AI Security Mastery — 26-Week Study Checklist
Execution layer. Tick boxes here as you complete work. The substantive content for each week — what the topic IS, why it matters, primary sources — lives in
roadmap.md. Each week's heading links to the matching roadmap section.Last verified against trends: 2026-05-12 — see
reconciliation-2026-05-12.md.
Stack Security Audit (do immediately)
↪ See roadmap.md → Cross-cutting → Stack-affecting CVEs
- Audit CVE-2026-35022/35020/35021 (Claude Code CLI) — check all
agent
.claude/settings.jsonforapiKeyHelper,awsAuthRefresh,gcpAuthRefreshfields; verify v2.1.118 patch status - Check if
mcp-server-gitormcp-remoteare installed; verify versions against CVE-2025-68143/44/45 and CVE-2025-6514 - Verify Claude Code version ≥ 2.0.72 (fixes CVE-2026-24887 find command bypass RCE)
- Verify anthropic-sdk-typescript not v0.79.0–0.91.0 (CVE-2026-41686 insecure file permissions on agent memory)
- Verify Claude Code version ≥ 2.1.64 (fixes CVE-2026-39861 sandbox escape via symlink; CVSS 10.0)
- Reboot VPS to kernel 6.8.0-111 to patch Copy Fail (CVE-2026-31431 kernel LPE + container escape); verify fix included
- Inspect
.claude/dirs in any repos cloned by builder for unexpectedSessionStarthook entries (Shai-Hulud persistence) - Review NIST IR 8596 (Cyber AI Profile) when final draft drops mid-2026 — overlay onto our agent architecture