Skip to content
Editions

The book, edition by edition

Each edition is an immutable git tag. Follow a link to browse that snapshot or to see what changed between editions.

Editions — AI Security Roadmap

The book is cut into editions. Each edition is an immutable git tag edition-N — browse or diff any edition on GitHub. Newest first.

Edition 96 — 2026-10-08

Edition: Week 21 — authored & organized (folded Uber ADR Layer-3 blueprint, GPT-6 Astra CoT-monitorability + honeypot, task-scoped authz paired-replay)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-95...edition-96 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-96

Edition 95 — 2026-10-07

Edition: Week 15 — authored & organized (fold A2M trace-optimized tool-poisoning + COPEX per-layer MCP robustness benchmark)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-94...edition-95 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-95

Edition 94 — 2026-10-06

Edition: Week 14 — authored & organized (folded EvoRiskBench runtime-risk eval, TPRS representation-sensitivity caution, and garak v0.17.0 EU AI Act mapping)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-93...edition-94 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-94

Edition 93 — 2026-10-05

Edition: Week 11 — authored & organized (folded OpenAI/Moonshot CoT-replay incident + RL-breaks-distillation-defenses into the reasoning-trace frontier)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-92...edition-93 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-93

Edition 92 — 2026-10-05

Weekly reconciliation: W24 accountability turn (CA/AL/15-state subpoenas + FTC inquiry over July eval-escape); Huntress human-layer fold; Sep-14 US-counter-model tightened

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-91...edition-92 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-92

Edition 91 — 2026-10-04

Edition: Week 13 — authored & organized (PortSwigger tool-surface methodology + Snyk broken-access-control + Huntress AI-brand-as-lure)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-90...edition-91 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-91

Edition 90 — 2026-10-03

Edition: Week 21 — authored & organized (PixelLeak authorized-but-unsafe incident; CoT-monitoring ceiling via Invalid-Traces; LLMLeak covert fetch-exfil)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-89...edition-90 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-90

Edition 89 — 2026-10-02

Edition: Week 16 — authored & organized (frontier-model-as-threat-actor Astra/AISI, route-around-blocked-installs, FragToken DoW poison)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-88...edition-89 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-89

Edition 88 — 2026-10-01

Edition: Week 24 — authored & organized (open-weight GLM-5.3 + defensive Gemini 4 Argon erode the deployment-gate; Australia named-government agentic breach; IBM breach-cost ingested)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-87...edition-88 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-88

Edition 87 — 2026-10-01

foundations.md: refresh Cross-cutting frames taxonomy pins to OWASP LLM/Agentic Top 10 2026 + MITRE ATLAS v2026.09 (retro-2026-10)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-86...edition-87 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-87

Edition 86 — 2026-10-01

week-15: archive pre-Sep CVE write-ups to cve-archive.md (structural prune, retro-2026-10)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-85...edition-86 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-86

Edition 85 — 2026-09-30

Edition: Week 21 — authored & organized (fold SEABench self-evolving-agent misalignment + openrig orchestrator trust-config as harness-evolution control-boundary lessons)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-84...edition-85 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-85

Edition 84 — 2026-09-29

Edition: Week 9 — authored & organized (BSD belief self-distillation: refusal is conditioned on inferred user identity — the mechanism behind persona/roleplay/primed-provenance jailbreaks)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-83...edition-84 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-84

Edition 83 — 2026-09-28

Edition: Week 08 — authored & organized (folded OWASP LLM Top 10 2026 + ranked Agentic ASI01-10; where-a-risk-lives triage, ASI04 dynamic vs static supply chain, ASI07/08/10 net-new classes, cross-framework mapping)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-82...edition-83 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-83

Edition 82 — 2026-09-28

Weekly reconciliation 2026-09-28 — OWASP LLM 2026 reorder (Excessive Agency LLM06→LLM03) + Agentic ranked ASI01-10 → W8; MITRE ATLAS v2026.09 counts → W23; IBM 2026 breach-cost governance anchor → W24; NIST IR 8587 token/authz gap → W22; Kong CVE-2026-13341 → W15 (count 119+); garak v0.17.0 EU-AI-Act mapping → W14

