Agentic AI: Hybrid systems combining LLMs with non-AI components (tools, memory) to autonomously execute tasks
Indirect Prompt Injection: Attacks where malicious instructions are embedded in external data (e.g., webpages) that the agent retrieves and processes
CIA Triad: Confidentiality, Integrity, and Availability—the three pillars of information security
MCP: Model Context Protocol—a standard for connecting AI assistants to systems and data
RAG: Retrieval-Augmented Generation—fetching external data to ground LLM responses
SSRF: Server-Side Request Forgery—a vulnerability where an attacker forces a server to make requests to internal resources
XSS: Cross-Site Scripting—injecting malicious scripts into trusted websites
PII: Personally Identifiable Information—sensitive data like names or financial records