One Bad OSINT Can Ruin Everything: How Secure is Your CTI RAG System, and Can You Minimize the Risk? @FIRSTdotorg
One Bad OSINT Can Ruin Everything: How Secure is Your CTI RAG System, and Can You Minimize the Risk?  @FIRSTdotorg
Uploaded June 2026 | Updated September 2026, 33 minutes ago
Sian-Yao Huang (CyCraft Technology, TW), Yen-Shan Chen (CyCraft Technology, TW)

The widespread adoption of LLM and RAG systems to analyze Cyber Threat Intelligence has created a critical and largely unexamined attack surface. What happens when the data you feed your AI is deliberately poisoned? This talk demonstrates how a single malicious OSINT report can be weaponized to compromise an entire CTI RAG pipeline. We will present a live end to end attack that uses a hidden trigger to hijack both the retrieval and generation stages, forcing the system to produce fabricated answers under the attacker's control, even when facing unknown models.

This session moves beyond theory to demonstrate the practical fragility of these systems. Attendees will witness the attack firsthand and, more importantly, will learn actionable, low-cost mitigation strategies to defend their own CTI platforms from this emerging threat.

This presentation's authors include Yen-Shan (Lily) Chen, Sian-Yao Huang, and Cheng-Ling.

---

Sian-Yao Huang, the technical lead at CyCraft Technology, specializes in creating advanced deep learning models to tackle cybersecurity challenges such as anomaly detection and security analysis. His work has been featured at major conferences like NeurIPS, EMNLP, IJCNN, and CVPR, and he's presented at Black Hat USA, Code Blue Japan, SINCON and SECCON.

Yen-Shan (Lily) Chen is a data scientist at CyCraft Technology, where she currently focuses on research into potential vulnerabilities in Retrieval-Augmented Generation (RAG) frameworks and developing methods to evaluate them. Lily has previously presented at major cybersecurity conferences such as Code Blue Japan and SINCON, and she also published her work at the renowned ACL conference.
One Bad OSINT Can Ruin Everything: How Secure is Your CTI RAG System, and Can You Minimize the Risk?Improving Security Across Nations with FIRST: Sametria McKinney, FIRST MemberClimbing Toward the Summit of Defense: Practical Methods for Strengthening CSIRT OrganizationsMonday Keynote: Perseverance, Growth and Success. The Sunburst Story from the CISO perspective.Evaluating Threat Intelligence Through VelocitySaving Ourselves the ID Headache: How Purls Can Work for Models and DatasetsImproving Security Across Nations with FIRST: Sneha Rangari, FIRSTCON26 SpeakerNational CSIRT as a CVD Hub: Lessons from CERT.PL’s Vulnerability Coordination CasesFrom Roadmap to Results: Measuring CWE Adoption to Enable PreventionFiltering the Noise: Crafting an Actionable Threat Feed from Community-Shared IntelligenceThe Convergence of Threat Behaviors Across IntrusionsForecasting Cybersecurity Data: Making Sense of the Senseless
FIRST |

One Bad OSINT Can Ruin Everything: How Secure is Your CTI RAG System, and Can You Minimize the Risk?

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER