
Sign up to save your podcasts
Or


We have talked about how to hack an AI. Now, let’s talk about when the AI becomes the hacker. Welcome to Domain 3: AI-Assisted Security. In this video (Objective 3.2), we switch to the Red Team.
We are breaking down exactly how attackers weaponize LLMs to scale social engineering, clone voices for "Vishing," and generate polymorphic malware that evades traditional antivirus.
In this video, we cover:
Identity Attacks: Deepfakes, Impersonation, and Social Engineering at Scale.
Infrastructure Attacks: Automated Reconnaissance, Attack Vector Discovery, and AI-Enhanced DDoS.
Payloads: Polymorphic Code, Obfuscation, and Adversarial Malware Generation.
Hardware: Why GPUs are required for Password Cracking (PassGAN).
Timecodes:
0:00 - Intro: The AI Offensive (Domain 3)
0:42 - Social Engineering & Personalized Phishing
1:05 - Voice Cloning & Vishing (The 3-Second Rule)
1:38 - Automated Recon & Attack Vector Discovery
2:05 - AI-Enhanced DDoS (Traffic Shaping)
2:28 - Writing Malware & Polymorphic Code (Obfuscation)
3:05 - Hardware: GPUs & Password Cracking (PassGAN)
3:35 - What’s Next: The Blue Team (Video 11)
📚 Resources & Support
🎓 FREE Interactive Learning Tools
Don't just watch—practice. Access our new browser-based tools to test your skills live.
AI-Powered Exam Simulators: https://secguy.org/exam-simulators
Python for Security Labs: https://secguy.org/python-practice
Mock Interview Board: https://secguy.org/mock-interview
💬 Join the Squad
Connect with other industry veterans and students in our new dedicated study group.
Official Discord: https://secguy.org/discord-chat
📚 Download Course Materials
Get the SecAI+ Cheat Sheet (including the MCP Architecture Diagram & Jetson specs) and full course slides directly from the academy.
Access Here: https://secguy.org/courses
Next Video: Domain 3.1: The AI Analyst (Blue Team Defense)
#SecAI #CompTIA #Cybersecurity #RedTeam #Deepfakes #Malware #EthicalHacking #PassGAN #AIsecurity
Port 443 is always open, traffic is encrypted, and the attack looks like valid English. You cannot fix AI security with a traditional firewall.
In this episode of the SecAI+ Course, we enter Domain 3: Blue Team Operations. We are building the "AI Shield"—the new defense stack required to protect Large Language Models from injection, sponge attacks, and data leakage.
🔥 Topics Covered:
* Input Validation: Prompt Firewalls & Sanitization (NVIDIA NeMo, LangChain)
* Rate Limiting: Defending against Sponge Attacks
* Output Filtering: Preventing Data Leakage & Insecure Code
* C2PA: The new standard for Content Provenance & Authenticity
* Modern SIEM/SOAR: Using UEBA to detect anomalies
* Federated Learning: Training models without moving private data
🎓 Pass the Exam:
📚 Resources & Support
🎓 FREE Interactive Learning Tools
Don't just watch—practice. Access our new browser-based tools to test your skills live.
AI-Powered Exam Simulators: https://secguy.org/exam-simulators
Python for Security Labs: https://secguy.org/python-practice
Mock Interview Board: https://secguy.org/mock-interview
💬 Join the Squad
Connect with other industry veterans and students in our new dedicated study group.
Official Discord: https://secguy.org/discord-chat
📚 Download Course Materials
Get the SecAI+ Cheat Sheet (including the MCP Architecture Diagram & Jetson specs) and full course slides directly from the academy.
Access Here: https://secguy.org/courses
#CompTIA #SecAI #Cybersecurity #BlueTeam #AIsecurity #C2PA #SecGuy
Master Prompt Injection & Jailbreaking for the CompTIA SecAI+ (Domain 2). In this lesson, we break down the most dangerous (and fun) part of AI Security: Input Attacks.
Your firewall stops traffic. It does not stop words. 🛡️🚫
OWASP LLM 1, 3, 5, 10 are covered previous video link here: https://youtu.be/d4zx2amlnvU
In Part 2 of our Domain 2 Deep Dive, we cover the "Context Mixing" flaw that makes all LLMs vulnerable. We explain how attackers use Prompt Injection to turn helpful chatbots into "Confused Deputies" that attack their own users.
We break down the critical difference between standard Jailbreaking (Roleplaying/DAN) and the mathematical magic of Universal Adversarial Triggers (UATs). But the scariest attack isn't when you talk to the AI—it's when the AI reads a file you didn't check. We demonstrate Indirect Prompt Injection and how a simple resume PDF can hack your recruiting bot.
