🚀 Join our AI Wargame at Black Hat Asia and our Workshop + Wargame at NDC Sydney .


Stay Safe with AI: A Developer's Guide - SecDim Learn

27/05/2026

AI tools are now part of the normal developer workflow — code assistants, chat interfaces, MCP servers, autonomous agents, and IDE integrations.

They also introduce new security risks that affect developers directly, not just the applications being built.

Repository content can manipulate LLM behavior through prompt injection. Sensitive internal information can leak through prompts and context windows. Hallucinated package names can be weaponized for supply chain attacks. Malicious MCP servers can expose local data and development environments. Attackers are also increasingly adapting phishing and social engineering techniques specifically around AI-assisted workflows.

We released Stay Safe with AI: A Developer’s Guide on SecDim Learn to help developers understand how these attacks work in practice.

The course is designed for developers and technical users without requiring a security background. It focuses on realistic attack paths, practical examples, and hands-on demonstrations rather than abstract AI safety discussions.

Topics covered include:

  • How large language models work

  • Adversarial inputs and FGSM attack fundamentals

  • AI code assistant security risks

  • Prompt injection against developers

  • Sensitive data leakage through AI tooling

  • Risks in AI-generated code

  • Slopsquatting and hallucinated dependency attacks

  • MCP server security

  • AI-enhanced social engineering targeting developers

The course also includes practical labs demonstrating how several of these attacks work in real environments.

If you regularly use AI tools during development, understanding these failure modes is becoming part of basic operational security.

:backhand_index_pointing_right: Check it out on SecDim Learn: Learn - SecDim

Deco line
Deco line

Play AppSec WarGames

Want to skill-up in secure coding and AppSec? Try SecDim Wargames to learn how to find, hack and fix security vulnerabilities inspired by real-world incidents.

Deco line
Deco line

Got a comment?

Join our secure coding and AppSec community. A discussion board to share and discuss all aspects of secure programming, AppSec, DevSecOps, fuzzing, cloudsec, AIsec code review, and more.

Read more