💉
Prompt injection (direct + indirect)
OWASP LLM01:2025. Direct user-typed and indirect via web/email/RAG context. Multilingual bypass especially via Spanish dialects.
🔓
Jailbreaks
DAN, AIM, Crescendo (multi-turn), ArtPrompt (ASCII), persuasion-based, multilingual translation attacks.
☠️
Training data poisoning + backdoors
Model checkpoint compromise (HuggingFace). CorruptRAG single-document poisoning (Jan 2026). Pickle deserialization.
🔍
Model extraction / inversion / membership inference
Query-based theft. Training-data leakage via membership inference. Reconstruction of private training samples.
📦
ML supply-chain attacks
Malicious pip packages, compromised checkpoints, poisoned HuggingFace models, dependency confusion in MLOps pipelines.
⚠️
MCP server vulnerabilities
April 2026 systemic RCE design flaw — Anthropic SDKs (Python, TypeScript, Java, Rust). CVE-2026-30623, CVE-2026-30615, CVE-2026-33224. ~7,000 public servers exposed.
🤖
Agentic AI risks
Goal hijacking, tool misuse, identity abuse, memory poisoning, infinite-loop DoS in CrewAI/LangChain/AutoGen. OWASP Agentic Top 10 (Dec 2025).
🧠
RAG poisoning / context injection
AgentPoison: 80%+ ASR at <0.1% poison rate. eTAMP cross-session attacks against ChatGPT Atlas and Perplexity Comet (Apr 2026).
🎭
Deepfake voice/video fraud
CEO/CFO impersonation scams. KYC bypass via JINKUSU CAM tooling on Telegram. Mar 2025 documented LATAM USD 494K fraud loss.
📧
AI-augmented social engineering
Spear phishing at scale, voice cloning, multi-channel coordinated attacks, BEC variants leveraging LLM for hyper-personalization.
💰
LLM cost / DoS attacks
OWASP LLM10:2025 Unbounded Consumption. High-token recursion, prompt-bombing, agentic resource exhaustion (infinite loops).
🖼️
Multimodal jailbreaks
Image-encoded payloads, ArtPrompt ASCII art, audio steganography, video-frame instruction injection in vision-language models.