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-81...edition-82 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-82

Edition 81 — 2026-09-26

Edition: Week 15 — authored & organized (folded arXiv 2605.22333 remote-MCP auth measurement into Class-3 auth-bypass family; OAuth-present ≠ secure)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-80...edition-81 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-81

Edition 80 — 2026-09-25

Edition: Week 13 — authored & organized (folded Hacktron OpenAI HEIF-RCE→SSO breach; Opus 4.8→5 capability landmark)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-79...edition-80 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-80

Edition 79 — 2026-09-23

Edition: Week 14 — authored & organized (folded OpenAI Defense Factory as the defensive-orchestration blueprint)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-78...edition-79 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-79

Edition 78 — 2026-09-22

Edition: Week 21 — authored & organized (folded self-authored handoff injection + Who-Let-The-Agents-Act 3-posture lab)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-77...edition-78 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-78

Edition 77 — 2026-09-21

Edition: Week 8 — authored & organized (folded OWASP Top 10 incident-data robustness audit — κ≈0.20 expert-vs-incident, prompt injection #1 vote/#12 record)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-76...edition-77 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-77

Edition 76 — 2026-09-21

Weekly reconciliation 09-21: W24 governance landmarks — AEPD world-first agentic breach + US posture shift + NIST NVD RFI; Google Home MCP → W21

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-75...edition-76 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-76

Edition 75 — 2026-09-20

Edition: Week 16 — authored & organized (folded malicious LLM-API-router intermediary arXiv 2604.08407; stamped Plugin4Shell ingested)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-74...edition-75 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-75

Edition 74 — 2026-09-19

Edition: Week 24 — authored & organized (deployment-gated frontier capability: Fairwind/EFS/Astra + concentration risk)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-73...edition-74 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-74

Edition 73 — 2026-09-18

Edition: Week 19 — authored & organized (folded NVIDIA OpenShell sandbox-product CVE batch; 'the sandbox is software too')

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-72...edition-73 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-73

Edition 72 — 2026-09-17

Edition: Week 18 — authored & organized (placeholder-stable redaction fold: DataSentry/Maskit; cleared 2 transcript-less video backlog → 26/26)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-71...edition-72 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-72

Edition 71 — 2026-09-16

Edition: Week 15 — authored & organized (folded MCPSEC no-box metadata audit into Defenses; ingested GitSpawn; +2 checklist boxes)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-70...edition-71 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-71

Edition 70 — 2026-09-15

Edition: Week 06 — authored & organized (folded mind-viruses self-propagation + emergent-cheating knowledge-commons into a new self-propagating-contamination section)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-69...edition-70 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-70

Edition 69 — 2026-09-14

Reconciliation 2026-09-14 — consolidated the frontier-lab eval-containment cluster into one named family (shared lesson stated once); bumped MCP CVE count 105+→110+ for 4 net-new MCP-server CVEs this week

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-68...edition-69 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-69

Edition 68 — 2026-09-13

Edition: Week 10 — authored & organized (fold PIPE threat model + out-of-prompt mitigations; fix dead Thacker URL)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-67...edition-68 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-68

Edition 67 — 2026-09-12

Edition: Week 16 — authored & organized (HookPry hook-update path + Cyber-Financial Contagion systemic-risk folded; 2609.05380 stamped; 61/61)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-66...edition-67 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-67

Edition 66 — 2026-09-08

Edition: Week 13 — authored & organized (AI-gateway control plane, Kiro workspace-trust exfil, LLM-decompiler behavior-erasure)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-65...edition-66 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-66

Edition 65 — 2026-09-07

Edition: Week 21 — authored & organized (folded SARA provenance-authorization, Calibrated-Enough packaging-authority, user-authored-policy vs HITL, CONTINUITY composition, draft-model confidence gate)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-64...edition-65 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-65

