Fetching from the wire…
Agents2026-08-12 · source-backed
LLM2SQLi, LLM2XSS, LLM2SSTI, LLM2CommandInjection, LLM2IDOR, LLM2CSRF, LLM2XXE, LLM2SSRF (arXiv 2608.10281). The model doesn't create the flaw. It acts as a mediation layer carrying attacker-controlled data past sanitization the app assumed was there. They tested LLM2SSRF against a purpose-built target across seven models and found wide variation in which ones relay the payload. The conclusion I didn't expect: model choice is now a web-application security control, alongside prompt design, architecture, and network rules.
Each link below shares sources, entities, or timing with this story.
Simon Willison released LLM / Same source domain / Shared topic / Tension
Linked by a graph relationship (Simon Willison released LLM); reported by the same outlet (arxiv.org); overlapping topics (against, attack, model).
Simon Willison released LLM / Shared entity: LLM / Earlier coverage / Tension
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-07-27.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-19.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-18.
Simon Willison released LLM / Shared topic
Linked by a graph relationship (Simon Willison released LLM); overlapping topics (against, attack, control, model).
Simon Willison released LLM / Shared entity: LLM / Earlier coverage
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-07-31.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-19.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-08-07.