Skip to content
Tomasus

Securing LLMs: A Field Guide

A practitioner tour of the LLM attack surface — the OWASP LLM Top 10, MLSecOps pipelines, threat modeling, the AI supply chain, and emerging governance.

3 articles published
  1. 1

    The OWASP Top 10 for LLMs: A Field Guide

    A field guide to the OWASP Top 10 for LLM Applications, the ten vulnerability categories that define modern AI application security.

  2. 2

    Prompt Injection: The XSS of LLMs

    How prompt injection subverts large language models through direct and indirect input, why it has no clean fix, and the layered defenses that contain it.

  3. 3

    Insecure Output Handling

    Why model output must be treated as untrusted input, how it becomes XSS, SSRF, and code execution downstream, and the encoding and validation that contain it.

17 more articles coming soon.