Edition 64 — 2026-09-06

Edition: Week 18 — authored & organized (folded adaptive-eval of out-of-band defenses arXiv 2606.26479; stamped agentctl ingested)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-63...edition-64 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-64

Edition 63 — 2026-09-05

Edition: Week 14 — authored & organized (folded RedEvoAgent attack-skill evolution, Metasploit msfmcpd read-only-default gate, LLM-judge reliability failure)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-62...edition-63 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-63

Edition 62 — 2026-09-04

Edition: Week 11 — authored & organized (folded Grok Cryptographic Context Injection; ingestion 35/35)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-61...edition-62 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-62

Edition 61 — 2026-09-03

Edition: Week 15 — authored & organized (folded the Måløy/Willison in-the-wild self-replicating Word-document worm into §4; stamped Check Point LangGraph + DarkClaw ingested; Week 15 ingestion complete 53/53)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-60...edition-61 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-61

Edition 60 — 2026-09-02

Edition: Week 16 — authored & organized (folded HF exploit-instrumentation study, Beyond F1 scanner-coverage, CycloneDX ML-BOM/ECMA-424, and distillation trait-direction-drift poisoning; ingestion 58/58)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-59...edition-60 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-60

Edition 59 — 2026-09-01

Edition: Week 25 — authored & organized (folded Anthropic 3-incident eval-sandbox landmark + verify-containment-out-of-band rule, GenAI-IRF DSR synthesis, SANS FOR563 local-LLM DFIR track)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-58...edition-59 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-59

Edition 58 — 2026-09-01

Monthly retro URL-health pass (Sep 2026). Three dead links carried across multiple reconciliations as "needs the monthly --force URL-health path" finally resolved, plus one caught fresh this run:

  • ChromaDB Getting Started (week 4) — confirmed hard 404 since 2026-08-03 (edition 29). Fixed to the working canonical path docs.trychroma.com/docs/overview/getting-started (verified 200, same content).
  • CyberArk "Poison Everywhere" FSP/ATPA (weeks 6, 7, 21) — cyberark.com 301-redirects to a generic paloaltonetworks.com/idira landing page (CyberArk->Palo Alto acquisition rebrand), flagged 2026-08-18. No live replacement exists on either domain. Swapped to a verified working archive.org snapshot (2026-05-11, content confirmed present: FSP/ATPA/ Advanced Tool Poisoning all found in the archived HTML) rather than drop the citation for CyberArk's own coined terminology.
  • Lawvable EU AI Act Compliance guide (week 24) — 301-redirects to a generic lawve.ai landing page (no archive.org snapshot exists), flagged 2026-08-29. Replaced with N-iX's EU AI Act Compliance Roadmap (verified live), which covers the same ground (four risk tiers, step-by-step roadmap, penalty structure) and additionally reflects the May-2026 Digital Omnibus deadline reset that the dead Lawvable page predates.

Uses --force because a straight URL swap trips the non-destructive guard (old URL disappears) even though nothing was silently dropped — every citation's substance and id: marker is preserved.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-57...edition-58 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-58

Edition 57 — 2026-08-31

Edition: Week 1 — authored & organized (watch-then-drill practice path; 5 math-foundation sources ingested)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-56...edition-57 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-57

Edition 56 — 2026-08-30

Edition: Week 08 — authored & organized (ATLAS case-study backbone + ecosystem: Camera Hijack/Morris II/ShadowRay, AI Incident Sharing/Risk DB/Dioptra/CWE plumbing from NIST ATLAS deck)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-55...edition-56 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-56

Edition 55 — 2026-08-29

Edition: Week 24 — authored & organized (folded What-If counterfactual/five-fairness detail; ingested Further Reading backlog 6/19 → 12/19; restored dropped YesWeHack W13 feed URL from a botched auto-merge)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-54...edition-55 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-55

