SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
GenAI is helping organisations tackle new challenges while reducing resource demands, but like any new technology, it also introduces security risks that attackers can exploit often due to limited understanding of how these systems work. This talk covers key concepts such as Large Language Models (LLMs), Vector Databases, and Retrieval Augmented Generation (RAG), and explains how a typical GenAI architecture functions. It then outlines the main risks in RAG-based applications across data, model, and application layers using practical examples, including prompt injection attacks that can manipulate AI behaviour to expose sensitive information or trigger malicious actions, particularly through vulnerabilities in vector databases. The session concludes with practical recommendations for securing and managing GenAI implementations effectively.


Ahmed is the founder of Cyberdojo with 17+ years in cloud, network, and application security. He specializes in GenAI security and has led projects in cloud security, application security, and incident response.
Read more about Ahmed Abugharbia