<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel>
<title>LLMGaurd blog</title><link>https://llmgaurd.si/blog/</link><description>LLMGaurd researches and builds security for LLM and AI systems: guardrails, enterprise AI usage protection, and controlled red-team tooling.</description>
<atom:link href="https://llmgaurd.si/feed.xml" rel="self" type="application/rss+xml"/><lastBuildDate>Thu, 01 Oct 2026 18:16:42 GMT</lastBuildDate>
<item><title>CARBONATO plants an AI agent on Docker hosts to steal API keys</title><link>https://llmgaurd.si/blog/carbonato-botnet-hermes-agent-docker/</link><guid>https://llmgaurd.si/blog/carbonato-botnet-hermes-agent-docker/</guid><pubDate>Thu, 01 Oct 2026 08:00:00 GMT</pubDate><description>CARBONATO worms through exposed Docker daemons and plants an unmodified Hermes Agent, reprogrammed by a 39-line file to steal AI API keys via Telegram.</description></item>
<item><title>Shadow AI at work: what employees paste into AI tools</title><link>https://llmgaurd.si/blog/shadow-ai-enterprise-data-leakage/</link><guid>https://llmgaurd.si/blog/shadow-ai-enterprise-data-leakage/</guid><pubDate>Wed, 30 Sep 2026 08:00:00 GMT</pubDate><description>Banning AI tools pushes usage out of sight. A practical approach to visibility, data protection, and policy that lets teams use AI safely.</description></item>
<item><title>Indirect prompt injection: when your agent obeys the wrong text</title><link>https://llmgaurd.si/blog/indirect-prompt-injection-agents/</link><guid>https://llmgaurd.si/blog/indirect-prompt-injection-agents/</guid><pubDate>Sat, 26 Sep 2026 08:00:00 GMT</pubDate><description>Why agents that read emails, web pages, and documents can be steered by attackers who never talk to them, and the architecture patterns that limit the damage.</description></item>
<item><title>The OWASP Top 10 for LLM Applications, explained for builders</title><link>https://llmgaurd.si/blog/owasp-top-10-llm-practitioners-guide/</link><guid>https://llmgaurd.si/blog/owasp-top-10-llm-practitioners-guide/</guid><pubDate>Tue, 22 Sep 2026 08:00:00 GMT</pubDate><description>A practical walk through each risk in the OWASP LLM Top 10 (2025), what it looks like in real systems, and the first control worth adding.</description></item>
</channel></rss>
