Security Isn't a Property of the Model — It's a Property of the Deployment
Prompt Injection Is the Common Thread, Not the Exception
Swipe or use ← → to navigate
Every fact has a receipt.
Swipe or use ← → to navigate
AI · AI Model Evaluation
Nine real incidents across Microsoft, Google, OpenAI, Salesforce, LangChain, and one open protocol (MCP) — plus a Booz Allen study showing one coding model's vulnerability rate shifted 130% based on who it thought was asking. The same mechanism, prompt injection, runs through nearly all of it. A vendor-neutral framework (OWASP's two Top 10 lists) for categorizing the risk, and a checklist for what to actually test before you ship.
26 July 2026
https://unicornle.com/learn/security-isnt-a-property-of-the-model · Every fact has a receipt.
OWASP Top 10 for LLM Applications 2025 · SQ Magazine
OWASP Top 10 for LLM Applications
OWASP Top 10 for Agentic Applications 2026 (GenAI Security Project)
Invariant Labs — MCP GitHub Vulnerability
Docker — MCP Horror Stories: GitHub Prompt Injection
Zenity — AgentFlayer Vulnerabilities
Embrace The Red — GitHub Copilot RCE via Prompt Injection
Tenable — The Trifecta
Zenity — Living off Microsoft Copilot
Noma Security — LangSmith Agent Vulnerability
Booz Allen Hamilton — "What's in America's Code?" (May 2026)
Synthesized from slides 1-9
Before you ship an AI coding tool or agent into production:
Synthesized from slides 1-9