AI Security · 2026
The AI Hacker's Handbook | Kapil Soni
Finding, Exploiting, and Reporting Vulnerabilities in LLMs and AI Agents
The AI Hacker's Handbook turns real engagement experience into a practical playbook for the newest attack surface in security: large language models and the agents built on top of them. It walks through prompt injection, retrieval-augmented generation (RAG) attacks, tool and agent abuse, data exfiltration, and full LLM red teaming, each with concrete techniques you can run yourself and a clear path from finding to a report that gets paid. Written by a bug bounty hunter who has reported flaws to more than 250 organizations, it is built for people who want to break systems, not just read about them.
What you'll learn
- How prompt injection works and how to weaponize it against real deployments
- Attacking RAG pipelines: poisoning, retrieval abuse, and context leakage
- Exploiting AI agents and their tools: SSRF, code execution, and privilege abuse
- Data exfiltration and sensitive-information disclosure from LLM apps
- Building a repeatable LLM red-team methodology
- Writing vulnerability reports that triage cleanly and earn bounties
Who it's for
Penetration testers, bug bounty hunters, red teamers, and AI/ML engineers who need to secure or attack LLM-powered systems.