VentureBeat
Prompt injection ranks No. 1 with OWASP and No. 12 in the incident record. The attack itself is invisible to a scan.

Analysis of 6,639 real-world incidents ranks prompt injection at #12, not #1, due to low visibility from undetectable instruction chains. A Bayesian model of 7,714 LLM security events shows weak expert–data agreement (Cohen’s κ = 0.20). Researchers recommend an external authorization gate that blocks models from granting themselves DNS-change privileges, curbing autonomous high-impact actions while allowing routine remediation.