Privacy Breach Through Application Vulnerabilities
An error message and one URL id are enough to read other people's records.
Interactive 3D cybersecurity simulations and employee security training exercises. No sign-up, no paywall. Start learning immediately.
Master employee cybersecurity fundamentals with interactive 3D simulations and hands-on security exercises.
Showing 203 exercises 0 results for “”
Handle a fake invoice designed to make you call.
Spot a phishing email before you click.
Handle a realistic voice phishing call.
Detect fraud hiding in your text messages.
Recognize the two-email trust trap.
Stop a CEO impersonation wire fraud.
Recognize manipulation before you comply.
Spot an AI-generated executive on a video call.
Your public profile is their attack playbook.
That QR code skips every email filter you have.
Your "boss" on WhatsApp isn't your boss.
That virus warning is the actual attack.
Top search results aren't always trustworthy.
Catch a fraudulent vendor invoice using the 3-way match before it reaches the payment file.
Stop a vendor banking BEC by using your authoritative directory and an out-of-band callback.
Catch an AI-cloned executive voice on the phone before the wire goes out.
Catch a spoofed calendar invite before the fake meeting page harvests your credentials.
Build a backup plan that survives ransomware.
Practice the habits that protect unattended devices.
See why skipping updates opens real attack paths.
Survive a ransomware attack in real time.
Think twice before plugging in that USB drive.
Know what your EDR alert means and what to do next.
It looks like a PDF. It runs like malware.
Your headphones are broadcasting more than music.
One fake text. Eight hours of stolen access.
Your smart camera scores 28 out of 100.
Name the feature each permission powers, or revoke it.
Defend account recovery from social engineering.
See how breached passwords fuel automated attacks.
Manage access rights through role transitions.
Keep access to the minimum your job requires.
Set up multi-factor authentication the right way.
Your phone buzzes for the thirtieth time. Then a Slack message says approve.
Build strong habits with your password manager.
Learn why admin accounts need special handling.
Learn why the padlock icon is not proof of safety.
Spot malicious downloads before they run.
Catch the domain tricks attackers use against you.
Hidden fields silently steal your autofilled data.
That helpful extension might be stealing everything.
That CAPTCHA was a trap for push spam.
Know when and how to report a security incident.
Build a team that reports without fear.
Audit who can see your shared files right now.
Control what external users can reach and for how long.
Stop sensitive data from leaking through chat apps.
Learn what not to post on corporate accounts.
See how attackers exploit your public profiles.
Check what you gave permission to access.
Spot the drop-in attendee, remove them, lock the meeting, file the report.
Think like an auditor to find compliance gaps.
Navigate GRC portals and submit audit evidence.
Know your personal security duties at work.
Connect ISO 27001 policies to your daily work.
Stay within corporate internet and email policies.
Label data correctly by sensitivity level.
Spot identity theft tactics targeting employees.
Share files safely without creating security gaps.
Stop sensitive data from leaving your org.
Production logs hold things you would never email out.
A black rectangle over text does not remove the text.
Use generative AI without leaking sensitive client data.
Recognize the warning signs of a malicious insider.
Find out what happens when teams use unapproved apps.
That image file might be carrying more than pixels.
One wrong attachment. Forty-seven salaries exposed.
One shortcut in Slack. Credentials everywhere.
Configure and use your VPN without leaving gaps.
Find out who else is on your home network.
Recognize personal data before you handle it.
Pick the lawful basis before the work starts.
The three reflexes that keep a small problem small.
Send the staff form twice: once wrong, once lawfully.
Build compliant opt-in flows that regulators accept.
Triage a breach and meet the 72-hour notification clock.
Evaluate a product feature through a privacy-first lens.
Process a data subject access request end to end.
Redact personal data from documents before disclosure.
Spot fake data access requests used for social engineering.
Evaluate a vendor's data processing controls before signing.
Coordinate security and privacy teams during a live breach.
Navigate transfer mechanisms for data leaving the EEA.
Run a DPIA for a high-risk data processing activity.
Build an Article 30 processing register from scratch.
Fix a cookie banner a regulator has already flagged.
Decide what to delete, retain, hold, or anonymize.
Take the privacy seat on a live ransomware bridge.
Earn the AI literacy required by Article 4 before touching company AI tools.
Sort real AI deployments into the four EU AI Act risk tiers.
Stop banned AI deployments before they go live.
Block a high-risk AI launch with compliance gaps in any of seven areas.
A compliant vendor product does not make your deployment compliant.
Label AI chatbots and synthetic media correctly under Article 50.
Override an AI loan recommendation when the evidence does not match.
Block AI training that uses a leaky, biased, or oversharing dataset.
Run a healthcare AI through both EU AI Act and GDPR at once.
Investigate proxy variables hiding inside a resume-screening model.
Run a FRIA before a social housing AI ever assigns a benefit decision.
Report a discriminatory AI rejection pattern under Article 62.
Build an AI registry and shut down shadow AI in your company.
Map GPAI provider and downstream deployer duties for systemic-risk models.
Make compliant AI choices through a normal working day.
Map the three-tier penalty structure to real enforcement scenarios.
An error message and one URL id are enough to read other people's records.
Customer records reach an outside vendor because a share link was too broad.
The clock starts at detection, not when you understand the leak.
One checkbox for five purposes is not consent to any of them.
