<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>infosecravi — notes</title><description>Field notes on agentic AI security, LLM red teaming, ML supply-chain security and offensive research — written by a practitioner who builds these systems and attacks them.</description><link>https://infosecravi.com/</link><item><title>An agentic AI red team checklist: 222 tests, WSTG-style</title><link>https://infosecravi.com/blog/agentic-ai-red-team-checklist/</link><guid isPermaLink="true">https://infosecravi.com/blog/agentic-ai-red-team-checklist/</guid><description>Agentic engagements fail by omission — the team tests prompt injection thoroughly and never checks the MLflow server, the IMDS endpoint or the vector store&apos;s tenant filter. This checklist fixes that with 222 tests across 20 categories in forced engagement order (recon → infra → cloud → supply chain → input → injection → output → tools → agency → memory → mesh → MCP → CI/CD → privesc → lateral → exfil → DoS → integrity → voice). Every row carries a framework ID, a MITRE ATLAS tactic, a how-to-test, tools, and a detection mode so you can prove the finding. Download it, work it top to bottom, mark status per row.</description><pubDate>Thu, 08 Oct 2026 00:00:00 GMT</pubDate><category>Agentic AI</category><category>AI Red Teaming</category><category>Penetration Testing</category><category>MITRE ATLAS</category><category>OWASP</category><category>Checklist</category></item><item><title>Excessive agency is an authorisation bug wearing an AI costume</title><link>https://infosecravi.com/blog/excessive-agency-is-an-authorisation-bug/</link><guid isPermaLink="true">https://infosecravi.com/blog/excessive-agency-is-an-authorisation-bug/</guid><description>Every agent incident has two halves: the model was manipulated, and the agent was allowed to act on it. You cannot reliably fix the first half, but the second is ordinary authorisation engineering. Scope each tool to the narrowest capability that works, separate read from write, and gate irreversible actions — then a successful manipulation produces wrong text instead of a wrong outcome.</description><pubDate>Tue, 06 Oct 2026 00:00:00 GMT</pubDate><category>Agentic AI</category><category>AI Security</category><category>Excessive Agency</category><category>OWASP LLM Top 10</category><category>IAM</category></item><item><title>LLM cost is a security control, not a finance problem</title><link>https://infosecravi.com/blog/llm-cost-is-a-security-control/</link><guid isPermaLink="true">https://infosecravi.com/blog/llm-cost-is-a-security-control/</guid><description>If every alert costs the same to analyse, economics forces you to choose between coverage and budget — and you will quietly drop coverage. Routing by severity, so cheap models triage volume and expensive models handle escalations, breaks that trade-off. In our agentic SOC it produced a 30× per-alert cost spread, kept daily spend at $25-40 against a $375-500 flat-rate equivalent, and removed an attacker-controlled path to exhausting the budget.</description><pubDate>Tue, 06 Oct 2026 00:00:00 GMT</pubDate><category>Agentic AI</category><category>SOC Automation</category><category>AI Cost Engineering</category><category>Denial of Wallet</category><category>AI Security</category></item><item><title>Prompt injection is not a prompt problem</title><link>https://infosecravi.com/blog/prompt-injection-is-not-a-prompt-problem/</link><guid isPermaLink="true">https://infosecravi.com/blog/prompt-injection-is-not-a-prompt-problem/</guid><description>Prompt injection persists because an LLM sees instructions and untrusted data on the same channel, with no structural way to tell them apart. Defences written as prompt text can always be overridden by more text. What actually holds is architectural: scope every tool to least privilege, treat all model output as untrusted input, and put a human gate in front of irreversible actions.</description><pubDate>Tue, 06 Oct 2026 00:00:00 GMT</pubDate><category>LLM Security</category><category>Prompt Injection</category><category>AI Red Teaming</category><category>OWASP LLM Top 10</category><category>Agentic AI</category></item><item><title>The agentic AI regulatory map is mostly blank — and one set of supervisors said so</title><link>https://infosecravi.com/blog/the-agentic-regulatory-map-is-mostly-blank/</link><guid isPermaLink="true">https://infosecravi.com/blog/the-agentic-regulatory-map-is-mostly-blank/</guid><description>Across healthcare, banking, ecommerce and platforms, only two bodies have published anything agent-specific: FINRA&apos;s 2026 oversight report names agents acting beyond delegated scope, and the FSB&apos;s June 2026 consultation carries a seven-category agentic risk taxonomy that names memory poisoning outright. US federal banking supervisors went the other way, expressly excluding generative and agentic AI from April 2026 model risk guidance. Healthcare rules cover AI but never mention agents. If you are building agentic systems in a regulated sector, you are deriving your controls from first principles, and you should know that rather than assume a framework exists.</description><pubDate>Tue, 06 Oct 2026 00:00:00 GMT</pubDate><category>Agentic AI</category><category>AI Regulation</category><category>FINRA</category><category>FSB</category><category>HIPAA</category><category>AI Security</category></item><item><title>Threat modeling agentic AI orchestration: a component-by-component map</title><link>https://infosecravi.com/blog/threat-modeling-agentic-orchestration/</link><guid isPermaLink="true">https://infosecravi.com/blog/threat-modeling-agentic-orchestration/</guid><description>Model the orchestration stack as nodes and edges, then ask which edges cross a trust boundary. Six do: untrusted content into context, planner into tool invocation, agent identity into tool authorization, memory write into memory read, agent into peer agent, and decision into execution. Every significant agentic attack is an abuse of one of those six. The model is not where the vulnerability lives.</description><pubDate>Tue, 06 Oct 2026 00:00:00 GMT</pubDate><category>Agentic AI</category><category>Threat Modeling</category><category>MITRE ATLAS</category><category>OWASP</category><category>MAESTRO</category><category>AI Security</category></item><item><title>Your model file is a code execution primitive</title><link>https://infosecravi.com/blog/your-model-file-is-a-code-execution-primitive/</link><guid isPermaLink="true">https://infosecravi.com/blog/your-model-file-is-a-code-execution-primitive/</guid><description>A model file is not data — several formats execute code on load. Pickle-based checkpoints run arbitrary Python during deserialisation, Keras .h5 and .keras files can carry Lambda layers that execute on load (CVE-2024-3660), and binary formats like GGUF have parser-level memory bugs. If your pipeline pulls weights from a public hub and calls load() without scanning first, you have a remote code execution path that no amount of prompt-level defence touches.</description><pubDate>Tue, 06 Oct 2026 00:00:00 GMT</pubDate><category>ML Supply Chain</category><category>Model Security</category><category>Pickle RCE</category><category>AI Security</category><category>CVE-2024-3660</category></item></channel></rss>