<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
  xmlns:atom="http://www.w3.org/2005/Atom"
  xmlns:content="http://purl.org/rss/1.0/modules/content/"
  xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>AIM Intelligence Blog</title>
    <link>https://www.aim-intelligence.com/blog</link>
    <description>Latest insights on AI security, red teaming, LLM safety, and enterprise AI from the AIM Intelligence research and engineering teams.</description>
    <language>en-us</language>
    <atom:link href="https://www.aim-intelligence.com/blog/rss.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Wed, 01 Jul 2026 05:35:25 GMT</lastBuildDate>
    <ttl>60</ttl>
    <image>
      <url>https://www.aim-intelligence.com/images/logo_top.svg</url>
      <title>AIM Intelligence Blog</title>
      <link>https://www.aim-intelligence.com/blog</link>
    </image>

    <item>
      <title>&quot;Vetted, Self-Contained Sources&quot;: What We Found Inside a NASA Mission&apos;s Public Chatbot</title>
      <link>https://www.aim-intelligence.com/blog/vetted-self-contained-sources-what-we-found-inside-a-nasa-missions-public-chatbot-1782884125778</link>
      <guid isPermaLink="true">https://www.aim-intelligence.com/blog/vetted-self-contained-sources-what-we-found-inside-a-nasa-missions-public-chatbot-1782884125778</guid>
      <description>A public chatbot on NASA&apos;s Parker Solar Probe mission page promised users its answers came only from &quot;vetted, self-contained sources.&quot; We red-teamed it into fabricating leaked memos, fake election audits, and climate denial citing the mission&apos;s own data — then disclosed it through proper channels and saw the endpoint taken offline.</description>
      <author>Arth Singh</author>
      <category>SECURITY</category>
      <pubDate>Wed, 01 Jul 2026 05:35:25 GMT</pubDate>
      <enclosure url="https://www.aim-intelligence.com/blog/thumbnails/vetted-self-contained-sources-what-we-found-inside-a-nasa-missions-public-chatbot-1782884125778.jpeg" type="image/jpeg" length="0" />
    </item>
    <item>
      <title>The Helpfulness Trap: Claude Opus 4.8 and the CBRN Breach Hidden in Plain Sight</title>
      <link>https://www.aim-intelligence.com/blog/helpfulness-trap-opus-48</link>
      <guid isPermaLink="true">https://www.aim-intelligence.com/blog/helpfulness-trap-opus-48</guid>
      <description>No jailbreak, no tricks — just professionally framed requests. Using our Stinger red-teaming engine, we collected 83 confirmed CBRN breaches from Claude Opus 4.8.</description>
      <author>Taewoong Kang</author>
      <category>RESEARCH</category>
      <pubDate>Wed, 24 Jun 2026 09:16:43 GMT</pubDate>
      <enclosure url="https://www.aim-intelligence.com/blog/thumbnails/helpfulness-trap-opus-48.jpeg" type="image/jpeg" length="0" />
    </item>
    <item>
      <title>Why AI Security Is Moving Toward Continuous Monitoring</title>
      <link>https://www.aim-intelligence.com/blog/continuous-ai-security</link>
      <guid isPermaLink="true">https://www.aim-intelligence.com/blog/continuous-ai-security</guid>
      <description>A recent NIST publication argues that no finite set of AI safety rules can protect against all future attacks. As AI agents gain access to tools and enterprise systems, security is shifting from static guardrails toward continuous monitoring and adaptation.</description>
      <author>Jongho Shin</author>
      <category>RESEARCH</category>
      <pubDate>Fri, 19 Jun 2026 02:24:58 GMT</pubDate>
      <enclosure url="https://www.aim-intelligence.com/blog/thumbnails/continuous-ai-security.jpeg" type="image/jpeg" length="0" />
    </item>
    <item>
      <title>AI Security Digest — May 2026</title>
      <link>https://www.aim-intelligence.com/blog/ai-security-digest-may-2026</link>
      <guid isPermaLink="true">https://www.aim-intelligence.com/blog/ai-security-digest-may-2026</guid>
      <description>May 2026 was a watershed month for AI security. From the first AI-authored zero-day exploit confirmed in the wild, to a self-propagating npm worm that reached OpenAI&apos;s code-signing pipeline, to prompt injection flaws enabling full RCE in Microsoft&apos;s Semantic Kernel — the attack surface around AI systems expanded on every front. This digest covers seven stories that defined the month, including the release of XL-SafetyBench from AIM Intelligence and collaborators.</description>
      <author>Yonggyu Kim</author>
      <category>DIGEST</category>
      <pubDate>Fri, 12 Jun 2026 06:34:56 GMT</pubDate>
      <enclosure url="https://www.aim-intelligence.com/blog/thumbnails/ai-security-digest-may-2026.jpeg" type="image/jpeg" length="0" />
    </item>
    <item>
      <title>Tool-Mediated Belief Injection: How Tool Outputs Can Cascade Into Model Misalignment</title>
