptocurrency, under a section titled “Prompts are the New Malware.” The telemetry shows pressure on the attack surface without proving defenses produced the No. 12 placement, but it is the pattern the mechanism predicts. The gap runs the other way too, and further Prompt injection is the headline case, and misinformation is the bigger one. The expert vote puts misinformation at No. 13, while the incident record places it at No. 2. The paper calls it “the widest disagreement between the two witnesses” and reports that its concordance flag “puts the probability that the two signals disagree at 99 percent.” The authors do not treat

Anthropic is making a calculated bet that the biggest bottleneck in enterprise AI isn't model intelligence — it's the fact that most people

Representante das fintechs de crédito, a Associação Brasileira de Crédito Digital (ABCD) anuncia Marcelo Buosi como seu novo presidente. Anteriormente vice-presidente da entidade,

Em pleno desenvolvimento, desde a primeira Parceria Público-Privada (PPP) de iluminação pública em 2014, as concessões do setor seguem avançando graças à combinação

Slack wants to drag AI coding out of the terminal and into the group chat. The Salesforce-owned messaging platform today announced Slack Code,

Nova etapa da gestão de veículos removidos exige mais do que digitalização: integração entre órgãos, pátios, sistemas e plataformas de leilão passa a

Serval is making Catalyst, its AI agent for building enterprise automations, generally available Thursday and enabling it by default for customers — allowing

Em um cenário marcado pelo crescimento das fraudes digitais impulsionadas pelo uso de inteligência artificial (IA), a Veridas, empresa global especializada em identidade

Ampliar as possibilidades de atuação de construtoras, integradores fotovoltaicos e arquitetos, desenvolvendo um olhar estratégico sobre o uso das superfícies das edificações na

No artigo anterior, escrevi sobre uma hipótese que me interessa cada vez mais: uma geração não é formada apenas pelos valores que recebe
Com estreia marcada para o dia 5 de maio de 2028, o novo filme dos X-Men vai ser responsável por introduzir de vez

Tomaz Silva/Agência Brasil Decisão do STF, de 2023, determinou a oferta gratuita de transporte coletivo no dia da eleição Desde 1974, a Lei

Especializada em guarda privada de bens de alto valor desde 2018, SEKURO aposta em cofres privados como alternativa para quem busca segurança, privacidade

Relato de Sérgio Zagarino sobre restrições a campanhas em comunidades retoma debate nacional sobre crime organizado e liberdade eleitoral. “O controle territorial do

47ª edição do encontro promovido pelo Grupo Mulheres Fazendo Negócios reuniu executivas e empresárias para discutir liderança, transformação e oportunidades no ambiente empresarial

Sérgio Zagarino relata que grupos criminosos tentam decidir quais candidatos podem entrar em comunidades e alerta para risco à liberdade eleitoral. “Isso ultrapassa

Você já virou adulto? Desde que idade se considera assim? Alguns acham que ser adulto é pagar contas. Outros dizem que é cuidar

A terapia não funciona por fórmulas mágicas ou técnicas secretas. Ela trabalha na maneira como duas pessoas se conectam, no espaço seguro que

Eduardo Prosdossimi durante experiência na Confraria dos Palcos, onde aprimorou técnicas de comunicação e presença de palco.

A presença da Inteligência Artificial (IA) nas escolas, universidades e ambientes virtuais de aprendizagem cresce rapidamente. Assistentes virtuais, ferramentas de escrita, sistemas de

Exibido de segunda a sexta-feira, das 7h às 8h, na Jovem Pan News Manaus 98,7 FM, jornalístico reúne informação, entrevistas, prestação de serviço
© 2025 Todos os direitos reservados a Handelsblatt