AI Security: Threats and Defense in the AI Era
A narrative textbook distilled from real incidents between April and July 2026
📚 Read online (below) or grab the file:
What this book is
The five chapters trace one arc: from the moment an AI thinks, to the moment it writes code, to the moment it becomes infrastructure. Each chapter ends with a defender playbook — the concrete steps a security team can take this quarter to harden what they already have.
The book is built from public reporting on real incidents that hit open-source maintainers, banks, hospitals, and frontier labs during a single four-month window. Names, dialogue, and scene details are composites; the attack mechanics, numbers, and references are not. Every chapter carries a statement on scenes and characters so readers never confuse the two.
Table of Contents
-
Introduction
Why This Book Matters Now
What this book covers (and doesn't), how to read it, and the scene-and-character disclaimer every chapter carries.
-
Chapter 1 — When AI Thinks
The LLM That Lies, Hallucinates, and Schemes
Capabilities, authority, and effect gates — the three lenses that explain why the same model is safe in one deployment and dangerous in another.
-
Chapter 2 — When AI Builds the Software
The Code That Bites Back
Vibe coding, SecureVibeBench, the Mastra and AsyncAPI supply-chain attacks, recovery playbooks, and what a real incident-response document should look like.
-
Chapter 3 — When AI Becomes Infrastructure
System-Level Threats and the Defender Response
Insider threats in agentic architectures, memory poisoning, watermarks and provenance, and the tooling defenders are building in response.
-
Conclusion
Take-aways for Defenders in the AI Era
Seven take-aways, five actions for this quarter, and the trends worth watching through 2026–2027.
About the sources
The book draws on roughly 150 Inoreader articles published between April and July 2026 — research from Anthropic, OpenAI, Google DeepMind, Trail of Bits, Cloudflare, Microsoft Threat Intelligence, plus working papers from independent teams on arXiv. Each chapter ends with a References section grouping URLs by month so the reader can verify any number that struck them.
Where the underlying paper appeared on arXiv, the identifier is preserved exactly as in the original research. Readers should still verify against the source before citing in their own reports — arXiv IDs occasionally move between preprint and published versions.
Source files
The HTML and EPUB files behind this site are kept alongside the blog that hosts it. This is a research artifact, not a finished commercial textbook — the text is released for non-commercial reading and reference.