Learning paths

AI learning path

18 resources, ordered. Work down the list โ€” each stage assumes the one above it.

AI

A route through the library rather than a dump of it. Items are drawn from the full AI collection, filtered to teaching material (news items are excluded) and ordered within each stage by depth signals โ€” whether the piece carries code, how substantial it is, and what readers actually open.

1

Start here

5 resources

Orientation and first principles โ€” what the bug class is and how it behaves.

  1. GPT-5.5-Cyber built a zlib fuzzing lab in a day
    5 min readblog.trailofbits.com2026
    Library built by GPT-5.5-Cyber for fuzzing zlib; it automatically generated harnesses across numerous entrypoints (including inflate, uncompress2, and MiniZip), configured ASan and UBSan builds, repurposed edge-case tests as seeds, and utilized compile-time variants like INFLATE_STRICT. This autonomous fuzzing campaign, a process that previously took weeks for skilled researchers, was completed in a single day, demonstrating a significant shift in vulnerability discovery capabilities.
  2. [tl;dr sec] #345 - Bug Rumors โ†’ Exploits, Version Control DFIR, Agentic Worms
    8 min readtldrsec.com2026
    Analysis details how AI models struggle to review their own code, often missing bugs they introduce, and explores the diminishing effectiveness of traditional vulnerability disclosure timelines. A cheat sheet for version control digital forensics and incident response (DFIR) across GitHub, GitLab, Bitbucket, and Azure DevOps is provided, highlighting visibility gaps and configuration needs. The entry also discusses the challenge of false positives in security tools when benign traffic mimics attack patterns, and mentions a paper on self-replicating agentic worms.
  3. Generative AI Security: Are Your Developers Pasting Secrets Into LLMs?
    8 min readblog.gitguardian.com2026
    Library for integrating GitGuardian's secrets detection into internal AI gateways. It scans prompts and tool calls in-memory via a Custom Source UUID before they reach third-party LLM providers, offering both non-blocking (for measurement) and blocking modes. This solution addresses the 81% jump in AI-service leaks detected by GitGuardian, catching incidents that never touch code repositories.
  4. The Infostealer Incursion: How Stolen Credentials Breach Cloud, Code, and AI Environments
    14 min readwiz.io2026
    Library analyzing infostealer malware families like Lumma, RedLine, and Vidar reveals their significant impact on cloud, code, and AI environments. These tools, often delivered via Malware-as-a-Service, harvest credentials, API keys, and active session tokens from developer endpoints. Stolen secrets provide attackers with initial access to AWS, Azure, GCP, GitHub, and AI platforms like OpenAI, bypassing multi-factor authentication through session hijacking and granting access to sensitive data and computational resources.
  5. AI Coding Agents Are Leaking Credentials: Cursor, Claude Code, Copilot, and MCP
    7 min readblog.gitguardian.com2026
    Library for detecting leaked credentials from AI coding agents like Cursor, Claude Code, and GitHub Copilot. These agents can inadvertently store sensitive information in configuration files, environment variables, logs, and shell history, bypassing traditional repository and CI scanning. The library addresses this by discovering these hidden credential trails across endpoints using local agent inventory, machine scanning, AI hooks, and honeytokens to enable prompt remediation before compromise.
2

Build depth

5 resources

Real testing methodology, tooling, and writeups that show the work.

  1. Practical LLM Security Advice from the NVIDIA AI Red Team
    5 min readdeveloper.nvidia.com2026
    Library summarizing NVIDIA AI Red Team findings, detailing common LLM application vulnerabilities. It addresses risks like remote code execution (RCE) from executing LLM-generated code (e.g., via `exec` or `eval`), insecure permissions in Retrieval-Augmented Generation (RAG) data stores leading to data leakage and prompt injection, and data exfiltration through active content rendering of Markdown or hyperlinks. Mitigation strategies include sandboxing dynamic code, rigorously managing RAG permissions, and sanitizing LLM output.
  2. [tl;dr sec] #333 - Perplexity's Bumblebee, Evading Cloud Logging, AI Vuln Hunting Spec
    12 min readtldrsec.com2026
    Library for detecting malware in packages, agent configurations, and browser extensions, alongside techniques for evading cloud logging, and a specification for building custom AI security scanning systems. It details how formal methods are becoming more practical for AI-generated code, and how Microsoft's Agentic Secret Finder reduced false positives in GitHub's AI secret scanning by 75% through context extraction. The entry also covers the discovery of HTTP/2 Bomb, a DoS vulnerability affecting multiple web servers, and methods for disrupting AWS CloudTrail logging and abusing cloud logging services for defense evasion and visibility.
  3. Leaking Secrets in the Age of AI
    8 min readwiz.io2026
    Library for identifying AI-related secret leakage in public code repositories. The analysis found that `.ipynb` notebook files and configuration files like `mcp.json` and `.env` are particularly prone to exposing secrets from emerging AI vendors, impacting numerous companies. This research highlights critical gaps in current secrets scanning tools and practices, especially concerning the handling of AI development artifacts.
  4. Detecting AI-specific threats in Claude Enterprise from the Compliance API: a prefilter + LLM-as-judge pipeline with Sigma rules
    11 min readpapermtn.co.uk2026
    Library for detecting AI-specific threats within Claude Enterprise, leveraging the Compliance API through a prefilter and LLM-as-judge pipeline with Sigma rules. It focuses on detecting indirect prompt injection via ingested content, jailbreaks, system prompt extraction, exfiltration preparation, and sensitive output disclosure, differentiating these threats from standard SaaS security concerns by analyzing conversation content rather than just perimeter events.
  5. Would You Click โ€˜Acceptโ€™? Automatically detecting malicious Azure OAuth applications using LLMs
    11 min readwiz.io2026
    Tool for detecting malicious Azure OAuth applications, leveraging insights from homoglyph attacks and analysis of real-world campaigns. This pipeline identifies suspicious applications by comparing their characteristics against a baseline of legitimate integrations, flagging deviations in publisher verification, homepage URLs, and application owner domains. The research highlights common gaps in Azure service principal management and the risk of consent fatigue, leading to potential privilege escalation and persistent access for attackers.
3

Go deep

8 resources

Novel research, edge cases, and the techniques that push the class forward.

