{
  "id": 3318447,
  "title": "Prompt injection ranks No. 1 with OWASP and No. 12 in the incident record. The attack itself is invisible to a scan.",
  "url": "https://urgent.news/2026/08/25/prompt-injection-ranks-no-1-with-owasp-and-no-12-in-the-incident",
  "topic": "ai",
  "section": "AI",
  "published": "2026-08-25T17:24:22.000Z",
  "source": {
    "name": "VentureBeat",
    "slug": "venturebeat",
    "url": "https://venturebeat.com/security/prompt-injection-ranks-no-1-with-owasp-and-no-12-in-the-incident-record-the-attack-itself-is-invisible-to-a-scan"
  },
  "original_language": "en",
  "account": "Cybersecurity experts have identified prompt injection as the top risk for large language model (LLM) applications, according to the OWASP Top 10 for LLM Applications. However, when compared to real-world incidents, prompt injection ranks only 12th in the incident record. This discrepancy is due to the fact that the attack operates in a way that is not visible to vulnerability scanners. The attack involves injecting malicious prompts into the content that the model reads, allowing the attacker to make tool calls using the attacker's credentials. Current defenses against prompt injection involve adversarial testing and hard caps on the agent's reach, but these measures are not foolproof. The authors of the study emphasize that prompt injection is the most understood LLM attack, but the defenses against it are not perfect. They recommend deploying agents that can read attacker payloads in logs and rewrite DNS with valid credentials, but acknowledge that this comes at the cost of the agent's ability to improvise high-impact changes. The authors argue that the current defenses are not sufficient to prevent the most dangerous attacks, and that systems need to be designed with the assumption that prompt injection will occur.",
  "summary": "A CISO who sees a low CVE count and deprioritizes prompt injection is reading the scoreboard wrong. Prompt injection has held the No. 1 spot on the OWASP Top 10 for LLM Applications for three consecutive years . When two leaders of that list checked it against 6,639 labeled real-world incidents, it came back at No. 12. The drop measures visibility rather than danger, because the attack operates…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}