03/09/2026
Would you notice if your AI chatbot leaked a customer's credit card number while just "summarizing complaints"? Most teams wouldn't until it's too late.
That's exactly what LLM02: Sensitive Information Disclosure looks like in the real world, and it's the second-biggest risk on OWASP's Top 10 list for AI applications. No hacking required — just an AI given too much access and too little oversight.
In this video, Vista InfoSec breaks it down with a real, live attack demo — showing how an AI chatbot's backend tool access can be exploited to expose (and even delete!) user data.
You'll also learn the exact OWASP-recommended defenses every business using AI should have in place.
Watch the full video here: https://www.youtube.com/watch?v=37wX9n1553A&list=PLRdtB0avncuE
Do you think most companies even know what data their AI tools can see? Drop your thoughts below