SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsEnterprises now face a volume of AI-discovered vulnerabilities that periodic, ticket-centered processes cannot absorb. NIST enriched nearly 42,000 CVEs in 2025 and still fell behind, with Q1 2026 submissions running roughly a third higher than the same period in 2025.
The VulnOps Field Guide is a practical, product-neutral guide to the discipline researchers Heather Adkins, Gadi Evron, and Bruce Schneier coined the term for: turning vulnerability discovery into verified risk reduction through a governed, repeatable operating model.
Inside, you'll find the seven-phase decision loop from intake through independent verification, guidance on governance and named ownership, guardrails for using AI as a recommender rather than an unsupervised executor, and the metrics that separate real closure from a hidden exception queue.
Pilot one decision loop. Prove it works, then expand.


Launched in 1989 as a cooperative for information security thought leadership, it is SANS’ ongoing mission to empower cybersecurity professionals with the practical skills and knowledge they need to make our world a safer place.
Read more about SANS Institute




















