
About this episode
AI Agents can be powerful tools for an organization - but are they a security risk? Richard talks to Niall Merrigan about his experiences dealing with the various ways that LLMs can be attacked, starting with prompt injection. While some attacks are humorous, others can be very serious, especially in the context of agents, where the right prompt can cause an agent to use its capabilities to access or affect data outside its expected behavior. This has already led to several well-publicized CVEs, including the ServiceNow Privilege Escalation advisory. New tools have emerged to help restrict prompts and keep agents on task - but as with all things security, this is another set of tools you need to get familiar with!
Links
- AI Recommendation Poisoning
- Detecting Prompt Injection Attacks
- Mark Russinovich Crescendo Multi-Turn LLM Jailbreak Attack
- Cross-Site Scripting (XSS)
- Cameron Mattis LinkedIn
- Privilege Escalation in ServiceNow AI Platform
- Azure AI Content Safety Prompt Shields
- Task Adherence
- Simon Willison's Lethal Trifecta
- Microsoft Agent 365
- PyRIT
- OWASP Securing Agentic Applications Guide
Recorded February 16, 2026
Get every episode summarized
Each time RunAs Radio publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from RunAs Radio

State of WSUS with Adam Marshall
RunAs Radio

Reimagining Intranets with Susan Hanley
RunAs Radio

Security Features of PowerShell 7 with Mike O'Neill
RunAs Radio

Automatic Attack Disruption with Liz Tesch
RunAs Radio