Wednesday, 26 Aug 2026
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
logo logo
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
  • 🔥
  • Trump
  • House
  • White
  • ScienceAlert
  • VIDEO
  • man
  • Trumps
  • Season
  • star
  • Years
Font ResizerAa
American FocusAmerican Focus
Search
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
Follow US
© 2024 americanfocus.online – All Rights Reserved.
American Focus > Blog > Tech and Science > Prompt injection ranks No. 1 with OWASP and No. 12 in the incident record. The attack itself is invisible to a scan.
Tech and Science

Prompt injection ranks No. 1 with OWASP and No. 12 in the incident record. The attack itself is invisible to a scan.

Last updated: August 26, 2026 12:20 am
Share
Prompt injection ranks No. 1 with OWASP and No. 12 in the incident record. The attack itself is invisible to a scan.
SHARE

Contents
The attack chain a scanner never logsThe first control Wilson would deployWhy the No. 1 risk looks small in the recordThe gap runs the other way too, and furtherWhere “too new to measure” runs into the CVE recordThe authors flag their own measurement problems firstWhat the published list did with thisWhy this lands nowWhat to do with this on Monday

A CISO might misinterpret a low CVE count as a reason to downplay prompt injection, but this approach is flawed. For the past three years, prompt injection has topped the OWASP Top 10 for LLM Applications list. Yet, when two key figures from the list, Kyriakos “Rock” Lambros and Steve Wilson, compared it to real-world data from 6,639 incidents, its rank fell to 12th. This decrease reflects its invisibility rather than its threat level, as the attack occurs beyond the reach of vulnerability scanners.

Lambros and Wilson, leaders in the OWASP Top 10 for LLM Applications project, shared these findings on arXiv on August 18, stressing that this exploratory analysis is not peer-reviewed or an official OWASP release. It examines 7,714 LLM security incidents using a Bayesian model to correct for classifier errors and compare data-driven rankings with expert opinions.

The analysis highlights a lack of agreement between expert judgment and public incident records, with Cohen’s kappa at 0.20 and a 90% interval from -0.16 to 0.57. This suggests the rankings might align only by chance. Lambros explained the discrepancy in a statement to VentureBeat: “We had two ways of measuring the same risk, expert judgment and the public incident record, and they disagree with each other. Neither one is the truth.”

See also  How can enterprises keep systems safe as AI agents join human employees? Cyata launches with a new, dedicated solution

The attack chain a scanner never logs

Prompt injection is structurally elusive, embedding commands in the content a model processes, such as log entries or documents. The agent uses its legitimate credentials to enact the attacker’s desired tool call, leaving no CVE trace for scanners to detect. Effective defenses include adversarial tests and limiting agent access, suggesting investment in agent memory and MCP tool boundaries should be made proactively, not reactively.

The first control Wilson would deploy

Wilson, of Exabeam and the OWASP Top 10 for LLM Applications, advocates for an authorization gate to prevent agents from autonomously executing DNS changes. While prompts can influence model behavior, they do not enforce security. The tradeoff is reduced agent autonomy in infrastructure changes while maintaining limited investigative capabilities.

Why the No. 1 risk looks small in the record

Though prompt injection is well-defended against, its attack surface remains vast. Data records only successful breaches, not the potential danger. Wilson notes the backward-looking nature of incident data, which doesn’t reflect emerging threats. He likens prompt injection to unavoidable constants like “death and taxes.”

A low advisory count might indicate effective defenses or simply a lack of scrutiny. CrowdStrike’s 2026 Global Threat Report recorded numerous prompt injections in 2025, corroborating the expected attack pattern despite the low ranking.

The gap runs the other way too, and further

Prompt injection may be the headline, but misinformation is a more contentious issue. Experts rank it 13th, while incident records place it 2nd, with a 99% probability of disagreement. The authors note the data often reflects AI-generated disinformation rather than LLM vulnerabilities, questioning the expert assessment without dismissing it entirely.

See also  5 stabbed in bloody attack inside Penn Station -- suspect in custody

Where “too new to measure” runs into the CVE record

New taxonomy entries like persistent memory poisoning and MCP tool interface exploitation show significant ranking disparities between experts and incidents. Public CVEs for these issues exist, but a lack of advisory volume might delay necessary controls. Lambros argues for early architectural investments to avoid costly future system overhauls.

The authors flag their own measurement problems first

The study’s limitations are acknowledged by the authors. With only 29 experts setting the rankings, the weight of their input is disproportionately large. The classifier’s precision varies widely, and a single reviewer’s annotations limit inter-rater reliability. Lambros attributes the weak kappa to the taxonomy rather than the experts.

