News

  • Press Release

Share

Facebook Twitter linkedin
2026.07.28

Following in the footsteps of "AI MONBAN," we are launching our second product: "AI Application Vulnerability Assessment Service," which combines world-class AI Red Teaming with web security expertise.

This report examines the security risks inherent in AI-powered services from an attacker's perspective, presenting the identified problems and specific improvement methods.

Cyber Security Cloud, Inc. (Headquarters: Shinagawa-ku, Tokyo; Representative Director, President and CEO: Toshihiro Koike; hereinafter referred to as "the Company"), a global security manufacturer, will begin offering its "AI Application Vulnerability Assessment Service" on July 28, 2026. This service diagnoses unique security risks for AI applications that utilize LLM, RAG, MCP, AI agents, and other technologies.

This service is the second in our group's AI security domain, following "AI MONBAN," which visualizes, controls, and audits the data flow of MCPs related to AI and AI agents. We are expanding our services from "visualizing and controlling" the risks when using AI to "diagnosing and evaluating" the security of the AI application itself.

■ AI applications are now required to undergo safety verification before being released to the public.

In recent years, the use of generative AI and AI agents has become widespread, and the production use of AI applications incorporating RAG, MCP, Tool Calling, and other technologies is rapidly progressing.

On the other hand, AI applications have risks that differ from traditional web applications, such as prompt injection, leakage of confidential information, and execution of malicious tools. Furthermore, the attack surface is expanding due to integration with external APIs, business systems, and various tools, and there are cases where traditional vulnerability assessments alone are insufficient for evaluation.

Against this backdrop, we offer an "AI Application Vulnerability Assessment Service" that examines the risks specific to AI/LLM, RAG, MCP, and AI agents from the attacker's perspective, and provides concrete improvement and mitigation measures.

 

■ About the 'AI Application Vulnerability Assessment Service'

In recent years, the use of generative AI and AI agents has become widespread, and the production use of AI applications incorporating RAG, MCP, Tool Calling, and other technologies is rapidly progressing.

On the other hand, AI applications have risks that differ from traditional web applications, such as prompt injection, leakage of confidential information, and execution of malicious tools. Furthermore, the attack surface is expanding due to integration with external APIs, business systems, and various tools, and there are cases where traditional vulnerability assessments alone are insufficient for evaluation.

Against this backdrop, we offer an "AI Application Vulnerability Assessment Service" that examines the risks specific to AI/LLM, RAG, MCP, and AI agents from the attacker's perspective, and provides concrete improvement and mitigation measures.

 

■ About the 'AI Application Vulnerability Assessment Service'

The "AI Application Vulnerability Assessment Service" is a professional service that evaluates the security of AI applications, including web applications using LLM, generative AI services, RAG systems, AI agents, and systems using MCP.

Based on the diagnostic items outlined in "OWASP Top 10 for Large Language Model Applications," the scope of the diagnosis and attack scenarios are individually designed according to the target system's purpose, usage model, reference data, permissions, and integration status with external services.

By combining systematic inspections using automated diagnostic tools with AI Red Teaming by experts, we verify risks that are difficult to detect through machine checks alone, such as those arising from system specifications, permission designs, business workflows, the autonomous behavior of AI agents, and external integrations.

After the assessment, a diagnostic report will be provided outlining the nature, severity, and expected impact of the detected vulnerabilities, as well as specific improvement and mitigation measures.

■ Main diagnostic targets

  • Web application generation AI service using LLM
  • A system using RAG
  • AI Agent/Multi-Agent System
  • A system using MCP/Tool Calling
  • Business systems using the LLM API
  • Multimodal AI system

* The scope of the diagnosis will be individually designed according to the system configuration and usage model.

■ Main diagnostic perspectives

  • LLM/Generative AI: Prompt injection, data leakage, output control, supply chain risk, etc.
  • RAG: Data corruption, access control, information leakage, etc.
  • AI agents: for access control, preventing unauthorized tool execution, and integrating with external systems.
  • MCP/Tool Calling: Authentication and authorization, MCP server, credential management, integration with external services, etc.