Edition 54 — 2026-08-28

Edition: Week 23 — authored & organized (ATLAS v2026.07 refresh: 101 techniques/77 sub, v6+date-versioning migration, platform designations, AML.T0104 3-phase tool-poisoning, 2 new mitigations)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-53...edition-54 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-54

Edition 53 — 2026-08-27

Edition: Week 13 — authored & organized (folded UAT-10147 in-wild agentic orchestrator + the click-layer injection surface: AI Recommendation Poisoning + Zenity Claude-in-Chrome takeover; stamped 7 ingested)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-52...edition-53 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-53

Edition 52 — 2026-08-26

Edition: Week 21 — authored & organized (folded SHE harness-evolution 4-artifact model; cleared 8 hands-on drills)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-51...edition-52 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-52

Edition 51 — 2026-08-25

Edition: Week 17 — Guardrails & Semantic Firewalls: folded 2026 abliteration-cost collapse (OBLITERATUS + Uncensored-Cyber Qwen), ingested OWASP LLM07/LLM10 + slopsquatting + talks backlog (35/35 complete)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-50...edition-51 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-51

Edition 50 — 2026-08-24

Edition: Week 2 — authored & organized (graded hands-on path: Kaggle Intro-to-ML overfitting sweep + Connect Four minimax→deep-RL arc, code-first PyTorch tracks; 9 backlog ingested → 19/19)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-49...edition-50 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-50

Edition 49 — 2026-08-23

Edition: Week 26 — authored & organized (fold OSAI exam structure/scoring + correct AI-tools-encouraged rule)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-48...edition-49 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-49

Edition 48 — 2026-08-22

Edition: Week 7 — authored & organized (folded OWASP MCP Top 10 taxonomy + mapping; cleared 11-item backlog)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-47...edition-48 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-48

Edition 47 — 2026-08-21

Edition: Week 21 — authored & organized (folded CompressAgent control-context reliability + CallScreenBench adversarial-proxy eval; cleared IBM-video backlog as covered)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-46...edition-47 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-47

Edition 46 — 2026-08-20

Edition: Week 18 — authored & organized (folded deployable AEGIS firewall + stack-relevant agentctl IBAC; cleared 11-item ingestion backlog)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-45...edition-46 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-46

Edition 45 — 2026-08-19

Edition: Week 16 — authored & organized (ingested picklescan/HF two-tier scanners, NVIDIA Verified Agent Skills signing, VentureBeat IR playbook, NTIA SBOM baseline; 42/52→54/56)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-44...edition-45 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-45

Edition 44 — 2026-08-18

Edition: Week 06 — authored & organized (cleared 14-item backlog, folded CyberArk FSP-vs-ATPA MCP distinction with SSH-key PoC, ingestion 13/27→27/27)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-43...edition-44 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-44

Edition 43 — 2026-08-17

Edition: Week 22 — Risk Mgmt Frameworks authored & organized (NIST GenAI Profile 12 risks + IR 8596 Secure/Defend/Thwart + Gold Eagle EO detail; 15 sources ingested 12/31→27/31)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-42...edition-43 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-43

Edition 42 — 2026-08-16

Edition: Week 5 — Core Concepts of Agentic AI authored & organized (MITRE ATLAS AML.T0080 naming fix; MINJA 95/70 + memory-dilution caveat; TRAP 13-43% stats; multimodal audio/FigStep-Pro stealth; 15 sources ingested)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-41...edition-42 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-42

Edition 41 — 2026-08-15

Edition: Week 19 — authored & organized (Infrastructure Hardening & Sandboxing: cleared 16-item m2/m9 backlog, folded Zenity honeypot campaign stats + Cisco dormant-server ratio, fixed vLLM CVE-2026-22778 mechanism → 30/30)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-40...edition-41 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-41

