Writing High-Quality AI Vulnerability Reports
How to give vendors enough evidence to reproduce, assess, and fix an AI vulnerability without overstating the claim.
Category
Evidence-led triage and analysis of vulnerabilities affecting AI models, frameworks, services, and dependencies.
How to give vendors enough evidence to reproduce, assess, and fix an AI vulnerability without overstating the claim.
How to triage an untrusted model repository using provenance, scanning, isolation, and evidence.
Why model formats and loaders matter when an AI system receives an untrusted artifact.
How to determine whether a vulnerability in an LLM framework or dependency actually affects your deployed AI application.
A defensive method for analyzing containment escapes across AI code interpreters, training jobs, agents, and shared infrastructure.
How to identify, prioritize, patch, mitigate, and verify vulnerabilities across GPU-backed AI infrastructure.
How security teams can connect CISA KEV exploitation evidence to real AI infrastructure, exposure, ownership, and verification.
A practical guide to using CVSS 4.0 for AI vulnerabilities without confusing technical severity with local risk.
An evidence framework for distinguishing model behavior, product weakness, boundary failure, and actionable prompt-injection vulnerability disclosures.
A defensive workflow for deciding whether an SSRF advisory affects an AI fetcher, proving reachability, applying mitigations, and verifying closure.
A hands-on worksheet for mapping AI security advisories to your exact component, version, configuration, reachability, evidence, fix, and verified closure.
A practical, evidence-led method for deciding whether an AI CVE or advisory affects your models, runtimes, frameworks, services, and deployments.