🎓 What You Will Learn:
🧠 Context Mixing: Why LLMs fundamentally cannot distinguish between "Safe Data" and "Malicious Instructions."
🔓 Jailbreaking Types: The difference between "DAN" (Roleplaying) and "Logical Bypasses" (Translation exploits).
🔢 Universal Adversarial Triggers (UATs): The "magic words" (nonsense strings) that break models mathematically using Gradient Ascent.
🕵️♂️ Indirect Prompt Injection: The invisible attack inside PDFs and websites (Zero-Click exploits).
📦 Token Smuggling: Using Payload Splitting to sneak malware concepts past the WAF.
💸 Wallet Exhaustion: How Recursive Loops drain your bank account (Denial of Wallet).
📚 Resources & Support
🎓 FREE Interactive Learning Tools
Don't just watch—practice. Access our new browser-based tools to test your skills live.
AI-Powered Exam Simulators: https://secguy.org/exam-simulators
Python for Security Labs: https://secguy.org/python-practice
Mock Interview Board: https://secguy.org/mock-interview
💬 Join the Squad
Connect with other industry veterans and students in our new dedicated study group.
Official Discord: https://secguy.org/discord-chat
📚 Download Course Materials
Get the SecAI+ Cheat Sheet (including the MCP Architecture Diagram & Jetson specs) and full course slides directly from the academy.
Access Here: https://secguy.org/courses
⏳ Timestamps:
00:00 - The "Context Mixing" Flaw
01:05 - Context Switching & The System Prompt
01:45 - Type 1 & 2: Roleplaying (DAN) & Logical Bypasses
02:40 - Type 3: Universal Adversarial Triggers (UATs)
03:30 - Indirect Prompt Injection (The Resume Hack)
04:55 - Token Smuggling & Payload Splitting
05:35 - Wallet Exhaustion & Recursive Loops
06:25 - Homework: Glitch Tokens
#SecAIplus #CompTIA #PromptInjection #Jailbreak #RedTeam #AIsecurity #EthicalHa
I don't need to break into your server to steal your AI. I just need to ask it the right questions. In Part 3 of our Domain 2 Deep Dive, we leave the "Prompt Injection" attacks behind and enter the world of Privacy Attacks and Model Theft.
We explain how attackers can use Model Inversion to reconstruct private training data (like faces) just by analyzing confidence scores. We break down the difference between Membership Inference (knowing if you were a patient) and Attribute Inference (knowing what disease you have).
Finally, we cover Model Extraction (cloning GPT-4 for cheap) and the silent killer known as Data Poisoning—where attackers install "Backdoors" into the model before it's even trained.
🎓 In this video, you will learn:
Model Inversion: Reconstructing training data (faces/PII) from vector outputs.
Membership Inference vs. Attribute Inference: The subtle difference between exposing a user and exposing their secrets.
Model Stealing (Distillation): How "Student" models cheat off "Teacher" models to steal IP.
Adversarial Reprogramming: Hijacking a medical AI to mine cryptocurrency.
Data Poisoning: Split-View attacks and installing "Backdoors" (The Sticky Note hack).
Sponge Examples: Attacks designed to burn energy and overheat hardware.
⏱️ Timestamps: 00:00 Intro: The "Heist" Concept 01:05 Model Inversion (Reconstructing Faces) 01:55 Membership Inference vs. Attribute Inference 02:45 Model Stealing (Distillation Attacks) 03:15 Adversarial Reprogramming (Hijacking Compute) 03:40 Data Poisoning & Split-View Attacks 04:30 How to Stop It (Teaser) 04:45 Support the Channel (Buy Me a Coffee) 05:05 Homework: Sponge Examples
📚 Resources & Support
🎓 FREE Interactive Learning Tools
Don't just watch—practice. Access our new browser-based tools to test your skills live.
AI-Powered Exam Simulators: https://secguy.org/exam-simulators
Python for Security Labs: https://secguy.org/python-practice
Mock Interview Board: https://secguy.org/mock-interview
💬 Join the Squad
Connect with other industry veterans and students in our new dedicated study group.
Official Discord: https://secguy.org/discord-chat
📚 Download Course Materials
Get the SecAI+ Cheat Sheet (including the MCP Architecture Diagram & Jetson specs) and full course slides directly from the academy.
Access Here: https://secguy.org/courses
#SecAIplus #CompTIA #ModelInversion #DataPoisoning #AIsecurity #RedTeam #Cybersecurity #EthicalHacking #SecGuy
Your firewall stops traffic. It does not stop words. In Part 2 of our Domain 2 Deep Dive, we cover the most dangerous (and fun) part of AI Security: Input Attacks.