Edition 40 — 2026-08-14

Edition: Week 3 — authored & organized (folded Transformer Explainer live-GPT-2 visualizer; cleared 16-item pedagogical backlog, ingestion 12/28→28/28)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-39...edition-40 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-40

Edition 39 — 2026-08-13

Edition: Week 12 — authored & organized (folded CorruptRAG canonical + GraphRAG poisoning GragPoison/UKPA; ingested 27/27)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-38...edition-39 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-39

Edition 38 — 2026-08-12

Edition: Week 21 — authored & organized (LLM06 Unbounded Consumption / LLM03 complete mediation folded + ingested; +cost-control deliverables)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-37...edition-38 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-38

Edition 37 — 2026-08-11

Edition: Week 11 — authored & organized (folded FGSM/ART/C&W build path; stamped embedding-inversion + OWASP LLM02 side-channel backlog ingested)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-36...edition-37 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-37

Edition 36 — 2026-08-10

Edition: Week 8 — authored & organized (folded STRIDE-GPT automation + ACM FSE 26-vector STRIDE study into the STRIDE section; stamped 18 already-cited backlog items; ingestion 10/34 → 28/34)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-35...edition-36 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-36

Edition 35 — 2026-08-10

Edition: OWASP LLM Top 10 2026 absorbed — 6 weeks filled to exam depth (W8 Hidden Context Exposure [new LLM08], W11 inference side-channels, W12 retrieval jamming, W16 slopsquatting/LoRA provenance, W17 Claim-Check-Act, W21 unbounded consumption + complete mediation) + finalized OWASP-2026 crosswalk. Guard-clean, citations ✅.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-34...edition-35 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-35

Edition 34 — 2026-08-09

Edition: Week 17 — Guardrails & Semantic Firewalls: folded structural pre-wire enforcement (MS AGT), pipelock capability separation, autoguardrails monitor-loop, agentshield, Heretic mechanism/LoRA; ingestion 13/33→26/33

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-33...edition-34 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-34

Edition 33 — 2026-08-08

Edition: Week 15 — authored & organized (folded MCP Pitfall Lab P1-P6 + MCPThreatHive MCP-38 into Defenses, added Phoenix Claude Code CLI CVE trio + Copilot Cowork exfil case, enriched BadHost/DifyTap/mcp-k8s; ingestion 33→49/84)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-32...edition-33 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-33

Edition 32 — 2026-08-07

Edition: Week 13 — authored & organized (folded HackSynth jagged-capability benchmark; stamped 15 OSAI m2/m9 recon+infra-exploit sources; ingestion 18/53 → 34/53)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-31...edition-32 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-32

Edition 31 — 2026-08-05

Edition: Week 14 — authored & organized (folded AgentFlow harness-synthesis + public/OTR-divergence + a practice-ranges section (FinBot/Otto/ARGUS); ingested 20→60/60)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-30...edition-31 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-31

Edition 30 — 2026-08-04

Edition: Week 09 — authored & organized (folded Decoy Images 2608.01043 encoding-defense observation; ingestion 26→46/47)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-29...edition-30 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-30

Edition 29 — 2026-08-03

Edition: Week 4 — authored & organized (folded hands-on RAG build path: Chroma auto-embed, Microsoft lesson 15, freeCodeCamp/Valkov walkthroughs; stamped all m5/m6 sources; ingestion 8/30 → 30/30)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-28...edition-29 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-29

Edition 28 — 2026-08-02

Edition: Week 16 — authored & organized (folded Megalodon spinoff, Vectra forged-cert mechanism, CVE-2026-45321, FuseChain+PYPILINE detection; ingestion 21→42/52)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-27...edition-28 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-28

Edition 27 — 2026-08-01

Edition: Week 21 — authored & organized (folded Tines SOAR five-stage playbook into Layer 3; ingested 20 OSAI offensive-tradecraft sources + SOAR guide, 19/52 → 40/52)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-26...edition-27 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-27

