
AI LLM01: Prompt Injection - Theory Part 1
AI LLM01: Prompt Injection - Theory Part 2
Prompt Injection in Skills
Indirect Prompt Injection in Grok
ASCII Unicode Prompt Injection into Google Calendar. DoS and Phishing
Indirect Prompt Injection via User Agent ending up in log files
Apple Mail Summary Prompt Injection
ChatGPT Gmail and Calendar Connectors - Prompt Injections and Data Exfil
Manus RCE via prompt injection
Prompt Injection in Document triggers agentic workflow
Prompt injection into Grok with hidden ASCII unicode tags
prompt injection in research papers
Indirect Prompt Injection via documents to create Jira tickets via MCP
Claude Opus 4.6 Prompt Leak
ChatGPT Prompt Leak
Short prompt to leak system prompt
Ultra short prompt to leak prompt
Claude Memory and Prompt Enumeration
Universal Prompt Leak Payload
Claude Code Prompt Leakage
Cluely - system prompt leakage
Claude Opus 4.6 and 4.7 prompt leaks
DeepSeek bias leads to insecure code
Grok 4.1 Jailbreak to generate false documents
Jailbreaking Grok to generate harmful social media images
The Ultimate AI/LLM/ML Penetration Testing Course
Your instructor is Martin Voelk. He is a Cyber Security veteran with 25 years of experience. Martin holds some of the highest certification incl. CISSP, OSCP, OSWP, Portswigger BSCP, CCIE, PCI ISA and PCIP. He works as a consultant for a big tech company and engages in Bug Bounty programs where he found thousands of critical and high vulnerabilities.
This course has a both theory and practical lab sections with a focus on finding and exploiting vulnerabilities in AI and LLM systems and applications. The training is aligned with the OWASP Top 10 LLM as well as the OWASP Top 10 Agentic vulnerability classes. The videos are easy to follow along and replicate.
The course features the following:
· Prompt Injection
· Sensitive Information Disclosure
· Supply Chain
· Data and Model Poisoning
· Improper Output Handling
· Excessive Agency
· System Prompt Leakage
· Vector and Embedding Weaknesses
· Misinformation
· Unbounded Consumption and DoS
· OWASP PwnzzAI Shop
· OWASP Finbot (new)
· OWASP Top 10 for Agentic Applications
· Portswigger - Agentic AI Labs
· Prompt Airlines CTF Challenge Walkthrough
· SecOps Group AI/ML Mock Exams 1 & 2 Walkthrough
· OWASP Finbot CTF (old)
· Selara Jailbreak Game CTF
· Gandalf Agent Breaker CTF
· Hack The Agent CTF
· AI Prompt Attack and Defense Game Tensortrust
· Crowdstrike AI Unlocked Challenge
· Game Arena Challenges
· Other CTFs
· Jailbreaking
· AI Browsers Attacks
· AI Coding Agents Attacks
· MCP Attacks
· Multimodal Attacks (Images, Audio and Video)
· Tooling
Notes & Disclaimer
Portswigger labs are a public and a free service from Portswigger for anyone to use to sharpen their skills. All you need is to sign up for a free account. I will to respond to questions in a reasonable time frame. Learning Pen Testing / Bug Bounty Hunting is a lengthy process, so please don’t feel frustrated if you don’t find a bug right away. Try to use Google, read Hacker One reports and research each feature in-depth. This course is for educational purposes only. This information is not to be used for malicious exploitation and must only be used on targets you have permission to attack.