11. Summary, Frameworks & Sources
Contents3 numbered sections
11.1 Summary Table
Section titled “11.1 Summary Table”| Rank | Vulnerability | OWASP ID | Severity | Primary Attack Vector |
|---|---|---|---|---|
| 1 | Prompt Injection | LLM01 | Critical | Malicious user input |
| 2 | Sensitive Information Disclosure | LLM02 | Critical | Data extraction |
| 3 | Supply Chain Vulnerabilities | LLM03 | High | Compromised components |
| 4 | Data and Model Poisoning | LLM04 | High | Training data manipulation |
| 5 | Improper Output Handling | LLM05 | High | Unvalidated outputs |
| 6 | Excessive Agency | LLM06 | High | Over-permissioned agents |
| 7 | System Prompt Leakage | LLM07 | Medium-High | Prompt extraction |
| 8 | Vector and Embedding Weaknesses | LLM08 | Medium-High | RAG/vector DB attacks |
| 9 | Misinformation and Hallucination | LLM09 | Medium | Inherent model behavior |
| 10 | Unbounded Consumption | LLM10 | Medium | Resource exhaustion |
11.2 Key Frameworks and References
Section titled “11.2 Key Frameworks and References”- OWASP Top 10 for LLM Applications (2025/2026) — The definitive industry framework for AI security risks
- OWASP Top 10 for Agentic Applications (2025) — Covers emerging agentic AI threats
- NIST AI Risk Management Framework (AI RMF) — Government standard for AI risk management
- MITRE ATLAS (Adversarial Threat Landscape for AI Systems) — Knowledge base of real-world AI attacks
- Google SAIF (Secure AI Framework) — Google’s approach to AI security
- IBM Cost of a Data Breach Report 2025 — Statistical data on AI-related breaches
- Trend Micro TrendAI State of AI Security Report (2H 2025) — CWE trends across the AI stack
11.3 Sources
Section titled “11.3 Sources”- OWASP GenAI Security Project — LLM Top 10 2025
- OWASP GenAI Security Project — LLM Top 10 2026
- Mindgard — Top 10 AI Security Risks of 2026
- SentinelOne — Top 14 AI Security Risks in 2026
- Cloudflare — OWASP Top 10 Risks for LLMs
- Trend Micro — Fault Lines in the AI Ecosystem: State of AI Security Report
- Bugcrowd — OWASP Top 10: Security Threats Facing AI Systems
- CSO Online — 10 Most Critical LLM Vulnerabilities
- ZDNet — 4 Critical AI Vulnerabilities Being Exploited
- Cycode — Top AI Security Vulnerabilities 2026
- HackTricks — AI Risk Frameworks
- BrightDefense — OWASP Top 10 LLM & Gen AI Vulnerabilities in 2026
- Cohere — The State of AI Security
- Cyberleveling — Top 10 Vulnerabilities in AI Systems on the Web
- Alex Ewerlof — OWASP Top 10 Agents & AI Vulnerabilities Cheat Sheet
Report generated on September 27, 2026. This report is intended for educational and defensive security purposes only.