Sean Park
8 articles
-
ResearchPwning Agentic AI Part III: Securing Your AI Agent
This final installment of our trilogy on Pwning Agentic AI covers defenses against the return-to-tool (RTT) attacks—read-only Postgres bypass, support-ticket ransomware, and KYC passport exfiltration—demonstrated in Part II. Here we take a look at what works and what doesn’t against this new class of attack.
August 6th, 2026 12 minSean Park
Read article -
ResearchPwning Agentic AI Part II: When Trusted Agents Do Untrusted Things
Return-to-tool isn't theoretical. TrendAI™ Research presents three cases showing exactly how a compromised agent—wielding only its own approved tools—becomes the most dangerous component in the stack.
July 16th, 2026 13 minSean Park
Read article -
ResearchSlopsquatting: When AI Agents Hallucinate Malicious Packages
Our research examines how AI coding assistants can hallucinate plausible but non-existent package names—therefore enabling slopsquatting attacks—while also providing practical defense strategies that organizations can implement to secure their development pipelines
June 5th, 2025Sean Park
Read article -
ResearchUnveiling AI Agent Vulnerabilities Part V: Securing LLM Services
To conclude our series on agentic AI, this article examines emerging vulnerabilities that threaten AI agents, focusing on providing proactive security recommendations on areas such as code execution, data exfiltration, and database access.
May 28th, 2025 7 minSean Park
Read article -
ResearchUnveiling AI Agent Vulnerabilities Part IV: Database Access Vulnerabilities
How can attackers exploit weaknesses in database-enabled AI agents? This research explores how SQL generation vulnerabilities, stored prompt injection, and vector store poisoning can be weaponized by attackers for fraudulent activities.
May 21st, 2025 7 minSean Park
Read article -
ResearchUnveiling AI Agent Vulnerabilities Part III: Data Exfiltration
In the third part of our series we demonstrate how risk intensifies in multi-modal AI agents, where hidden instructions embedded within innocuous-looking images or documents can trigger sensitive data exfiltration without any user interaction.
May 12th, 2025Sean Park
Read article -
ResearchUnveiling AI Agent Vulnerabilities Part II: Code Execution
Our research examines vulnerabilities that affect Large Language Model (LLM) powered agents with code execution, document upload, and internet access capabilities. This is the second part of a series diving into the critical vulnerabilities in AI agents.
May 5th, 2025 7 minSean Park
Read article -
ResearchUnveiling AI Agent Vulnerabilities Part I: Introduction to AI Agent Vulnerabilities
This introductory post kicks off a blog series on AI agent vulnerabilities, outlining key security risks like prompt injection and code execution, and sets the stage for future parts, which will dive deeper into issues such as code execution flaws, data exfiltration, and database access threats.
April 22nd, 2025 6 minSean Park, Principal Threat Researcher
Read article