Free AI Security Labs Update!

71 FREE AI Security Labs

The AI Security Labs Hub Just Hit 71 Free Labs

Hey everyone! Remember when we opened up the Arcanum AI Sec Resource Hub? It started as a link dump we emailed to Attacking AI students so they had something real to practice on between sessions. It kept growing. It grew a lot.

71 free, curated labs for AI pentesting & prompt injection No paywalls, no fluff. Hands-on targets you can hit today to actually get good at attacking LLMs and agents. This is a big one, and a few of the new additions are genuinely fire.

The TL;DR

  • 71 free labs now live, plus 7 competitions, 5 bug bounties, 13 tools, and 7 text resources. All free or self-hostable.

  • 8kSec dropped 10 free hosted AI labs covering direct & indirect injection, jailbreaks, and agent/tool abuse. No paywall.

  • AIPWN.ME is a slick browser-based red-team playground. Zero setup, just start breaking things.

  • Bot-Tricks is a full structured curriculum of prompt-injection lessons and live challenges, beginner mindset through advanced evasion.

/ Revamp

When we launched the Hub it had 23 active labs. Getting to 71 was not us padding a list. Every entry is link-checked live, deduped against what is already in there, and picked because it teaches you something real.

If you are trying to break into AI security, the hardest part is not theory. It is reps. You need targets. You need to feel what a successful indirect injection looks like, what agent tool-abuse actually chains into, what a guardrail bypass feels like when it finally pops. Reading about prompt injection makes you conversational. Running 71 labs makes you dangerous.


Wanna come see me and Flare and Anthropic at DEFCON?!!?! 👇👇👇

AI, Offense, and the Limits of Guardrails: A No-BS Conversation

AI is reshaping both sides of the security equation, and the gap between what these models can do and what vendors say they prevent is widening fast. In this panel, offensive security legend Jason Haddix and Anthropic's Rob Bair join moderator Norman Menz to go deep on what AI safety actually looks like from the inside, where it breaks down under real adversarial pressure, and what practitioners need to understand about the threat models that AI companies are, and aren't, defending against.

This candid conversation will cover autonomous agents, prompt injection, model abuse at scale, and whether the safeguards being built today can keep pace with the attackers already probing them.

Reserve Your Spot → FlareFlare Academy Darkroom

/ New Labs Worth Your Weekend

8kSec — AI/LLM Exploitation Challenges

BEGINNER–ADVANCED · ONLINE

The crew at 8kSec opened up 10 free hosted AI security labs through their Battlegrounds platform, and they ramp from beginner to advanced. You get direct and indirect prompt injection, jailbreaking, agent manipulation, and insecure tool use, all running in cloud sandboxes. Free account, nothing to stand up locally. A clean structured path from "I get the concept" to "I can chain an agent attack."

INTERMEDIATE · ONLINE

AIPWN is a hands-on AI red-team playground you run right in the browser. Prompt injection, jailbreaks, data exfiltration, and the LLM security fundamentals, hosted with zero setup. This is the one I would hand someone who says "I want to try attacking an LLM but I do not want to spend an hour on Docker first." Open the tab, start pwning.

Bot-Tricks

BEGINNER–ADVANCED · ONLINE

My kind of resource: a structured compendium of prompt-injection lessons, challenge walkthroughs, and live labs against real LLM targets. It takes you from the foundational injection mindset all the way through advanced evasion, Base64 smuggling, leetspeak, chunking, the works. Organized by technique family, so it doubles as a curriculum.

/ How To Actually Use This

Same flow I always recommend, and it still holds:

  1. Pick a beginner lab and run it end to end. Gandalf and Merlin are still perfect first steps, and now AIPWN.ME joins that easy-on-ramp tier.

  2. Work Bot-Tricks by technique family so your reps have structure instead of being random pokes.

  3. Graduate to the 8kSec agent and tool-abuse labs once direct injection feels easy. That is where the modern attack surface actually lives.

  4. Pull a tool like Garak or PyRIT from the Hub and start automating and scaling your testing.

  5. Hit the competitions and in-scope bug bounties against live targets once you are confident.

/Outro

Huge thanks to every challenge author, lab builder, and tool maker in here. This Hub does not exist without your work, and calling it out is the least we can do. 8kSec, AIPWN, Bot-Tricks, and everyone else who dropped something free for the community: respect.

We keep this thing living. If you know a lab, CTF, or tool we are missing, send it our way and we will vet it. And if you are new to attacking AI, there has never been a lower barrier. 71 free labs are sitting right there.

Go run one today

Happy hacking 😎

— Jason