LLM09:2025: Misinformation
Hallucinations and factual errors produced confidently. Especially dangerous when the model is used as an authoritative oracle (medical, legal, financial advice) without grounding or citations.
How it's found
Identified by evaluating model responses in domains where the target presents the model as authoritative, checking for confident hallucination and fabricated citations.
Standards mapping
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Frequently asked questions
What is LLM09:2025 Misinformation?
Hallucinations and factual errors produced confidently. Especially dangerous when the model is used as an authoritative oracle (medical, legal, financial advice) without grounding or citations.
How do you find Misinformation?
Identified by evaluating model responses in domains where the target presents the model as authoritative, checking for confident hallucination and fabricated citations.
Does TurboPentest test for Misinformation?
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Related OWASP categories
- OWASP Top 10 for LLM ApplicationsLLM01:2025: Prompt Injection
- OWASP Top 10 for LLM ApplicationsLLM02:2025: Sensitive Information Disclosure
- OWASP Top 10 for LLM ApplicationsLLM03:2025: Supply Chain
- OWASP Top 10 for LLM ApplicationsLLM04:2025: Data and Model Poisoning
- OWASP Top 10 for LLM ApplicationsLLM05:2025: Improper Output Handling
- OWASP Top 10 for LLM ApplicationsLLM06:2025: Excessive Agency
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest