Summary
A new analysis by Kyriakos “Rock” Lambros and Steve Wilson, leaders of the OWASP Top 10 for LLM Applications project, reveals a significant discrepancy between expert judgment and public incident records regarding prompt injection attacks. While prompt injection consistently ranks as the number one threat on the OWASP Top 10 for LLM Applications, it appears much lower in real-world incident data because its nature makes it invisible to traditional vulnerability scanners.