All news

Company · Jul 23, 2026

Join us at Black Hat 2026

Two-day training: AI Red Teaming: Attacks on LLMs, Agents, and Multimodal Systems. Taught by Gary Lopez, founder & CEO of Tinycode.

AI Red Teaming · Aug 1–2

Mandalay Bay in Las Vegas, home of Black Hat 2026

At Black Hat USA 2026 in Las Vegas, Tinycode is teaching a two-day core course: AI Red Teaming: Attacks on LLMs, Agents, and Multimodal Systems. Sessions run Saturday, August 1 through Sunday, August 2, led by Gary Lopez, founder & CEO of Tinycode.

Red teaming AI is no longer optional. Regulators increasingly expect security testing for foundational models and high-risk applications. This course teaches you to systematically probe AI systems across traditional security vulnerabilities, adversarial ML attacks, and Responsible AI harms.

What you'll learn:

  • Attack LLMs, multimodal models, and AI agents
  • Exploit Model Context Protocol (MCP) integrations
  • Jailbreak, inject, extract, and poison
  • Build AI agents for automated security testing
  • Fine-tune models and evaluate security posture
  • Deploy defenses that actually work

Hands-on throughout: a CTF platform with 40+ challenges and 10 Python labs, plus open-source tooling (PyRIT, Inspect AI, Autogen, and MCP). Final modules cover mitigations, regulatory requirements, and building security into AI from the start, including the same assessment checklist used for production AI at scale.

Students leave with 30 days of CTF access after the course, complete labs and target apps (runs in Colab), API keys for model interaction, and a 400+ slide deck. Basic Python is enough; no ML background required.

Why we teach this

Tinycode's work is breaking AI systems for the teams that ship them. That work is the curriculum. Most modules in this course started as a finding from an engagement: an agent talked out of its own guardrails, an MCP server that trusted its tool output, a multimodal pipeline where the image was the payload. We teach the attacks we run, in the order we run them.

We teach it in person because offensive knowledge is perishable. Building the course forces us to re-derive our methodology against whatever the current generation of models, agent frameworks, and guardrails are actually doing. Challenges get rebuilt every cycle, and the ones that stop working tell us as much as the ones that still land.

It also runs on our own infrastructure. The labs and CTF sit on the Tinycode Cyber Range, the same environment our customers use for continuous AI testing, and the assessment checklist in the final module is the one our team uses on production systems. Nothing in the room is a teaching-only mock-up.

View the course on the Black Hat schedule and register.