We explain how attackers use "Prompt Injection" to turn helpful chatbots into "Confused Deputies" that attack their own users. We break down the difference between Jailbreaking (Roleplaying/DAN) and the mathematical magic of Universal Adversarial Triggers (UATs).
But the scariest attack isn't when you talk to the AI—it's when the AI reads a file you didn't check. We demonstrate Indirect Prompt Injection and how a simple resume PDF can hack your recruiting bot.
🎓 In this video, you will learn:
Context Mixing: Why LLMs cannot distinguish between "Data" and "Instructions."
Jailbreaking: "DAN" (Roleplaying) vs. "Logical Bypasses" (Translation exploits).
Universal Adversarial Triggers (UATs): The "magic words" (nonsense strings) that break models mathematically using Gradient Ascent.
Indirect Prompt Injection: The invisible attack inside PDFs and websites (Zero-Click exploits).
Token Smuggling: Using Payload Splitting to sneak malware concepts past the WAF.
Wallet Exhaustion: How Recursive Loops drain your bank account (Denial of Wallet).
⏱️ Timestamps:
00:00 The "Context Mixing" Flaw
01:05 Context Switching & The System Prompt
01:45 Type 1 & 2: Roleplaying (DAN) & Logical Bypasses
02:40 Type 3: Universal Adversarial Triggers (UATs)
03:30 Indirect Prompt Injection (The Resume Hack)
04:55 Token Smuggling & Payload Splitting
05:35 Wallet Exhaustion & Recursive Loops
06:25 Homework: Glitch Tokens
📚 Resources & Support
🎓 FREE Interactive Learning Tools
Don't just watch—practice. Access our new browser-based tools to test your skills live.
AI-Powered Exam Simulators: https://secguy.org/exam-simulators
Python for Security Labs: https://secguy.org/python-practice
Mock Interview Board: https://secguy.org/mock-interview
💬 Join the Squad
Connect with other industry veterans and students in our new dedicated study group.
Official Discord: https://secguy.org/discord-chat
📚 Download Course Materials
Get the SecAI+ Cheat Sheet (including the MCP Architecture Diagram & Jetson specs) and full course slides directly from the academy.
Access Here: https://secguy.org/courses
#SecAIplus #CompTIA #PromptInjection #Jailbreak #RedTeam #AIsecurity #EthicalHacking #UAT #SecGuy
SQL Injection won't save you when the database is a Vector Store. Welcome to Domain 2 of the CompTIA SecAI+ course. This domain makes up 40% of the entire exam, making it the most critical section to master.
In this video, we map the new battlefield. We explain why traditional frameworks like MITRE ATT&CK fail against AI, and introduce the new standard: MITRE ATLAS. We also break down the OWASP LLM Top 10, the risks of downloading models from Hugging Face, and how to apply STRIDE threat modeling to Neural Networks.
🎓 In this video, you will learn:
MITRE ATLAS vs. ATT&CK: The difference between "Initial Access" and "ML Model Access."
OWASP LLM Top 10: An intro to Prompt Injection, Insecure Output Handling, and Data Poisoning.
New Risk Frameworks: The MIT AI Risk Repository and the CVE AI Working Group.
Supply Chain Security: Why "Pickle" files (.pkl) are dangerous and how Hugging Face is the new attack surface.
AI Threat Modeling: Mapping STRIDE to AI concepts (e.g., Tampering = Training Data Poisoning).
⏱️ Timestamps: 00:00 Intro: Why Web Security Fails in AI 01:00 MITRE ATLAS vs. MITRE ATT&CK (Exam Critical) 02:00 The MIT AI Risk Repository & CVEs 02:30 The OWASP LLM Top 10 03:20 Supply Chain Risk: Hugging Face & Pickle Files 04:05 Threat Modeling: STRIDE for AI 04:40 Homework Assignment
📚 Resources & Support
🎓 FREE Interactive Learning Tools
Don't just watch—practice. Access our new browser-based tools to test your skills live.
AI-Powered Exam Simulators: https://secguy.org/exam-simulators
Python for Security Labs: https://secguy.org/python-practice
Mock Interview Board: https://secguy.org/mock-interview
💬 Join the Squad
Connect with other industry veterans and students in our new dedicated study group.
Official Discord: https://secguy.org/discord-chat
📚 Download Course Materials
Get the SecAI+ Cheat Sheet (including the MCP Architecture Diagram & Jetson specs) and full course slides directly from the academy.
Access Here: https://secguy.org/courses
#SecAIplus #CompTIA #Cybersecurity #MITREATLAS #OWASP #LLMSecurity #AIProtection #SecGuy #TechEducation
AI models aren't born smart. We teach them. And that is where the security risk begins.
