Indirect Prompt Injection via Retrieved Documents
Retrieved documents have become an undefended attack vector for LLMs.
Correspondent
Marco Quist covers prompt injection, ai security governance and ai vendor risk analysis for LLM Security Review.
14 stories
Retrieved documents have become an undefended attack vector for LLMs.
Contracts must protect data from vendor training and map hidden AI supply chains.
Enterprises face notification deadlines they cannot hand off to AI vendors.
Open-source LLM risks hide in the supply chain layers enterprises aren't monitoring.
Developers are shipping AI agents with unvetted plugins that bypass security controls at scale.
Organizations claim OWASP alignment while handling AI risks in fundamentally different ways.
Standard vendor questionnaires miss AI-specific risks like model training data and prompt injection.
Traditional vendor questionnaires miss AI's opacity, bias, and drift problems.
Employees paste confidential data into unsanctioned chatbots faster than security teams can stop it.
Most sensitive data now enters AI tools, and legacy security tools can't detect it.
Platforms claiming framework alignment often lack the runtime controls to prove it.
Silent cost explosions hit LLM deployments where traditional monitoring misses them.
System prompts leak sensitive data when attackers trick LLMs into revealing their instructions.
Why LLMs break traditional security models and how to rebuild threat analysis around them.