ai-security
Safeguard articles tagged "ai-security" — guides, analysis, and best practices for software supply chain and application security.
585 articles
The LLM Supply Chain: Risks Hiding in Foundation Models
Large language models have their own supply chains: training data, fine-tuning datasets, model weights, and serving infrastructure. Each layer introduces risk.
OWASP Top 10 for LLM Applications: A First Look
OWASP published its first Top 10 for LLM Applications on August 1, 2023. Here is what it covers, where it overreaches, and how to use it on real systems.
Securing LLM Applications: The OWASP Top 10 for Large Language Models
OWASP released its Top 10 for LLM Applications in August 2023, providing the first standardized framework for understanding and mitigating risks in AI-powered software.
LLM Prompt Injection: The New Supply Chain Attack Vector
Prompt injection attacks against large language models represent a dangerous new frontier in software supply chain security. Here's what defenders need to know.
ChatGPT Plugins and the New Plugin Supply Chain Attack Surface
AI plugins connect LLMs to external services, creating a supply chain of trust that most users never examine. The risks are significant.
OpenAI ChatGPT Data Breach March 2023: What Was Exposed
A bug in ChatGPT exposed user chat histories and payment information. Here's what happened and what it means for AI service security.
AI-Generated Code Security Risks: Copilot, ChatGPT, and the New Attack Surface
AI code assistants are writing a growing share of production code. The security implications are significant and largely unaddressed.
Securing AI/ML Pipelines: The Supply Chain You're Not Watching
AI/ML pipelines introduce unique supply chain risks from training data to model distribution. Most organizations have zero visibility into this attack surface.
ChatGPT and AI Security Implications for Software Supply Chains
The explosion of AI tools like ChatGPT is reshaping how developers write code — and introducing new supply chain risks that most teams aren't thinking about.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.