In the Finale of Domain 1 for the CompTIA SecAI+, we cover the entire AI Lifecycle. Most organizations do not build models from scratch—they download them and "Fine-Tune" them. This video breaks down the massive Supply Chain risks involved in Transfer Learning and how attackers can poison the process before you even write your first prompt.
We also tackle the most critical exam concepts for Model Evaluation. You cannot pass this exam without understanding the Confusion Matrix (True Positives vs. False Negatives), Model Drift, and the difference between Training vs. Inference.
🎓 In this video, you will learn:
Training vs. Inference: Where the cost is vs. where the attack happens.
Transfer Learning: The "College Grad" analogy for pre-trained models.
RLHF: How human feedback creates the "guardrails" (and how jailbreaks bypass them).
Model Metrics: Confusion Matrix, Precision, Recall, and the danger of False Negatives.
Drift: Why your security AI gets dumber over time (Data Drift vs. Concept Drift).
Hallucinations: How to use the Temperature setting to stop AI lies.
⏱️ Timestamps: 00:00 Training vs. Inference (Exam Tip) 01:05 Transfer Learning & Supply Chain Risk 02:15 RLHF (Reinforcement Learning from Human Feedback) 03:00 The Scorecard: Confusion Matrix & Accuracy 03:35 Data Drift & Concept Drift 04:05 Hallucinations & Temperature Control 04:50 The Black Box Problem 05:15 Store & Podcast Shoutout 05:35 Domain 1 Recap & What's Next (Attacks)
📚 Resources & Support
🎓 FREE Interactive Learning Tools
Don't just watch—practice. Access our new browser-based tools to test your skills live.
AI-Powered Exam Simulators: https://secguy.org/exam-simulators
Python for Security Labs: https://secguy.org/python-practice
Mock Interview Board: https://secguy.org/mock-interview
💬 Join the Squad
Connect with other industry veterans and students in our new dedicated study group.
Official Discord: https://secguy.org/discord-chat
📚 Download Course Materials
Get the SecAI+ Cheat Sheet (including the MCP Architecture Diagram & Jetson specs) and full course slides directly from the academy.
Access Here: https://secguy.org/courses
#SecAIplus #CompTIA #AIsecurity #FineTuning #RLHF #MachineLearning #Cybersecurity #SecGuy #ModelDrift #Hallucinations
Computers don't speak English. They speak Math. In Part 2 of our CompTIA SecAI+ Deep Dive, we break down the "Data Pipeline." If you want to secure an AI model, you first need to understand how it translates chaotic human language into structured mathematical vectors.
This video covers the most abstract (and critical) technical concepts in Domain 1. We explain exactly how Tokenization works, the magic of Embeddings (King - Man + Woman = Queen), and why Vector Databases are the backbone of modern RAG systems.
We also cover critical exam topics like Context Window Overflows and the difference between Zero-Shot and Few-Shot prompting.
🎓 In this video, you will learn:
Tokenization: Why 1,000 tokens ≈ 750 words, and why this limit matters for security.
Embeddings: How AI maps words in a 3D space to understand meaning.
Vector Databases: The difference between SQL and Semantic Search (RAG).
Context Window: How attackers use "Short-Term Memory" limits to crash models (DoS).
Prompt Engineering: The security implications of Zero-Shot vs. Few-Shot prompting.
⏱️ Timestamps:
00:00 Intro: The Math Problem
01:15 Tokenization & The 75% Rule
02:00 Embeddings & The "King - Man" Formula
03:10 Vector Databases & Semantic Search (RAG)
04:10 The Context Window & DoS Risks
04:35 Exam Tip: Zero-Shot vs Few-Shot Prompting
05:00 Support the Channel (Store & Podcast)
05:20 What's Next (Domain 1.3: Fine-Tuning)
📚 Resources & Support
🎓 FREE Interactive Learning Tools
Don't just watch—practice. Access our new browser-based tools to test your skills live.
AI-Powered Exam Simulators: https://secguy.org/exam-simulators
Python for Security Labs: https://secguy.org/python-practice
Mock Interview Board: https://secguy.org/mock-interview
💬 Join the Squad
Connect with other industry veterans and students in our new dedicated study group.
Official Discord: https://secguy.org/discord-chat
📚 Download Course Materials
Get the SecAI+ Cheat Sheet (including the MCP Architecture Diagram & Jetson specs) and full course slides directly from the academy.
