← Back to list

You’re already good at cybersecurity. These resources will make you dangerous with AI.

The field just got an upgrade. Here’s how to make sure you did too, without throwing away everything you already know.

h@shtalk · 2026-06-01 14:06 · 0 claps · 4.1 min read
#cybersecurity #ai #infosec #info-sec-writeups #ai-tools
Open on Medium ↗
Wiki topics: AI · AI · General 🔒 · Cybersecurity

You’re already good at cybersecurity. These resources will make you dangerous with AI.

The field just got an upgrade. Here’s how to make sure you did too, without throwing away everything you already know.

Let’s skip the part where I tell you AI is changing everything. You know that. You’ve seen the LinkedIn posts. You’ve watched the conference talks. You’ve probably already used an LLM to write a detection rule or summarize a threat report and thought, okay, this is actually useful.

So this isn’t a beginner’s guide to AI. And it’s definitely not a “learn Python in 30 days” listicle dressed up in new clothes.

This is for the person who already knows what a SOC is, who has a cert or two, who can hold their own in an incident response conversation and who is quietly wondering whether the AI wave is something they should be surfing or just watching from the beach.

The answer is surfing. And the good news is that everything you already know is the advantage most AI learners don’t have.

Photo by Steve A Johnson on Unsplash

Photo by Steve A Johnson on Unsplash

Why cybersecurity people are actually ahead here

Most people learning AI are starting from scratch. They understand the models but they have no idea what to do with them. They can fine-tune a classifier but they couldn’t tell you what an adversarial example means in a real environment.

You can.

You already understand threat models. You already think in terms of attack surfaces, anomalies, and adversaries. You understand what it means when something behaves in a way it shouldn’t. That mental model, the hacker’s mental model is exactly what makes AI in security so powerful when it’s in the right hands.

The gap you need to close is not conceptual. It’s technical and applied. And that gap is much smaller than you think.

What you’re actually learning

Before we get to resources, let’s be clear on what the skill actually is. There are two distinct directions here and they’re both worth knowing about:

AI for defence — using machine learning and LLM-based tools to do your job better. Faster alert triage, anomaly detection at scale, automated threat hunting, smarter incident summarization. This is the “make your current work twice as fast” path.

AI as the attack surface — understanding how AI systems themselves can be attacked. Prompt injection, model poisoning, adversarial inputs, jailbreaks at scale. This is the “new category of vulnerability that barely anyone understands yet” path.

If you’re on the defensive side of the house, start with the first. If you’re in red team or research, the second one is where things get genuinely interesting.

The resources, ranked by where you are right now

If you want to understand the landscape first

SANS Free AI Security Resources — SANS built a plain-language framework specifically for security professionals, covering how AI systems can be attacked and how they can be protected. It’s aligned with OWASP’s AI Exchange, which matters because OWASP frameworks have a habit of becoming industry standard faster than anything else. Start here if you want orientation before you commit to a course. It’s free, it’s not trying to sell you anything, and it was written by people who actually work in security.

**The Awesome-AI-Security GitHub repo I personally love these, **someone did the curation work so you don’t have to. DoD risk management guides, NCSC secure development frameworks, red teaming research, dark web tooling analysis. It’s a living document and it’s genuinely good. Bookmark it, come back to it monthly.

If you want structured learning with a credential at the end

Johns Hopkins AI for Cybersecurity Certificate — this is the one I’d point to for SOC analysts and Tier 1/2 people specifically. It’s project-based, it’s built for practitioners not academics, and it results in something you can put on a resume. Not cheap, but it’s Johns Hopkins. The ROI is real.

**Microsoft AI Red Teaming Training — **Free video series from Microsoft’s actual AI red team.

SANS SEC595 — if you want the deep technical version with a GIAC cert at the end, this is it. Expensive. Dense. Worth it if you’re serious about making machine learning for security your actual specialization.

If you want to learn by doing

Secure Code Game —a free, open-source in-editor experience by GitHub Security Lab where you exploit and fix intentionally vulnerable code. Season 4 just dropped, and it’s entirely focused on Agentic AI security.

Zero to Mastery AI for Cybersecurity Bootcamp — covers both offensive and defensive applications, practical projects throughout. Good if you learn better from a structured course than from documentation.

IncidentDatabase.ai — a collection of real AI incidents. Not all cybersecurity-related but that’s actually what makes it useful. Pattern recognition across failures is how you build intuition. Read these the way you’d read post-mortems.

The community that matters

AI Village — this is where the actual intersection of hacking culture and AI research lives. Hackers, data scientists, security researchers, all in one place working through the same questions you’re working through. They run events at DEF CON. They publish research. If you want to know what serious people are actually thinking about AI security right now, this is the room to be in.

The order I’d do it in

  1. Read the SANS guidelines. One afternoon. Gets you oriented.
  2. Explore the GitHub repo. Not all of it — just enough to know what exists.
  3. Pick your direction — defence or attack surface — and commit to one course.
  4. Join AI Village. Lurk first. Then contribute.
  5. Build one thing. Anything. A simple detection rule using an LLM API. A prompt injection test. Something you can point to.

One last thing

The attackers are already using AI. They got there faster, as usual. AI-generated phishing now has perfect grammar, perfect tone, personalized context pulled from your public profiles. The “check for spelling mistakes” advice that worked for a decade is dead.

That’s not meant to scare you. It’s meant to clarify the stakes.

You already know how to think like an adversary. Now you just need to know how the adversary’s new tools work.

That’s the whole job and you’re closer than you think.


메타데이터
post_id
bbfbad2feef3
slug
youre-already-good-at-cybersecurity-these-resources-will-make-you-dangerous-with-ai-bbfbad2feef3
url
https://medium.com/@eva-georgieva/youre-already-good-at-cybersecurity-these-resources-will-make-you-dangerous-with-ai-bbfbad2feef3
canonical_url
https://medium.com/@eva-georgieva/youre-already-good-at-cybersecurity-these-resources-will-make-you-dangerous-with-ai-bbfbad2feef3
author_url
https://medium.com/@eva-georgieva
status
ok
fetched_at
2026-06-09 15:37:30