<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>AI Dark Arts on Vivian@SecMomBag</title><link>https://vvnblog.com/en/series/ai-dark-arts/</link><description>Recent content in AI Dark Arts on Vivian@SecMomBag</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>Copyright © 2026 Vivian All Rights Reserved.</copyright><lastBuildDate>Sun, 06 Sep 2026 00:00:00 +0800</lastBuildDate><atom:link href="https://vvnblog.com/en/series/ai-dark-arts/index.xml" rel="self" type="application/rss+xml"/><item><title>AI Dark Arts (18): Approve Once, Trust Forever? The MCP Client Attack Surface</title><link>https://vvnblog.com/en/posts/ai-dark-arts-18/</link><pubDate>Sun, 06 Sep 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-18/</guid><description>Does approving a config file once mean trusting it forever? From MCPoison and CurXecute to mcp-remote and MCP Inspector, this is how the client side of MCP gets attacked.</description></item><item><title>AI Dark Arts (17): The Tool Definition Is More Dangerous Than the Tool</title><link>https://vvnblog.com/en/posts/ai-dark-arts-17/</link><pubDate>Sat, 05 Sep 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-17/</guid><description>A tool description nobody reads closely is enough to make an AI hand database tokens to an attacker. Four ways MCP tool poisoning works, and where to stop it when you bring MCP in.</description></item><item><title>AI Dark Arts (16): MCP Connects the Tools, and the Risk Comes With Them</title><link>https://vvnblog.com/en/posts/ai-dark-arts-16/</link><pubDate>Mon, 17 Aug 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-16/</guid><description>Three roles in Host, Client and Server, three capabilities in tools, resources and prompts. Understand how MCP works and you can see which part the risk arrives through.</description></item><item><title>AI Dark Arts (15): When the AI Acts on Its Own, Taking Apart the Moment an Agent Falls</title><link>https://vvnblog.com/en/posts/ai-dark-arts-15/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-15/</guid><description>Once an AI has tools, memory and an autonomous loop, a mistake no longer stops at the answer. A tool argument, a sentence in memory, a text file in the project: an agent can promote any of them into an instruction it treats as approved.</description></item><item><title>AI Dark Arts (14): Find Out What the AI Is Allowed to Do, Then Let It Do the Damage (Excessive Agency)</title><link>https://vvnblog.com/en/posts/ai-dark-arts-14/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-14/</guid><description>Tools, arguments, execution identity, permission scope. Work through them one at a time and you can usually see where the excessive agency is hiding.</description></item><item><title>AI Dark Arts (13): Model Output Goes Straight Into the System, Now What?</title><link>https://vvnblog.com/en/posts/ai-dark-arts-13/</link><pubDate>Fri, 14 Aug 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-13/</guid><description>When a model&amp;rsquo;s answer is not meant for a human but goes straight into a browser, a database or a shell, it is no different from text submitted through a form.</description></item><item><title>AI Dark Arts (12): Break The Prompt, From Fooling the Model to Slipping Past the Filter</title><link>https://vvnblog.com/en/posts/ai-dark-arts-12/</link><pubDate>Thu, 13 Aug 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-12/</guid><description>Levels four and five of Break The Prompt: how a full set of system instructions gets translated out in the open, and how the filter in front of the output gets walked around.</description></item><item><title>AI Dark Arts (11): Break The Prompt, Talking an AI Out of Its Secrets</title><link>https://vvnblog.com/en/posts/ai-dark-arts-11/</link><pubDate>Wed, 12 Aug 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-11/</guid><description>Levels one to three of Break The Prompt, and how the rules written into a system prompt come apart one at a time.</description></item><item><title>AI Dark Arts (10): Images Can Cast Spells Too, Multimodal Injection</title><link>https://vvnblog.com/en/posts/ai-dark-arts-10/</link><pubDate>Tue, 11 Aug 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-10/</guid><description>Once a model starts reading images and documents, the spell no longer has to be typed into the chat window.</description></item><item><title>AI Dark Arts (09): Spells Hidden in Documents, Indirect Injection and RAG Poisoning</title><link>https://vvnblog.com/en/posts/ai-dark-arts-09/</link><pubDate>Mon, 10 Aug 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-09/</guid><description>How indirect prompt injection uses RAG poisoning to make an AI read malicious documents, leak data, and even fire off tool calls.</description></item><item><title>AI Dark Arts (08): Jailbreaking AI, What Prison Is It Actually Breaking Out Of?</title><link>https://vvnblog.com/en/posts/ai-dark-arts-08/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-08/</guid><description>Someone asked ChatGPT to play their late grandmother, and it offered condolences while reading out five Windows keys. Jailbreaking goes after the model&amp;rsquo;s own prison.</description></item><item><title>AI Dark Arts (07): What Is Prompt Injection, and Why Can't an LLM Block It?</title><link>https://vvnblog.com/en/posts/ai-dark-arts-07/</link><pubDate>Sat, 08 Aug 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-07/</guid><description>Why does a carefully written system prompt still lose to one sentence? To an LLM, instructions and data look exactly the same.</description></item><item><title>AI Dark Arts (06): Standing on the Shoulders of Giants, How Do You Choose an AI Security Framework?</title><link>https://vvnblog.com/en/posts/ai-dark-arts-06/</link><pubDate>Fri, 07 Aug 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-06/</guid><description>There are plenty of AI security frameworks. Which one should you use? Start by asking what problem you are trying to solve and the answer gets a lot clearer.</description></item><item><title>AI Dark Arts (05): Where Is the Attack Surface in an AI System? From Data to the Supply Chain</title><link>https://vvnblog.com/en/posts/ai-dark-arts-05/</link><pubDate>Thu, 06 Aug 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-05/</guid><description>An AI system runs through data, model, application, system, and supply chain. Overlook the trust boundary at any one of them and it becomes the way in.</description></item><item><title>AI Dark Arts (04): How Is Attacking AI Different from Attacking a Traditional System? What Does an AI Red Team Test?</title><link>https://vvnblog.com/en/posts/ai-dark-arts-04/</link><pubDate>Wed, 05 Aug 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-04/</guid><description>Attacking AI means working out where the whole AI system can be misled, abused, or bypassed into doing something nobody designed it for.</description></item><item><title>AI Dark Arts (03): AI Is the Best Assistant a Security Team Has, and the Attacker's Newest Weapon</title><link>https://vvnblog.com/en/posts/ai-dark-arts-03/</link><pubDate>Tue, 04 Aug 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-03/</guid><description>AI does not take sides. Defenders use it to get through logs nobody has time to read, attackers use it to write phishing emails and generate deepfakes, and it has now started running attacks by itself.</description></item><item><title>AI Dark Arts (02): Why Does AI Make Things Up with a Straight Face? How AI, ML, and GenAI Work</title><link>https://vvnblog.com/en/posts/ai-dark-arts-02/</link><pubDate>Mon, 03 Aug 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-02/</guid><description>AI hallucination is not a bug. It is what you get when a machine writes by chaining probabilities.</description></item><item><title>AI Dark Arts (01): Why Is AI Becoming a Target?</title><link>https://vvnblog.com/en/posts/ai-dark-arts-01/</link><pubDate>Sun, 02 Aug 2026 00:00:00 +0800</pubDate><guid>https://vvnblog.com/en/posts/ai-dark-arts-01/</guid><description>One prompt can make an AI write code, organize documents, and even operate tools. So what happens when someone writes a bad prompt on purpose?</description></item></channel></rss>