Mark RadarMARK RADAR
About
EN
Sign in

High-Risk Flaws in AI and LLM Applications Reach 2.7 Times Overall Average

1 reports · First detected 2026-07-02 · Last active 2026-07-02

Companies are rapidly adopting large language models (LLMs) and AI applications, improving operational efficiency and security testing while also expanding attack surfaces such as prompt injection, data leakage and access-control failures. Security company Cobalt said AI systems are emerging as a new risk for corporate cybersecurity governance, making expert human validation indispensable.

Cobalt’s latest penetration-testing report found that high-risk vulnerabilities accounted for 32% of flaws in AI applications, 2.7 times the average across all applications. Nearly 80% of respondents also said automated tools had missed important vulnerabilities, indicating that AI can currently accelerate testing but cannot yet replace cybersecurity professionals.

All Coverage

1 original reports

The Backstory

The history behind this event
More Than 60% of LLM iOS Apps Expose AI Credentials or Proxy Access Risksfirst seen 2026-06-24 · 1 reports · similarity 0.75 · same topic: Large Language Models (LLMs)

A Wake Forest University study of credential management in large language model, or LLM, iOS apps found that mobile applications may leak API keys at runtime or connect to AI services through backend proxies lacking authorization controls. Such vulnerabilities could allow attackers to misuse developers' resources and access services, creating additional costs and data risks.

The study found that as many as 64% of the LLM iOS apps tested exposed API credentials or unauthorized backend proxies, indicating that more than 60% were potentially vulnerable to misuse of AI service access information. Only a small number fixed the issues after researchers notified the developers. Available information does not specify the study's publication date, the total number of apps tested, the number of developers that made fixes or the amount of losses.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)