AI Hacking
Your complete guide to AI & LLM security testing, vulnerabilities, and best practices.
Quick Navigation
Prompt Injection
The #1 LLM vulnerability. Learn attack techniques, defenses, and how to test your AI systems.
Learn More →OWASP LLM Top 10
Comprehensive guide to the top 10 LLM security risks with testing approaches and mitigations.
View Risks →Agentic AI Security
Securing autonomous AI agents, MCP servers, and multi-step AI workflows.
Explore →MCP Security
60+ CVEs discovered in 2026. Learn about MCP server vulnerabilities and hardening.
MCP Guide →Testing Tools
Curated collection of AI security testing tools, scanners, and red teaming frameworks.
Browse Tools →Certifications
AI security certifications and training programs to advance your career.
View Courses →Why AI Security Matters
Trending Topics
Stay ahead of the curve with the hottest topics in AI security right now.
LMDeploy SSRF: 12 Hours
CVE-2026-33626 exploited within 12 hours. Attackers now reverse-engineer advisories without waiting for PoC.
Read more →AI Coding Agent Epidemic
Six research teams exploited major AI agents in 9 months. Every attack targeted credentials, not models.
Read more →OpenClaw Security
40,000+ exposed instances. 6 CVEs. 824 malicious skills. ClawJacked proved website-to-agent takeover is real.
Read more →Vercel Breach
AI agent OAuth becomes identity attack path. Vercel breach traced to Context.ai compromise.
Read more →Comment and Control
Claude Code, Gemini CLI, Copilot Agent vulnerable to prompt injection via GitHub comments.
Read more →AI Red Teaming in 2026
Advanced adversarial simulation techniques for modern AI systems and autonomous agents.
Read more →NSA MCP Security Guidance
First-ever government guidance on Model Context Protocol security. mTLS, tool scoping, network isolation.
Read more →HF Backdoor Models
50K+ downloads of Hugging Face models with hidden backdoor triggers. AI supply chain attack surfaces expand.
Read more →What's New — October 2026
Latest updates to AI Hacking resources and guides.
CVE Database Now Tracks 767 AI Vulnerabilities
Curated from the NVD: 185 MCP-related entries, 107 Critical or High. Searchable, filterable, and sourced.
Browse CVEs →MCP Atlassian Runs Without Verified Identity
CVE-2026-77244 (CVSS 10.0): the HTTP transport accepted unauthenticated requests and fell back to globally configured Jira credentials.
View Incident →Two MCP Servers Shipped Wide Open
MySQL MCP Server and @zereight/mcp-gitlab both rated CVSS 10.0 — SSE transport with no auth, no DNS-rebinding protection, and arbitrary file reads.
Harden Your MCP Server →Clawdbot Skill Supply Chain
Agent skills are an unsigned dependency channel. What the malicious-skill campaigns teach defenders about reviewing agent extensions.
Read Analysis →OWASP LLM Top 10 2026 Mapping
The 2026 release is the active standard. We remapped every risk, test case, and the downloadable checklist to the new numbering.
See the Mapping →LangChain MongoDB Injection
CVE-2026-55253: filter dictionaries went straight into MongoDB queries in both the checkpoint and store integrations.
View Details →Popular Resources
Threats Catalog
Comprehensive catalog of AI-specific vulnerabilities and attack vectors.
View threats →Standards & Compliance
Stay compliant with global AI security frameworks and regulations.
NIST AI RMF
Risk Management Framework for trustworthy AI systems.
EU AI Act
European Union AI regulation — enforcement started 2026.
ISO/IEC 23053
International standard for ML system engineering.
Latest from the Blog
Stay updated with the latest in AI security research and vulnerabilities.
Visit Blog →