Attacking the model
Injection, jailbreaks, obfuscation, token smuggling.
Attack-first. Hands-on. Reproducible.
Finding, Exploiting, and Reporting Vulnerabilities in LLMs and AI Agents
The AI bugs companies pay the most for are mostly the classes you already hunt, reached through a new door.
By Kapil Soni, who has reported flaws to 250+ organizations including Apple, Cisco, Amazon, AT&T, Mastercard, and the U.S. Government.
The gap
Every product is bolting on a chatbot, a copilot, an agent, and shipping faster than anyone can secure it.
They're mostly the classes you already hunt, IDOR XSS SSRF RCE, reached through a new door: a model that follows instructions in whatever text it reads.
No ML theory you'll never use. Here's the lab, here's the payload, run it, watch it work.
Free chapter
Chapter 4, First Blood: five real exploits with copy-ready payloads and named legal targets. See the method before you buy.
What's inside
From the model itself out to the autonomous agent, then how to defend it all and get paid for what you find.
Injection, jailbreaks, obfuscation, token smuggling.
System-prompt theft, RAG poisoning, exfiltration, model theft.
Poisoned dependencies, model provenance, cost-exhaustion attacks.
Tool-call abuse, MCP, multi-agent, memory poisoning.
The new high-value attack surface hiding in developer tooling.
Harness, fuzzing at scale, CI/CD-driven testing.
Mitigations that hold, plus reporting and bounty strategy.
Attack the door,
then the room
behind it.
36 chapters · 7 appendices · 79 figures · a payload library you'll actually use.
Reproducible
Here's the lab, here's the payload, run it, change one thing, watch it work. Every exploit runs against a named, legal target.
Living updates
The print book links here for anything volatile, so the numbers stay right without a reprint. Updated with a single commit.
Loading…
Loading…
Loading…
Who & who by
Kapil Soni is a security researcher who has reported vulnerabilities to 250+ organizations, from Apple and Cisco to the U.S. Government. He builds offensive-security tooling and trains hunters to find the bugs that matter.
Get the book
The AI bugs companies pay the most for are mostly the classes you already hunt, reached through a new door.
Your skills didn't just stay relevant. They got more valuable. Time to collect.
ISBN 978-93-6038-679-5