A Gentle Crash Course to LLMs
ID: 6a446335-cf5c-57dd-a13c-305e50142c35
STIX ID: report--6a446335-cf5c-57dd-a13c-305e50142c35
Feed Name: SpecterOps Blog
This blog provides a concise history of LLMs and focuses on the security implications of integrating them into applications, detailing how non-determinism, RAG/CAG, tool/function calling, the Model Context Protocol (MCP), and agent frameworks expand attack surfaces. It explains techniques and pitfalls including direct and indirect prompt injection, data poisoning, tool disclosure/abuse, MCP tool poisoning and weak authentication, supply-chain risks, SQL injection, and path traversal, emphasizing the need for careful context preparation, strict trust boundaries, and secure coding practices when deploying LLM-enabled systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
