The moment an enterprise connects a large model to its business systems, the model itself becomes a new attack surface. The security community no longer disputes this: prompt injection has topped the OWASP LLM risk list for consecutive editions, and real-world attacks have moved from labs to crime scenes.

Three landmark incidents

Data exposure: the DeepSeek database incident

In January 2025, researchers found several DeepSeek databases had been left accessible without authentication for a period, containing chat logs and API keys. The issue was quickly fixed, but it reminded the whole industry: the security level of AI companies directly determines public trust in the technology.

Deepfake: the HK$200 million "video conference"

In early 2024, employees of a multinational's Hong Kong office joined a "CFO-initiated" video call in which several "colleagues" were deepfaked personas — resulting in fraudulent transfers of about HK$200 million. Seeing is no longer believing.

Crime-as-a-service models

Underground models like WormGPT and FraudGPT circulate on dark-web subscriptions, optimized for phishing, malware and social-engineering scripts. Once weaponized, model capabilities lower both the threshold and cost of attack.

Threat landscape: three layers

🗺️ LLM security threat map

Model layer: training-data poisoning, backdoors, model extraction and membership inference, model-file supply-chain pollution;

Application layer: direct/indirect prompt injection, RAG corpus poisoning, sensitive information leakage, hallucination abuse, privilege escalation;

Agent layer: excessive tool permissions, injection-driven agent manipulation, plugin and MCP supply-chain risks, privilege escape in multi-agent collaboration.

Especially alarming is indirect prompt injection: attackers embed malicious instructions in web pages, emails or documents that the AI reads — once agents hold real tool permissions (email, orders, APIs), the attack escalates from "making the model say wrong things" to "making the system do wrong things".

Defense in depth

Referencing the NIST AI RMF and China's generative-AI security requirements, we recommend four defensive layers:

Security is not a pre-launch checklist but a continuous engineering discipline across the AI lifecycle.

The NineZenith practice

Zenith-Safety is designed exactly on these four layers: data lineage audit and poisoning detection, built-in red-team baselines, prompt-injection identification and compliance filtering, plus operations-layer linkage with content labeling and audit tracing. Combined with Zenith-Act's fully private deployment, enterprise data and model weights never leave the customer's domain. In AI-era cybersecurity, whoever builds security as an intrinsic property of AI systems will go steady and far.