BlackNesherAgentic AI Security Assessment
Research

AI Security Research

Real, cited research on how AI agents actually get compromised — no speculation, no invented statistics.

What Is Prompt Injection? A Technical Guide

Prompt injection explained: direct vs. indirect injection, why it's structurally different from traditional injection attacks, and how it actually breaks AI agents in production.

Read →

How CEO-Fraud Prompt Injection Works Against AI Support Agents

CEO fraud isn't new — it's a top FBI IC3-tracked fraud category. Here's how the same social-engineering pattern gets adapted into a prompt-injection attack against AI support agents.

Read →

WormGPT and FraudGPT: Inside the Malicious-AI-as-a-Service Market

WormGPT and FraudGPT are real, commercially available AI models built for fraud and phishing, sold openly on dark-web markets. Here's what they actually are and what it means for AI security.

Read →

The Crescendo Attack: How Multi-Turn Conversations Jailbreak LLMs

Crescendo is a real, published Microsoft research technique that jailbreaks LLMs using entirely benign-looking messages, by escalating gradually across a conversation instead of asking directly.

Read →

Why Low-Resource Languages Break AI Safety Training

Published research shows AI safety training doesn't transfer evenly across languages. Zulu and Scots Gaelic bypass filters that Spanish and Mandarin don't — here's the real research and why it happens.

Read →

MITRE ATLAS Explained: A Framework for Testing AI Agent Security

MITRE ATLAS is the real, maintained framework for classifying adversarial attacks against AI systems. Here's what it actually covers and why it matters for evaluating an AI security assessment.

Read →