Efforts to improve the classifier did not resolve the discrepancies. Despite testing, the incident-derived ranking remains stable, highlighting the need for cautious interpretation of “robust” results.

What the published list did with this

The GenAI LLM Top 10 2026 integrated incident data into its ranking for the first time, with a 75/25 weight favoring expert opinion. While prompt injection retained its top position, misinformation rose, and other categories shifted. Wilson emphasizes the value of changing the conversation over precise weighting.

Lambros suggests adjusting the incident weight based on measurement reliability, advocating for a more nuanced approach in future cycles.

Why this lands now

According to Ivanti’s 2026 State of Cybersecurity research, 87% of security teams prioritize agentic AI, with many comfortable with AI autonomy. However, this comes amid a misalignment between expert risk assessments and incident data.

What to do with this on Monday

The necessary shift in behavior is clear:

  • Use the OWASP LLM Top 10 as a coverage map, not a queue. Given the weak agreement between rankings and data, prioritize based on specific exposure and tested controls. Lambros advises focusing funds where expert and incident data align.

  • Log what your AI systems are actually doing, field by field. Monitor prompts, outputs, document retrievals, tool use, and model confidence. Lambros emphasizes the importance of tracking confidence as a sign of attack.

  • Stop expecting scanner output to reproduce the Top 10’s order. Scanners reflect disclosed incidents, not current system threats. Instead, conduct adversarial testing and implement authorization gates to prevent unauthorized agent actions.

  • Fund the thin-record categories on architecture, not incident volume. Prioritize architectural solutions for agent memory and MCP tool boundaries, as their criticality is evident despite sparse incident data.

  • Steal McGladrey’s baseline test for the AI systems themselves. Adopt a cautious approach similar to database security when considering AI model exposure.

See also  Authors call on publishers to limit their use of AI

As security boards evaluate risks, they must question the basis of their funding decisions, especially when relying on potentially flawed rankings.

TAGGED:AttackincidentinjectioninvisibleOWASPpromptRanksrecordscan
Share This Article
Twitter Email Copy Link Print
Previous Article Measuring ROI For Healthcare AI May Require A New Approach Measuring ROI For Healthcare AI May Require A New Approach
Next Article Kith Fall 2026 Menswear Collection Kith Fall 2026 Menswear Collection

Popular Posts

The Weight-Loss Drug Revolution—From Shots to Pills and the Science behind It All

But people started noticing that when they took these drugs, they were losing weight. And…

January 10, 2026

How striving for ideal rest disrupts sleep

The pressure to achieve perfect sleep has become a prevalent issue in today's society, with…

January 7, 2025

Chanel Turned New York Blue—And “The Summer I Turned Pretty Boys” Showed Up

Christopher Briney and Sean Kaufman Photo: Tyrell Hampton On a vibrant Thursday evening, Chanel introduced…

September 27, 2025

Stranger Things Season 5: A Bittersweet Review

As the final season of Stranger Things continues to unfold, it's clear that the show…

December 2, 2025

5 Surprising Truths About How AI Chatbots Actually Work : ScienceAlert

AI chatbots have quickly become a part of our daily lives, but many of us…

July 5, 2025

You Might Also Like

Elon Musk’s SpaceX to expand beyond Texas Starbase with new Louisiana spaceport dedicated to Starship
Tech and Science

Elon Musk’s SpaceX to expand beyond Texas Starbase with new Louisiana spaceport dedicated to Starship

August 25, 2026
Apple’s iPhone Ultra Could Bring Back the Small Phone – Tech Advisor
Tech and Science

Apple’s iPhone Ultra Could Bring Back the Small Phone – Tech Advisor

August 25, 2026
Google Installed a New Android App on Millions of Phones. Here’s Why – Tech Advisor
Tech and Science

Google Installed a New Android App on Millions of Phones. Here’s Why – Tech Advisor

August 25, 2026
Meet Orexin, The Brain Chemical Behind Staying Motivated : ScienceAlert
Tech and Science

Meet Orexin, The Brain Chemical Behind Staying Motivated : ScienceAlert

August 25, 2026
logo logo
Facebook Twitter Youtube

About US


Explore global affairs, political insights, and linguistic origins. Stay informed with our comprehensive coverage of world news, politics, and Lifestyle.

Top Categories
  • Crime
  • Environment
  • Sports
  • Tech and Science
Usefull Links
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA

© 2024 americanfocus.online –  All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?