Logo Hackmosphere Blanc Baseline
  • About us
  • Our services
    • Cyber pentesting
    • Physical Penetration Test
    • Phishing
    • Red Team
  • Our training courses
  • Contact
  • Blog
  • English
Free audit
Model Extraction: How API Requests Can Be Used to Steal an AI Model

Model Extraction: How API Requests Can Be Used to Steal an AI Model

by Saoussen Bahloul | Aug 31, 2026 | Other, Red Team

In February 2026, Anthropic publicly accused three Chinese AI labs (DeepSeek, Moonshot AI, and MiniMax) of generating more than 16 million interactions with Claude through approximately 24,000 fraudulent accounts, with the explicit goal of siphoning off its...
AI Security and Function Calling: Risks and Best Practices

AI Security and Function Calling: Risks and Best Practices

by Saoussen Bahloul | Aug 31, 2026 | Other, Red Team

Before invoking a tool via MCP or performing several steps independently, an agent relies on a fundamental mechanism: the function calling . Function calling allows an LLM to translate a natural-language request into a structured instruction (JSON format) that can be...
OWASP LLM Top 10 2026: What’s New in the Latest AI Security Ranking

OWASP LLM Top 10 2026: What’s New in the Latest AI Security Ranking

by Saoussen Bahloul | Aug 31, 2026 | Other, Red Team

On August 4, 2026, the OWASP GenAI Security Project released the most extensive overhaul theOWASP Top 10 for LLM applications since its creation in 2023: eight of the ten categories changed positions, one was renamed, and its scope was substantially expanded. A...
AI Agent Security: Why Does the MCP Protocol Increase Vulnerabilities?

AI Agent Security: Why Does the MCP Protocol Increase Vulnerabilities?

by Saoussen Bahloul | Aug 31, 2026 | Other, Red Team

Published by Anthropic in November 2024 As an open protocol for connecting AI models to external tools and data sources, the Model Context Protocol (MCP) has established itself in less than two years as the de facto standard of the agent-based ecosystem: more than 97...
AI Security Audit: What a Functional Audit Actually Covers (The 7 Key Areas)

AI Security Audit: What a Functional Audit Actually Covers (The 7 Key Areas)

by Saoussen Bahloul | Aug 24, 2026 | Other, Red Team

An AI audit involves mapping an organization’s AI attack surface. It is conducted exclusively through interviews and a review of documentation, without any technical actions on the systems. The functional audit answers a specific question before even considering a...
RAG poisoning: When the knowledge base becomes a cyberattack weapon

RAG poisoning: When the knowledge base becomes a cyberattack weapon

by Saoussen Bahloul | Aug 24, 2026 | Other, Red Team

A case reported by AI Alert illustrates the risk of knowledge base (RAG) poisoning in a corporate setting. At a financial services company, an internal HR assistant—powered by a RAG corpus of HR policies—reportedly provided an incorrect reimbursement threshold for...
« Older Entries

Recent Posts

  • Model Extraction: How API Requests Can Be Used to Steal an AI Model
  • AI Security and Function Calling: Risks and Best Practices
  • OWASP LLM Top 10 2026: What’s New in the Latest AI Security Ranking
  • AI Agent Security: Why Does the MCP Protocol Increase Vulnerabilities?
  • System Prompt Leakage: Risks and Security of AI Chatbots

Recent Comments

No comments to show.
Logo Hackmosphere Blanc Baseline
Icon email

contact [ at ] hackmosphere.fr

Icon Linkedin

Follow us

Privacy policy

General terms and conditions

Cookie policy

 

Pôle Alpha
Rue Pierre Lafitte
06410 Biot | Sophia Antipolis
Alpes-Maritimes | 06 | PACA | France

2026 IT-Marketing. All Rights Reserved.

Terms of use

Site map

Gérer le consentement
Pour offrir les meilleures expériences, nous utilisons des technologies telles que les cookies pour stocker et/ou accéder aux informations des appareils. Le fait de consentir à ces technologies nous permettra de traiter des données telles que le comportement de navigation ou les ID uniques sur ce site. Le fait de ne pas consentir ou de retirer son consentement peut avoir un effet négatif sur certaines caractéristiques et fonctions.
Fonctionnel Always active
L’accès ou le stockage technique est strictement nécessaire dans la finalité d’intérêt légitime de permettre l’utilisation d’un service spécifique explicitement demandé par l’abonné ou l’utilisateur, ou dans le seul but d’effectuer la transmission d’une communication sur un réseau de communications électroniques.
Préférences
L’accès ou le stockage technique est nécessaire dans la finalité d’intérêt légitime de stocker des préférences qui ne sont pas demandées par l’abonné ou l’internaute.
Statistiques
Le stockage ou l’accès technique qui est utilisé exclusivement à des fins statistiques. Le stockage ou l’accès technique qui est utilisé exclusivement dans des finalités statistiques anonymes. En l’absence d’une assignation à comparaître, d’une conformité volontaire de la part de votre fournisseur d’accès à internet ou d’enregistrements supplémentaires provenant d’une tierce partie, les informations stockées ou extraites à cette seule fin ne peuvent généralement pas être utilisées pour vous identifier.
Marketing
L’accès ou le stockage technique est nécessaire pour créer des profils d’internautes afin d’envoyer des publicités, ou pour suivre l’utilisateur sur un site web ou sur plusieurs sites web ayant des finalités marketing similaires.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Voir les préférences
  • {title}
  • {title}
  • {title}