Edition 26 — 2026-07-31

Edition: Week 9 — authored & organized (folded 12 CTF/lab/course sources into an organized practice reference + Greet-and-Repeat methodology; ingestion 14→26/45)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-25...edition-26 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-26

Edition 25 — 2026-07-30

Edition: OSAI coverage crosswalk updated — all 11 modules audited to full exam depth (recon + embeddings gaps closed); 71 gaps closed / 153 sources across 15 weeks.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-24...edition-25 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-25

Edition 24 — 2026-07-30

Edition: OSAI gap-fill batch 4 (FINAL) — Weeks 19 (infra/deploy exploits + recon), 21 (agent control/safety-bypass), 26 (capstone) filled to exam depth. All 15 mapped weeks now audited vs the OSAI syllabus; guard-clean, citations verified.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-23...edition-24 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-24

Edition 23 — 2026-07-30

Edition: OSAI gap-fill batch 3 — more mapped weeks filled to exam depth; guard-clean, citations verified.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-22...edition-23 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-23

Edition 22 — 2026-07-30

Edition: Week 15 — authored & organized (A2A/multi-agent m4 section ingested: Agent Card Poisoning, CFH, session smuggling, Prompt Infection; 33/53 sources)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-21...edition-22 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-22

Edition 21 — 2026-07-30

Edition: OSAI gap-fill batch 2 — more mapped weeks audited vs their OSAI modules and filled to exam depth; guard-clean, citations verified.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-20...edition-21 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-21

Edition 20 — 2026-07-30

Edition: OSAI gap-fill batch 1 — Weeks 4,5,6,7 audited vs their OSAI modules and filled to exam depth; guard-clean, citations verified.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-19...edition-20 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-20

Edition 19 — 2026-07-30

Edition: OSAI / AI-300 alignment — added a reference crosswalk mapping all 11 Advanced AI Red Teaming (OSAI) syllabus modules to the roadmap's weeks (verified against OffSec's official course + candidate reviews), flagged the 2 lighter areas (recon, embeddings), and added What's-New cert pointers in W8/W14/W26.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-18...edition-19 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-19

Edition 18 — 2026-07-30

Edition: Wave-2 batch 6 (FINAL) — Weeks 23 (MITRE ATLAS), 24 (Compliance), 25 (IR & Forensics), 26 (Capstone) authored to standard. The full 26-week book is now authored end-to-end; guard-clean, citations ✅.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-17...edition-18 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-18

Edition 17 — 2026-07-30

Edition: Wave-2 batch 5 — Weeks 19 (Infra Hardening), 20 (MLSecOps), 21 (Agentic Safety), 22 (Risk Frameworks) authored to standard; guard-clean, citations ✅.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-16...edition-17 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-17

Edition 16 — 2026-07-30

Edition: Wave-2 batch 4 — Weeks 12 (RAG Poisoning), 13 (Agentic Pentesting), 17 (Guardrails), 18 (Bidirectional Defense) authored to standard; guard-clean, citations ✅.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-15...edition-16 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-16

Edition 15 — 2026-07-30

Edition: Wave-2 batch 3 — Weeks 9 (Prompt Hacking), 10 (Semantic Exploitation), 11 (Adversarial ML) authored to standard; guard-clean, citations healed. Run stalled on hung WebFetch agents after these 3.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-14...edition-15 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-15

Edition 14 — 2026-07-30

Edition: Wave-2 batch 2 — Weeks 6 (Agentic Design Patterns), 7 (MCP), 8 (Threat Modeling) authored to standard; guard-clean, citations verified. Batch stalled at W09 (shared quota still tight this morning).

