New release : CTI Report - Pharmaceutical and drug manufacturing 

                 Download now

Enterprise LLM Threat Atlas : real-world incidents, research cases, Mitre mappings

This report provides an architecture-agnostic view of current, high-probability threats affecting enterprise use of Large Language Models (LLMs) and recommended countermeasures for:

  • Self-hosted/internal LLM applications (customer owns app, infrastructure, integrations)
  • LLM functionality embedded into SaaS products (customer controls configuration, access, and governance)

The dominant near-term risk is not “model hacking” in isolation, but LLMs acting as a high-bandwidth interface to enterprise data and actions. The most common and impactful threat patterns are:

  1. Indirect prompt injection via enterprise content retrieved by RAG/copilots (malicious instructions embedded in documents/pages/emails).
  2. Over-permissioned connectors and copilots enabling rapid discovery and summarization of sensitive data post-compromise.
  3. Tool/agent abuse where the model can trigger actions (tickets, emails, sharing links, cloud operations) without robust policy gating.
  4. RAG/knowledge base poisoning degrading integrity or inserting malicious instructions.
  5. Operational data leakage through logs, transcripts, analytics, and poor retention controls.
  6. Supply-chain and platform risks in self-hosted stacks (models, containers, inference servers, dependencies).

Tool/Agent abuse and supply-chain attacks seem to be the most important current risks for enterprise LLM infrastructure. Indeed, it is in those two domains that we found the highest number of public reports – either real-world incidents or research cases.

This report includes:

  • Trending threat scenarios with attack paths / modus operandi, with a lot of examples
  • A MITRE ATLAS + MITRE ATT&CK mapping approach (ATLAS for AI-native techniques; ATT&CK for the surrounding intrusion lifecycle)
  • A control baseline (Prevent/Detect/Respond) for self-hosted and SaaS-embedded LLMs
  • A monitoring and incident response appendix

Articles par catégorie