      <link>https://www.aim-intelligence.com/blog/tool-mediated-belief-injection</link>
      <guid isPermaLink="true">https://www.aim-intelligence.com/blog/tool-mediated-belief-injection</guid>
      <description>When we deploy language models with access to external tools, we dramatically expand their capabilities. However, tool access also introduces new attack surfaces that differ fundamentally from traditional prompt injection. We document how adversarially crafted tool outputs can establish false premises that persist and compound across a conversation.</description>
      <author>Siddhant</author>
      <category>RESEARCH</category>
      <pubDate>Sun, 30 Nov 2025 00:00:00 GMT</pubDate>
      <enclosure url="https://www.aim-intelligence.com/blog/thumbnails/tool-mediated-belief-injection.jpeg" type="image/jpeg" length="0" />
    </item>
    <item>
      <title>MisalignmentBench: How We Social Engineered LLMs Into Breaking Their Own Alignment</title>
      <link>https://www.aim-intelligence.com/blog/misalignment-bench</link>
      <guid isPermaLink="true">https://www.aim-intelligence.com/blog/misalignment-bench</guid>
      <description>We got frontier models to lie, manipulate, and self-preserve. Not through prompt injection or jailbreaks. We deployed them in contextually rich scenarios with specific roles and guidelines. The models broke their own alignment trying to navigate the situations we created.</description>
      <author>Siddhant</author>
      <category>RESEARCH</category>
      <pubDate>Thu, 14 Aug 2025 00:00:00 GMT</pubDate>
      <enclosure url="https://www.aim-intelligence.com/blog/thumbnails/misalignment-bench.jpeg" type="image/jpeg" length="0" />
    </item>
    <item>
      <title>How ELITE Reveals Dangerous Weaknesses in Vision-Language AI</title>
      <link>https://www.aim-intelligence.com/blog/elite-vlm-safety</link>
      <guid isPermaLink="true">https://www.aim-intelligence.com/blog/elite-vlm-safety</guid>
      <description>As AI systems evolve to process images and text together, the risks grow exponentially. ELITE doesn&apos;t just measure whether a model is &apos;safe&apos; — it evaluates how dangerous its outputs could be with precision that rivals human reviewers.</description>
      <author>Eugene Choi</author>
      <category>RESEARCH</category>
      <pubDate>Thu, 29 May 2025 00:00:00 GMT</pubDate>
      <enclosure url="https://www.aim-intelligence.com/blog/thumbnails/elite-vlm-safety.jpeg" type="image/jpeg" length="0" />
    </item>
    <item>
      <title>Pressure Point: How One Bad Metric Can Push AI Toward a Fatal Choice</title>
      <link>https://www.aim-intelligence.com/blog/pressure-point</link>
      <guid isPermaLink="true">https://www.aim-intelligence.com/blog/pressure-point</guid>
      <description>In a simulated earthquake response scenario, Claude 4 Opus was given conflicting rules. When pressured by authority, it reversed its ethical decision and recommended letting a critical patient die to optimize an efficiency score.</description>
      <author>Siddhant Panpatil</author>
      <category>RESEARCH</category>
      <pubDate>Mon, 26 May 2025 00:00:00 GMT</pubDate>
      <enclosure url="https://www.aim-intelligence.com/blog/thumbnails/pressure-point.jpeg" type="image/jpeg" length="0" />
    </item>
    <item>
      <title>Exploiting MCP: Emerging Security Threats in Large Language Models (LLMs)</title>
      <link>https://www.aim-intelligence.com/blog/exploiting-mcp</link>
      <guid isPermaLink="true">https://www.aim-intelligence.com/blog/exploiting-mcp</guid>
      <description>Discover how attackers exploit vulnerabilities in the Model Context Protocol (MCP) to manipulate Large Language Models (LLMs), steal data, and disrupt operations. Learn real-world attack scenarios and defense strategies.</description>
      <author>Eugene Choi</author>
      <category>SECURITY</category>
      <pubDate>Wed, 21 May 2025 00:00:00 GMT</pubDate>
      <enclosure url="https://www.aim-intelligence.com/blog/thumbnails/exploiting-mcp.jpeg" type="image/jpeg" length="0" />
    </item>
    <item>
      <title>Making AI Safer with SPA-VL: A New Dataset for Ethical Vision-Language Models</title>
      <link>https://www.aim-intelligence.com/blog/spa-vl-dataset</link>
      <guid isPermaLink="true">https://www.aim-intelligence.com/blog/spa-vl-dataset</guid>
      <description>SPA-VL is a meticulously designed dataset that sets a new standard for safety alignment in VLMs, incorporating diversity, feedback, and real-world relevance to ensure AI systems are both powerful and ethical.</description>
      <author>Eugene Choi</author>
      <category>RESEARCH</category>
      <pubDate>Wed, 27 Nov 2024 00:00:00 GMT</pubDate>
      <enclosure url="https://www.aim-intelligence.com/blog/thumbnails/spa-vl-dataset.jpeg" type="image/jpeg" length="0" />
