0.00 Is a Lab Number. Grok's Incident Standard Is Still Missing.
xAI's Grok 4.20 card reports a 0.00 chat violation rate. The same PDF shows AgentHarm at 0.30. Production, a DSA case, and AB 316 already bind operators.
Securing applications built on language models: the OWASP LLM Top 10, output handling, sandboxing, and trust boundaries.
xAI's Grok 4.20 card reports a 0.00 chat violation rate. The same PDF shows AgentHarm at 0.30. Production, a DSA case, and AB 316 already bind operators.
Adobe's APSB26-146 hotfix closes CVE-2026-75650, a CVSS 10.0 Magento RCE exploited from 4 Sept. Patching is not cleanup: hunt the implant and rotate credentials.
Calif demoed a zero-click WeChat account worm via an incoming call. Tencent blocked the exploit for all users by 28 August. There is no CVE and no reported outbreak.
Manifold showed AI coding agents executing repo-named git helpers before any prompt. We reproduced the sink on Goose 1.41.0 and recorded the 1.44.0 fix.
A threat brief on CVE-2024-37032, the Ollama path-traversal RCE, and what it exposes about self-hosted AI runtimes shipping with no authentication.
Why prompt injection has no clean fix, how direct and indirect variants differ, and which defences measurably reduce risk in production LLM applications.