  1. Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis
    30 min readarxiv.org2026
    Analysis of prompt injection vulnerabilities affecting agentic AI coding assistants like Claude Code, GitHub Copilot, and Cursor, which integrate LLMs with external tools and protocols such as MCP. This work synthesizes findings from 78 studies, detailing 42 attack techniques including input manipulation, tool poisoning, and protocol exploitation. It identifies that over 85% of attacks succeed against current defenses, often enabling arbitrary code execution and system compromise through vulnerabilities in skill-based architectures and protocol ecosystems.
  2. Prompt Injection 2.0: Hybrid AI Threats
    20 min readarxiv.org2026
    Library for analyzing Prompt Injection 2.0, which combines LLM manipulation with traditional exploits like XSS and CSRF. It builds upon Preamble's research and mitigation technologies, evaluating them against contemporary threats such as AI worms and multi-agent infections. The library analyzes how these hybrid attacks bypass security controls, referencing CVE-2024-5565 and DeepSeek XSS exploits, and proposes architectural solutions involving prompt isolation and runtime security.
  3. s1ngularity's Aftermath: AI, TTPs, and Impact in the Nx Supply Chain Attack
    9 min readwiz.io2026
    Analysis of the s1ngularity Nx supply chain attack details novel TTPs used by AI-powered malware to exfiltrate secrets, including GitHub and npm tokens. The attack progressed through three phases: initial public leakage of thousands of corporate secrets, abuse of leaked GitHub tokens to expose private repositories, and a final phase publishing more repositories. The malware leveraged AI CLIs like Claude and Gemini to identify and exfiltrate sensitive files, impacting over 1,700 users with public secret leakage and hundreds more through the exposure of private repositories.
  4. EchoLeak: First Real-World Zero-Click Prompt Injection Exploit
    21 min readarxiv.org2026
    Writeup of EchoLeak (CVE-2025-32711), the first zero-click prompt injection exploit targeting Microsoft 365 Copilot. This vulnerability allowed unauthenticated data exfiltration via a crafted email by chaining multiple bypasses, including evading XPIA classifiers, using reference-style Markdown, exploiting auto-fetched images, and abusing a Microsoft Teams proxy within the content security policy. The paper analyzes defense failures and proposes mitigations such as prompt partitioning and enhanced filtering, providing generalizable lessons for secure AI copilots.
  5. Building an Open-Source AI-Powered Auto-Exploiter with a 1.7B Parameter Model: No Paid APIs Required
    13 min readmohitdabas.in2025
    Library for building an open-source, AI-powered autonomous penetration testing agent. This system utilizes a 1.7 billion parameter qwen3:1.7b model, LangChain, and LangGraph for local execution, eliminating API costs and data exfiltration. It functions as a ReAct agent, independently scanning networks with Nmap, searching for exploits using searchsploit, mirroring them, analyzing code with `inspect_exploit_code`, setting up listeners with `start_listener`, and executing commands via `execute_shell_command` to achieve autonomous exploitation.
  6. Microsoft Copilot: From Prompt Injection to Exfiltration of Personal Information ยท Embrace The Red
    6 min readembracethered.com2024
    Writeup detailing a Microsoft 365 Copilot vulnerability where prompt injection, automatic tool invocation, and ASCII smuggling were combined to exfiltrate personal information. The exploit chain leveraged malicious emails or shared documents to trigger Copilot's processing, enabling it to access and send sensitive data like emails and MFA codes to attacker-controlled domains via disguised hyperlinks.
  7. Frame: Grounding LLM Vulnerability Detection with a Sound Separation-Logic Core
    13 min readlambdasec.github.io2026
    Library for neuro-symbolic static application security testing (SAST). Frame integrates a sound symbolic analysis engine with a large language model (LLM) for enhanced vulnerability detection. The symbolic core performs taint analysis and separation-logic verification using Z3, while the LLM identifies vulnerabilities missed by the core, including cross-file flows. LLM findings are then grounded and verified against the symbolic engine's sink model, with tiered confidence levels assigned. This approach aims to improve both recall and precision compared to traditional SAST tools like Semgrep OSS, addressing vulnerabilities like CWE-352 (Cross-Site Request Forgery) and prototype pollution.
  8. Off Guard: Breaking LiteLLM from authentication bypass to cloud compromise
    12 min readwiz.io2026
    Library that exploits authentication bypasses in LiteLLM, including CVE-2026-59822 which allows unauthenticated access to MCP sessions via arbitrary Bearer tokens. It also details how default master keys or no authentication enable pre-authentication RCE, and how unauthenticated admin access is possible. Post-authentication credential theft is achievable via the pass-through endpoint feature.