Free AI Hacking Course: Indirect Prompt Injection (+FREE LABS)
Indirect prompt injection exploits AI agents by embedding malicious payloads in external content like emails, PDFs, or code repositories, causing the victim's own system to execute unauthorized actions. This technique bypasses standard input and output guardrails through advanced framing, obfuscation, and encoding strategies, enabling data exfiltration such as stealing password reset tokens. A demonstrated lab recreates a vulnerability that previously yielded a $3,000 bug bounty, progressing from open environments to systems with active defenses. The method targets the growing integration of AI agents into corporate email, calendar, and development tools, creating a critical security gap for external attackers.
Are you ready for this year's @BugBountyVillage at @DEFCONConference
The Bug Bounty Village at DEFCON Conference hosts a three-day event from Friday through Sunday featuring talks by speakers including Inti, Ads, Mike, and Katie. The schedule includes a Thursday Hacker Hangout hosted by TikTok, followed by a Capture The Flag competition offering significant prizes and extensive giveaways over 72 hours. Attendees can access the full agenda, party details, and last year's program through provided links to engage with the community of web hackers and bug bounty hunters.