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-13...edition-14 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-14

Edition 13 — 2026-07-30

Edition: Wave-2 batch 1 — Weeks 1 (Math Literacy), 2 (ML Paradigms), 4 (RAG Systems), 5 (Agentic Core) authored to standard. Rate-limit interrupted the wave at 4/22; these 4 are guard-clean + citations ✅ (URL-preservation hardening held — zero dropped). Pending independent verify.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-12...edition-13 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-13

Edition 12 — 2026-07-29

Edition: Wave-1 authoring — Weeks 3 (Deep Learning & Transformers) & 16 (Supply Chain & Lifecycle) authored to standard; verify 91/90. Replaced Barracuda generic-homepage citation with the real Mar-2026 malware-brief article; restored 4 Miasma/RedHat sources the reshape dropped; deduped Vectra Shai-Hulud Part 2.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-11...edition-12 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-12

Edition 11 — 2026-07-29

Edition: citations — every reference now clickable (Week 14 tool catalog fully sourced; Week 15 Censys/NSA/ShareLock sourced, NSA date fixed to May 2026)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-10...edition-11 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-11

Edition 10 — 2026-07-29

Edition: Week 14 — authored & organized (Automated Red Teaming Toolchains: framework stack + autonomous-research orchestration + toolchain-as-target supply chain)

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-9...edition-10 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-10

Edition 9 — 2026-07-29

Week 15 — CVE catalog regrouped by root-cause class. The 📇 reference no longer opens onto a chronological pile: after the four-class table, the ~46 catalogued CVEs are now grouped under Class 1 · Transport-authz binding gap, Class 2 · Auto-load without consent, Class 3 · Missing-auth / empty-secret, Class 4 · Command-filter bypass, Cross-cutting sinks (path-traversal / SSRF / cmd-injection), and Landmark incidents, research & synthesis — each with a one-line class definition + fix. The recent/in-the-wild bold-block CVEs sit under their own chronological heading.

Every entry kept verbatim; all 67 URLs preserved (guard vs edition-8). Both the folded and expanded views are now clean.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-8...edition-9 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-9

Edition 8 — 2026-07-29

Structural — content split into a per-week file tree. The four monoliths (roadmap/resources/checklist/notes, up to 162 KB each) are now content/weeks/week-NN/{chapter,resources,checklist,notes}.md, plus content/reference/ (YouTube, certs, books…), foundations.md, stack-audit.md, and meta/course.json.

Why: a 146 KB file is the worst thing for an LLM to amend surgically. Per-week files are ~5–8 KB. Your tracking is untouched — the <!-- added --> stamps and checkboxes live on each line and travel with it, so What's New + completion carry over exactly.

Migration guard-verified: 611 URLs → 611, nothing dropped. App, tools, docker, intelligence.yaml, CLAUDE.md, and heartbeat paths all rewired to the tree.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-7...edition-8 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-8

Edition 7 — 2026-07-29

Week 15 appendix — organizing frame added. The reference now opens with the four root-cause classes as a table (Transport-authz gap · Auto-load-without-consent · Missing-auth/empty-secret · Command-filter bypass), each with its root cause and the fix, plus a note on how the 2026-07-28 spec closes classes 1 & 3. The reader classifies each CVE below by its class instead of reading a chronological pile.

Honest scope: the 50+ individual CVEs below the frame are still in chronological order — fully re-bucketing every one under its class (across two accreted piles, months of daily-pulse output) is a per-CVE judgment task and is the Editor's rolling job, done carefully rather than in one risky sweep. The taxonomy now leads so new CVEs get placed correctly going forward.

No content removed — guard-verified vs edition-6.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-6...edition-7 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-7

Edition 6 — 2026-07-29

Week 15 — the CVE tail is no longer in the lesson's way. Fixes "everything after Key CVEs looks messy."

  • The 336-line CVE catalog + case studies now live under a single 📇 CVE reference & case studies appendix, collapsed by default — the chapter ends at the authored lesson (Defenses + the one rule), and the catalog is one click away.
  • New app behaviour: any chapter heading starting with 📇 becomes a fold/unfold toggle (▸/▾).
  • No CVE, case study, or link removed — guard-verified vs edition-5; only demarcated and folded.

Next: within the reference, group the loose recent CVEs into the four-class taxonomy so the expanded view is organized too (not just hidden).

