
Prompt injection is the top OWASP risk for LLM apps but ranks No. 12 in real incidents.
The gap reflects visibility, not danger.
The attack is invisible to vulnerability scanners.
What happened
A study by two leaders of the OWASP Top 10 for LLM Applications, Kyriakos "Rock" Lambros and Steve Wilson, compared the list against 6,639 labeled real-world incidents and found prompt injection ranks No. 12 in actual incidents, despite holding the No. 1 spot on the OWASP list for three consecutive years.
Why it matters
The researchers say the drop measures visibility rather than danger, because prompt injection operates where a vulnerability scanner cannot see it. A CISO who sees a low CVE count and deprioritizes prompt injection is reading the scoreboard wrong.
What to watch
The analysis is exploratory, not peer reviewed, and not the official OWASP release. It is based on 7,714 LLM security incidents from sources like CVE, GitHub Security Advisories, OSV, and the AIAAIC AI-harm database, with 6,639 labeled against a 20-entry taxonomy.
Ask the AI about this article →
The OWASP Top 10 for LLM Applications has listed prompt injection as the top risk for three years, reflecting its theoretical severity. But when two project leaders checked the list against real-world incidents, they found it appears less frequently in labeled events—at No. 12. This does not mean prompt injection is less dangerous; rather, it suggests that current vulnerability scanning methods often miss it, so it goes underreported in incident databases.
The study's data comes from multiple sources, including CVE and the AIAAIC AI-harm database, covering 7,714 incidents, of which 6,639 were labeled. Because the analysis is exploratory and not official, its findings should be seen as a signal for deeper investigation rather than a revision of the OWASP list. For security leaders, the key takeaway is that low CVE counts are not a reliable measure of risk for prompt injection.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Israeli startup DataAgent Ltd
SK Hynix presented a custom HBM concept at SEMICON Taiwan 2026, where compute functions are placed in the base…

The U.S. Department of Defense announced on August 31 that it has deployed ChatGPT Mil, a customized version o…

Nvidia reported earnings that were both remarkable and boring, reflecting its focus on avoiding a consolidated…

Anthropic has agreed to a $35bn cloud-computing contract with Lambda, a Nvidia-backed cloud provider

The Supreme Court of Japan has included about ¥60 million in its fiscal 2027 budget request for AI-related exp…