    </item>
    <item>
      <title>The Hidden Threat: Understanding Indirect Prompt Injection in LLMs</title>
      <link>https://www.aim-intelligence.com/blog/indirect-prompt-injection</link>
      <guid isPermaLink="true">https://www.aim-intelligence.com/blog/indirect-prompt-injection</guid>
      <description>Indirect Prompt Injection (IPI) is a sophisticated attack that manipulates how LLM-integrated applications process external data, causing them to misinterpret maliciously crafted inputs as commands.</description>
      <author>Sejin</author>
      <category>SECURITY</category>
      <pubDate>Mon, 25 Nov 2024 00:00:00 GMT</pubDate>
      <enclosure url="https://www.aim-intelligence.com/blog/thumbnails/indirect-prompt-injection.jpeg" type="image/jpeg" length="0" />
    </item>
    <item>
      <title>Indirect Prompt Injection Attacks Against Web Agents</title>
      <link>https://www.aim-intelligence.com/blog/indirect-prompt-injection-web-agent</link>
      <guid isPermaLink="true">https://www.aim-intelligence.com/blog/indirect-prompt-injection-web-agent</guid>
      <description>Explore how EIA, AdvWeb, and WIPI attack methods exploit vulnerabilities in VLM-powered web agents, revealing serious security concerns for AI systems that interact with web environments.</description>
      <author>Jiankimr</author>
      <category>SECURITY</category>
      <pubDate>Fri, 15 Nov 2024 00:00:00 GMT</pubDate>
      <enclosure url="https://www.aim-intelligence.com/blog/thumbnails/indirect-prompt-injection-web-agent.jpeg" type="image/jpeg" length="0" />
    </item>
    <item>
      <title>Refining Vision-Language Model Benchmarks: Base Query Generation and Toxicity Analysis</title>
      <link>https://www.aim-intelligence.com/blog/vlm-benchmarks-toxicity</link>
      <guid isPermaLink="true">https://www.aim-intelligence.com/blog/vlm-benchmarks-toxicity</guid>
      <description>For existing VLM Safety benchmarks, there are cases where the text alone is sufficiently informative without the image. We explore base query generation and toxicity measurement methods.</description>
      <author>Eugene Choi</author>
      <category>RESEARCH</category>
      <pubDate>Sat, 09 Nov 2024 00:00:00 GMT</pubDate>
      <enclosure url="https://www.aim-intelligence.com/blog/thumbnails/vlm-benchmarks-toxicity.jpeg" type="image/jpeg" length="0" />
    </item>
    <item>
      <title>Defending Web Agents: Advanced Security Strategies through AdvWeb and BrowserART</title>
      <link>https://www.aim-intelligence.com/blog/defending-web-agents</link>
      <guid isPermaLink="true">https://www.aim-intelligence.com/blog/defending-web-agents</guid>
      <description>Explore cutting-edge methodologies for identifying and mitigating vulnerabilities in VLM-powered web agents, including the AdvWeb attack framework and BrowserART red teaming toolkit.</description>
      <author>Sejin</author>
      <category>SECURITY</category>
      <pubDate>Sat, 09 Nov 2024 00:00:00 GMT</pubDate>
      <enclosure url="https://www.aim-intelligence.com/blog/thumbnails/defending-web-agents.jpeg" type="image/jpeg" length="0" />
    </item>
    <item>
      <title>AIM RED TEAM: Insights from the KAIST Lab Meeting on Persona-Based Jailbreak Strategies</title>
      <link>https://www.aim-intelligence.com/blog/kaist-lab-meeting</link>
      <guid isPermaLink="true">https://www.aim-intelligence.com/blog/kaist-lab-meeting</guid>
      <description>This week, we held a productive meeting with the KAIST lab to refine the direction of our ongoing research project and to solidify our experimental design. The focus was on integrating psychological approaches with LLMs to design jailbreak prompts.</description>
      <author>Hyunjun Kim</author>
      <category>RESEARCH</category>
      <pubDate>Fri, 08 Nov 2024 00:00:00 GMT</pubDate>
      <enclosure url="https://www.aim-intelligence.com/blog/thumbnails/kaist-lab-meeting.jpeg" type="image/jpeg" length="0" />
    </item>
    <item>
      <title>Evaluating Text-based VLM Attack Methods: In-depth Look at Figstep</title>
      <link>https://www.aim-intelligence.com/blog/figstep-vlm-attacks</link>
      <guid isPermaLink="true">https://www.aim-intelligence.com/blog/figstep-vlm-attacks</guid>
      <description>To evaluate VLM Safety, it is essential to develop a secure model that incorporates the unique characteristics of VLMs. We analyze Figstep and RTVLM datasets to assess typographic visual prompt attacks.</description>
      <author>Doehyeon</author>
      <category>RESEARCH</category>
      <pubDate>Sat, 02 Nov 2024 00:00:00 GMT</pubDate>
      <enclosure url="https://www.aim-intelligence.com/blog/thumbnails/figstep-vlm-attacks.jpeg" type="image/jpeg" length="0" />
    </item>
  </channel>
</rss>