logo

A Gentle Crash Course to LLMs

ID: 6a446335-cf5c-57dd-a13c-305e50142c35

STIX ID: report--6a446335-cf5c-57dd-a13c-305e50142c35

Feed Name: SpecterOps Blog

Date Published: 2025-10-16

Date Updated: 2026-04-30

Author: Blaise Brignac

...
...

This blog provides a concise history of LLMs and focuses on the security implications of integrating them into applications, detailing how non-determinism, RAG/CAG, tool/function calling, the Model Context Protocol (MCP), and agent frameworks expand attack surfaces. It explains techniques and pitfalls including direct and indirect prompt injection, data poisoning, tool disclosure/abuse, MCP tool poisoning and weak authentication, supply-chain risks, SQL injection, and path traversal, emphasizing the need for careful context preparation, strict trust boundaries, and secure coding practices when deploying LLM-enabled systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.