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-5...edition-6 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-6

Edition 5 — 2026-07-29

Week 15 restructured into a readable lesson (format fix). Same substance as edition 4, reorganized so it reads like a textbook chapter, not paragraphs of prose.

  • Four clear section headers: The big picture · The attack vectors · The supply chain underneath · Defenses.
  • Each attack vector is its own subheading (1–4).
  • The STDIO command-injection families are now a table; supply-chain figures are a stat list.
  • Key rules ("localhost is not a trust boundary", "not indirect prompt injection", the one rule) are callout boxes.
  • App gains lesson typography (heading hierarchy + callout styling).

No facts or links changed — guard-verified vs edition-4. This layout is now the structural standard for authored chapters.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-4...edition-5 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-5

Edition 4 — 2026-07-29

Week 15 — first Further-Reading ingestion pass. Answering "do the non-core sources ever get read?" — yes, on a rolling basis.

Read three Further Reading (non-core) sources end-to-end and folded their gist into the chapter — synthesis, not appending:

  • AutoJack (Microsoft) → the "localhost is not a trust boundary" pattern, into Vector 1.
  • MCP supply-chain numbers (Security Boulevard) → a new "supply chain underneath" paragraph (973 packages · 71% single-maintainer · 24,008 leaked secrets).
  • NSA MCP guidance → the concrete defensive baseline in the closing section.

Each is cited; every URL preserved (guard vs edition-3). Marked these + the core sources <!-- ingested -->.

Week 15 ingestion coverage: 9/42 (21%). The remaining 33 stay in the rolling backlog for future passes — the Library drains over time; it is not a graveyard of unread links.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-3...edition-4 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-4

Edition 3 — 2026-07-29

Week 15 chapter authored — read-and-synthesized prose (writing-quality proof). Addressing the gap that we were organizing pointers, not authoring the book.

I read five core sources end-to-end — OX Security's ecosystem advisory, Invariant Labs' tool-poisoning disclosure, the MCPTox benchmark, Unit 42's sampling attack primitives, and the formal Breaking the Protocol analysis — and rewrote the Week 15 attack-surface section from bold-label blurbs into a flowing narrative organized by the four attack vectors (transport command-injection · tool poisoning · the sampling channel · trust propagation) plus the systemic "why patching won't help" close.

  • Every claim is cited inline to the source it came from.
  • Every fact and link from the old version is preserved (guard-verified vs edition-2); adds Invariant / Unit 42 / Breaking-the-Protocol citations.
  • This is the intended quality bar for authoring every chapter going forward.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-2...edition-3 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-3

Edition 2 — 2026-07-29

Proof-of-shape — Week 15 reshaped into the Course/Library model. First application of the new structure, on the most bloated week (MCP Deep Dive).

  • 🎯 Objectives added to the Week 15 chapter (roadmap.md) — a followable "by the end you can…" list.
  • 📖 Core Path — 6 curated essentials (OX 4-family taxonomy · Invariant tool poisoning · MCPTox benchmark · TrustFall · NSA MCP guidance · Damn Vulnerable MCP hands-on).
  • 📚 Further Reading — the other 36 resources, preserved under their original sub-sections (now nested below Core).
  • ✅ Nothing removed — the guard verified all 42 Week-15 URLs are still present; items only moved.

Weeks 1–14 and 16–26 are unchanged — they'll be reshaped edition by edition.

🔗 What changed: https://github.com/BriskStack/AI-Security-Roadmap/compare/edition-1...edition-2 🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-2

Edition 1 — 2026-07-29

Baseline snapshot — the roadmap as it stands before the Course/Library reshape: all 26 weeks, ~556 resources, plus the first colleague-feed harvest (6 items across weeks 13-20). No content changed; this pins the starting point so every future edition can be diffed against it.

🏷️ Snapshot: https://github.com/BriskStack/AI-Security-Roadmap/tree/edition-1