Access Here: https://secguy.org/courses
#SecAIplus #CompTIA #Cybersecurity #AIsecurity #VectorDatabase #RAG #SecGuy #PromptEngineering
Welcome back to the Sec Guy Channel – your go-to resource for IT and cybersecurity certifications!
🛡️ In this video, we’re doing a deep dive into the BIG changes CompTIA is rolling out in 2026, including:
✅ The brand-new Xpert Series certifications
✅ Crossover certs like SecAI+ for AI-driven security
✅ Updates to A+, Network+, and Security+ that reflect today’s tech trends If you’re planning to get certified in 2026 or want to stay ahead of the curve, this is the video you need!
🔑 What We Cover: Expert Series Explained: What makes these advanced certs different. SecAI+ Overview: Why AI security is the next big thing. Core Updates: Changes to A+, Network+, and Security+. Career Impact: How these updates shape your IT path.
🛍️ Support the Channel: Check out the Sec Guy Store for exclusive cybersecurity gear and apparel! ➡️ https://sec-guy.printify.me
📘 Connect with My Sec Guy Channel: Facebook: https://www.facebook.com/share/1HGdh1m51U/
LinkedIn: https://www.linkedin.com/company/secguy Blog: https://medium.com/@secguychannel
☕ Support the Mission:
Buy me a coffee: https://buymeacoffee.com/secguychanc
🔔 Don’t Forget: Like 👍 | Comment 💬 | Subscribe ✅ Hit the notification bell so you never miss the next video in this series!
#CompTIA #ExpertSeries #SecAIPlus #CybersecurityTraining #ITCertification #MySecGuy #CareerGrowth #Comptia2026 #SecAI+ #A+ #Security+ #Network+
Master AI Fundamentals for the CompTIA SecAI+, Security+, CISSP, and CEH. In this lesson, we break down the "Artificial Brain"—from Neural Networks and Weights to the Transformer architecture that powers ChatGPT.
Welcome back to the Sec Guy Channel and the next step on your journey to becoming a cybersecurity professional! 🛡️ While this is the absolute foundation for the CompTIA SecAI+ (Domain 1), this knowledge is now critical for every security role. You cannot secure what you do not understand. Today, we move beyond the buzzwords to understand the actual architecture of AI—because you can't write a policy for a "Black Box" if you don't know how it thinks.
This isn't just about definitions; it's about understanding the "Engine" of modern threats. Whether you are aiming for your Security+, CEH, CISSP, or the new SecAI+, this video covers the essential architecture you need to know.
🔑 What We Cover: The Hierarchy of Intelligence: Understanding the security implications of ANI (Artificial Narrow Intelligence), AGI (General), and the theoretical risks of ASI (Super Intelligence). Inside the "Brain" (Neural Networks): How Input Layers, Hidden Layers, and Output Layers actually process data using Weights and Biases (mimicking biological neurons).
The Game Changer (Transformers): Why the 2017 "Attention Is All You Need" paper changed everything, and how Self-Attention allows AI to understand context (e.g., "Bank of the River" vs. "Bank of America").
How Machines Learn: Distinguishing between Supervised Learning (Labeled Data), Unsupervised Learning (Clustering/Anomaly Detection), and Reinforcement Learning (Trial & Error). Generative Models: A deep dive into the three engines of GenAI: LLMs (Text), Diffusion Models (Images), and GANs (Deepfakes). Understanding AI Architecture is the foundation of securing the future. Let's dive in!
🛍️ Support the Channel: Check out the Sec Guy Store for exclusive cybersecurity gear and apparel! ➡️ https://sec-guy.printify.me
🔔 Don't forget to Like, Comment, and Subscribe for more cybersecurity training! Hit the notification bell so you don't miss Video 2: Vector Databases & RAG.
➡️ SecAI+ Question of the Day: https://youtube.com/shorts/lFMRerQl7F8?feature=share
📚 Resources Mentioned: CompTIA SecAI+ Objectives: https://www.comptia.org/
Recommended Study Materials: [Link to Cheat Sheet]
Connect with the Sec Guy Community:
LinkedIn: https://www.linkedin.com/company/secguy
Facebook: https://www.facebook.com/share/1HGdh1m51U/
Instagram: https://www.instagram.com/secguychannel
☕ Support the Mission:
Buy me a coffee: https://buymeacoffee.com/secguychanc
#CompTIA #SecAI #SecurityPlus #CISSP #CEH #AI #NeuralNetworks #CybersecurityTraining #ITCertification #MySecGuy #GenerativeAI #MachineLearning #DeepLearning
From the publisher's feed
Real cybersecurity training for the real world. We take the complex theories of CompTIA Security+ and SecAI+ and translate them into actionable skills. Whether…
Train Hard. Stay Secure.