Prompt Injection
CRITICALCrafted inputs override LLM system instructions to bypass safety controls or exfiltrate confidential data.
AI & LLM threat landscape ยท curated by Vikas Pandita, GenAI Security Specialist
Crafted inputs override LLM system instructions to bypass safety controls or exfiltrate confidential data.
AI-generated fake audio/video used for fraud, social engineering, and large-scale disinformation campaigns.
LLMs generating highly personalised, grammatically perfect phishing at scale in any language.
Corrupting datasets to embed backdoors or malicious biases into production AI models before deployment.
Extracting sensitive PII or IP through crafted prompts against RAG systems and vector databases.
Agentic AI with excessive permissions taking unauthorised real-world actions without human oversight.
Stealing proprietary AI models via systematic API extraction or direct model-weight exfiltration.
Voice cloning and AI personas used for financial fraud, BEC, and executive impersonation at scale.
GCC banking sector facing AI-generated executive voice cloning targeting fraudulent wire transfer approvals.
AI-forged official communications targeting GCC public sector โ verify all digital correspondence and requests.
LLMs now produce fluent Arabic phishing โ language quality is no longer a reliable detection indicator.
AI-optimised attacks on Vision 2030 and UAE smart city infrastructure (SCADA + AI convergence risk).