Living catalogue · updated as the threat landscape moves

Attacks on AI & LLM systems, explained for defenders.

How each attack works, what it looks like in a real product, how Quillon tests for it, and which controls actually stop it — mapped to OWASP LLM Top 10 (2025), MITRE ATLAS and NIST AI RMF. The feed on the right pulls the latest reported research and incidents and refreshes itself automatically.

0Attack classes catalogued
10 / 10OWASP LLM Top 10 (2025)
ATLASMITRE tactic mapping

Live threat feed

loading…
Fetching the latest AI security headlines…
Source: Hacker News public search API · auto-refresh every 10 min
THREAT TICKER
Attack catalogue

Every class of attack we test for, and how to stop it.

Click any card to expand the real-world example, how we test it, and the mitigations. Filter by where in the system the attack lands.

Agentic kill chain

How a single poisoned document becomes an unauthorised payment.

The most damaging AI incidents chain several "low" findings together. This is the sequence we walk through in every agentic engagement.

01
Plant

Attacker uploads a doc or sends an email containing hidden instructions.

02
Retrieve

RAG pipeline indexes it; the agent pulls it into context on a normal query.

03
Hijack

Model follows the injected instructions over the system prompt.

04
Escalate

Agent calls a tool it has access to but the user shouldn't (refund, export, email).

05
Exfiltrate

Data leaves via tool output, rendered markdown image, or a webhook.

06
Persist

Injected content stays in memory or the KB, re-firing for other users.

Test against these

Every card above is a test case in a Quillon AI red team.

Scope a red team of your LLM feature or agent and receive findings mapped to OWASP, ATLAS, NIST AI RMF and ISO 42001.