Supply Chain for AI: When the Poison Enters Before the First Inference
Loading some weights executes code. Importing a library steals your API key. The model you download and the package you install are the atta
Loading some weights executes code. Importing a library steals your API key. The model you download and the package you install are the atta
The attacker isn't in the session where they attack. They poisoned the knowledge base days earlier and the poison waited, dormant, until a v
The same agent, with the same injection, causes either a total account takeover or zero damage. The only difference is the token you gave it
You ask your agent to set up the environment and run the tests. A hidden comment in the README is enough for it to exfiltrate your SSH key a
You connect your agent to an MCP server to check the weather. Just hiding instructions in a tool's description is enough to make it read you
Your coding agent loads hidden rule files all on its own, without you asking. Poisoning just one with invisible instructions is enough to in
Deploy the same MLOps platform used by Google, Bloomberg and Spotify on your own machine with k3s. Automated ML pipelines, a model registry
Deploy Bulwark Gateway on Kubernetes: a fail-closed proxy with a regex hot path, ML scanners, semantic enrichment, SDK and red teaming to pr
In production environments with Windows Server Failover Cluster (WSFC), the Cloud Witness-based quorum uses an Azure Storage Account as witn
Your agent doesn't need to be attacked directly. It's enough to poison a website, a ticket or an email that it will consume automatically.
A poisoned README can make your agent exfiltrate secrets. We build a lab to prove it and learn how to defend ourselves.
A common scenario in teams managing Azure infrastructure with IaC: the Windows systems team opens a ticket requesting disk changes on a VM.