* Depending on the system configuration, we will also check the connectivity with web applications, APIs, authentication/authorization, databases, cloud infrastructure, etc.

 

■ Features of the 'AI Application Vulnerability Assessment Service'

 

1. Leveraging expertise gained in web and cloud security to AI security.

Our company provides security services to protect web applications from cyberattacks, and we have accumulated expertise in the web and cloud security domain, including WAF operation, defense, vulnerability information collection and management, and managed security for cloud environments.
This service not only detects vulnerabilities specific to AI and LLM, but also assesses risks based on the actual system configuration and operation, including the web applications, APIs, authentication and authorization systems, databases, and cloud infrastructure that make up the AI application. By combining AI-specific expertise with our accumulated knowledge of web and cloud security, we provide practical diagnostics covering the entire AI application.

2. Systematic diagnosis based on OWASP Top 10 for Large Language Model Applications

Based on the international AI/LLM security standard, "OWASP Top 10 for Large Language Model Applications," we systematically assess AI application-specific risks such as LLM, RAG, AI agents, MCP, and Tool Calling.

We design diagnostic items and attack scenarios individually according to the target system's purpose and configuration, and conduct diagnostics that are tailored to the actual usage environment.

3. AI Red Teaming by Experts

Because AI and LLM behave differently depending on the input content and usage environment, there is a risk that they cannot be adequately evaluated by automated diagnosis alone.

In addition to systematic inspections using automated diagnostic tools, this service includes AI Red Teaming conducted by experts from the attacker's perspective. It examines risks that are difficult to detect through automated diagnostics alone, such as indirect prompt injection and attacks that exploit the permissions and external connections of AI agents, and evaluates the overall security of the AI application.

4. Practical support that encompasses everything from diagnosis to improvement.

Based on the configuration and usage of the target system, we conduct a diagnostic assessment and provide a diagnostic report that summarizes the risks, anticipated impacts, priority of countermeasures, and specific improvement/mitigation measures for the vulnerabilities detected.

Through the diagnostic results reporting meeting, we will explain the findings and, as needed, propose related services such as improvement consulting and implementation/operation support to support our customers' ongoing AI security measures.

■ Business partnership with Konoe Intelligence Co., Ltd.

Our company has entered into a business partnership with Konoe Intelligence Co., Ltd. with the aim of strengthening our service provision system in the areas of AI/LLM vulnerability assessment and AI Red Teaming.

Konoe Intelligence is an AI security company with high expertise in AI/LLM vulnerability assessment and AI Red Teaming. Their team was the only Japanese team to place in the Top 20 out of over 5,000 entries in the "Red-Teaming Challenge – OpenAI gpt-oss-20b," an international security competition hosted by OpenAI.

This partnership will combine the company's expertise in AI Red Teaming and AI/LLM vulnerability assessment with our defense and operational knowledge cultivated through web application security, WAF, cloud security, and managed security operations. This will enable us to provide highly effective vulnerability assessment services that take into account not only the risks specific to AI/LLM but also the surrounding web, API, authentication/authorization, and cloud infrastructure. Moving forward, both companies will continue to collaborate to advance services and technologies in the AI security domain.

■ About Konoe Intelligence Co., Ltd.

Konoe Intelligence is an AI security company whose mission is to "reach secure superintelligence as quickly as possible."

To enable companies to securely utilize AI, we provide AI security services and solutions, including AI/LLM vulnerability assessments, AI Red Teaming, shadow AI detection, AI governance visualization, and AI firewalls.

Company Name: Konoe Intelligence Co., Ltd.
Location: Nishijin Industrial Creation Center, 97 Kaimori-cho, Kamigyo-ku, Kyoto City, Kyoto Prefecture
Representative: Keigo Kansa, Representative Director
Established: February 2025
Business activities: AI security business, cybersecurity services
Website:https://www.konoe-intelligence.net/

 

■ Inquiries regarding this service

株式会社サイバーセキュリティクラウド
戦略事業室
TEL:03-6416-9996
Web サイト:https://www.cscloud.co.jp/ai-application-vulnerability-assessment/