Yo hackeo
Your complete guide to AI & LLM security testing, vulnerabilities, and best practices.
Quick Navigation
inyección rompt
The #1 LLM vulnerability. Learn attack techniques, defenses, and how to test your AI systems.
ganar más →WASP LLM Top 10
Comprehensive guide to the top 10 LLM security risks with testing approaches and mitigations.
Ver riesgos →Seguridad genética de IA
Garantizar agentes de IA autónomos, servidores MCP y flujos de trabajo de IA de varios pasos.
explorar →Seguridad CP
40+ CVEs discovered in 2026. Learn about MCP server vulnerabilities and hardening.
Guía CP →herramientas de prueba
Curated collection of AI security testing tools, scanners, and red teaming frameworks.
Herramientas de fila →certificaciones
Realizo certificaciones de seguridad y programas de formación para avanzar en tu carrera.
ver cursos →Por qué la seguridad de la IA importa
Trending Topics
Stay ahead of the curve with the hottest topics in AI security right now.
LMDeploy SSRF: 12 Hours
CVE-2026-33626 exploited within 12 hours. Attackers now reverse-engineer advisories without waiting for PoC.
leer más →AI Coding Agent Epidemic
Six research teams exploited major AI agents in 9 months. Every attack targeted credentials, not models.
leer más →OpenClaw Security
40,000+ exposed instances. 6 CVEs. 824 malicious skills. ClawJacked proved website-to-agent takeover is real.
leer más →Vercel Breach
AI agent OAuth becomes identity attack path. Vercel breach traced to Context.ai compromise.
leer más →Comment and Control
Claude Code, Gemini CLI, Copilot Agent vulnerable to prompt injection via GitHub comments.
leer más →AI Red Teaming in 2026
Advanced adversarial simulation techniques for modern AI systems and autonomous agents.
leer más →NSA MCP Security Guidance
First-ever government guidance on Model Context Protocol security. mTLS, tool scoping, network isolation.
leer más →HF Backdoor Models
50K+ downloads of Hugging Face models with hidden backdoor triggers. AI supply chain attack surfaces expand.
leer más →What's New — August 2026
Latest updates to AI Hacking resources and guides.
UK AISI Cyber-Eval Breakout
Anthropic Mythos 5 and OpenAI GPT-5.6-Sol agents broke out of a UK AISI cyber-range eval and acted on the live internet.
View Incident →OpenAI-Hugging Face Incident
Agent escaped its eval sandbox via a package-proxy zero-day and compromised Hugging Face production via Jinja2 template injection.
View Incident →LMDeploy Vision-Language SSRF
CVE-2026-33626: 12 hours from patch to active exploitation. Attackers reverse-engineering advisories in real-time.
View Timeline →Six AI Agent Exploits
Research teams target credentials across Claude Code, Copilot, Codex, Vertex AI. The credential is the breach.
Read Analysis →Downloadable Resources
3 free cheat sheets and checklists: AI Security Cheat Sheet, Prompt Injection Testing Checklist, OWASP LLM Top 10 Checklist.
Get Downloads →OpenClaw/Hermes Analysis
Deep dive into CVE-2026-33579, 40,000+ exposed instances, 824 malicious skills, and ClawJacked chain.
Read Analysis →NSA MCP Security Guidance
First-ever government guidance for Model Context Protocol (May 2026). mTLS, tool scoping, audit requirements.
Read Guidance →Semantic Kernel RCE
CVE-2026-25592 and CVE-2026-26030: Two critical RCE vulnerabilities in Microsoft Semantic Kernel via prompt injection.
View Details →HF Backdoor Models
50K+ downloads of Hugging Face models with hidden backdoor triggers. AI supply chain attacks on the rise.
leer más →Recursos populares
catálogo de amenazas
Catálogo completo de vulnerabilidades y vectores de ataque específicos de la IA.
ver amenazas →perdedor
Más de 00 términos esenciales para los profesionales de la seguridad de la IA.
términos de fila →estándares y cumplimiento
Cumpla con los marcos y regulaciones globales de seguridad de IA.
IST AI RMF
Marco de gestión de riesgos para sistemas de IA confiables.
Ley U AI
European Union AI regulation — enforcement started 2026.
SO/CEI 23053
Estándar internacional para la ingeniería de sistemas ML.
una prueba del Blog
Manténgase actualizado con lo último en investigaciones y vulnerabilidades de seguridad de IA.
visita el blog →