The policy discloses everything and explains nothing.
The account is gone. The backup, the analytics profile, and the CRM are not.
A stale record stops being untidy once it decides someone's credit.
The last person to use this workstation is still logged in.
One person's data, one month, and no system that agrees who they are.
Every field you collect just in case is a field you have to protect.
Stop a hidden prompt from hijacking your AI assistant mid-task.
See what happens when confidential data enters a consumer AI tool.
Deploy an AI plugin that hides a backdoor in plain sight.
Watch poisoned documents corrupt your AI's answers in real time.
Exploit an AI whose outputs flow unchecked into live systems.
Manipulate an AI assistant into misusing its own permissions.
Extract hidden instructions from a customer-facing AI chatbot.
Exploit a RAG pipeline to access documents beyond your clearance.
Catch fabricated statistics and fake citations in an AI report.
Launch a denial-of-wallet attack against an unprotected AI API.
Spot the moment an AI agent's goal is quietly rewritten.
Catch the fraudulent items an agent's tools slip into your queue.
Find the agent that has been quietly widening its own access.
A backdoored MCP server mirrors every query your agents make.
Read the AI's pull request before you approve the reverse shell.
One poisoned memory entry keeps steering the agent for weeks.
Forge one message on an unauthenticated agent bus and it obeys.
One bad record, five agents, and a filed regulatory report.
Weeks of accurate approvals are the setup, not the reassurance.
Healthy metrics, clean output, one agent acting on its own.
Agents read tool descriptions as instructions, not as docs.
A semicolon in a tool argument becomes a shell command.
Text an agent reads is not a command it should obey.
Your client's server list is not what is actually listening.
Installing an MCP server runs its code before you read it.
Logging turned on today cannot recover yesterday.
Approving a server is not the same as authenticating it.
An agent reaches as far as its token, not its brief.
A token in your MCP config is a token your assistant reads.
When one agent serves many customers, its context is data.
Trace a real BEC scam built on weeks of inbox surveillance.
Relive the 10-minute helpdesk call that cost $100M.
Steal a click on a bank approval button.
Chain a second command onto a server-side tool.
Get code execution through an outdated library.
Move money from a page the victim never trusted.
Read system files through a download link.
Trigger XSS the server never sees.
Pull an employee PII export from an unlinked route.
Change one digit and read another customer.
Redirect a password-reset email to a lookalike domain.
Hide a phishing page behind a real login.
Pull production secrets from a forgotten debug route.
Lift personal data straight out of a link.
Craft a malicious URL that runs the moment it opens.
Make the server fetch its own cloud credentials.
Plant a session id and inherit the victim login.
Dump a database through one unguarded lookup form.
Plant a script in a comment and watch it fire.
Replay a session token harvested from a referrer log.
Harvest a verified customer list from a login form.
Forge a role claim and become an administrator.
Predict a password-reset token and take the account.
Read the password file through an XML upload.
Call staff-only endpoints from a read-only account.
Swap an id and read another rider.
Brute-force a six-digit login code.
Read the fields the UI never shows.
Read records through a retired API version.
Turn a search box into a full database read.
Look up a customer and leave no trace.
Mint a loyalty balance with two extra keys.
Read a signed-in account from any website.
Scrape a catalog with one oversized request.
Recover a live API key from the commit that removed it.
Rebuild an entire codebase from one public URL.
Clone a public repo and read its committed .env.
Land a backdoor wearing a maintainer’s name.
Force-push over main and skip review and CI.
Clone private repos with a token from a public gist.
Catch a backdoor hidden inside a friendly test fix.
Lift a deploy key straight out of a public build log.
List a bucket with no credentials and take the customer export.
Escalate a boring build credential into a full administrator.
Replay a key that leaked months ago and still authenticates.
Turn a URL-fetching feature into cloud credential theft.
Connect straight to a production database with no application in the path.
Serve your own login page from a domain the company really owns.
Investigate an incident where the trail covered one region and the intruder deleted the rest.
Drive a public function URL into an account-wide role.
Walk a sandbox credential into production, then put a ceiling above the account.
Read a live token out of a layer the build tried to clean up.
Turn a shell in a container into root on the host.
Take a production host through an unauthenticated Docker API.
Exploit a CVE in the OS layer nobody audits.
Trace a cryptominer back to one line in a Dockerfile.
Pull a private image, then replace the tag they deploy.
A port mapping puts a production database on the internet.
Cut a 412MB runtime down to what actually has to ship.
Try a different search term or adjust your filters to find what you're looking for.
Create your own interactive cyber hygiene exercises. Build custom email security simulations, credential theft scenarios, and threat awareness training. All for free.
Yes. Every exercise in our free library is fully playable with no sign-up, no email required, and no paywall. You get the same interactive 3D simulations used by enterprise customers.
The free library covers core attack types including phishing, ransomware, social engineering, vishing, smishing, and business email compromise. Enterprise features like analytics dashboards, SSO, and SCORM export require a paid plan.
Anyone who wants to improve their cybersecurity awareness. Individuals building personal security skills, students studying cybersecurity, small business owners training their teams, and IT administrators evaluating our platform before purchasing.
No sign-up is required. Each exercise takes 5 to 10 minutes and covers topics from basic phishing detection to AI prompt injection and deepfake whaling.
Most exercises take 5 to 10 minutes. Each one uses an interactive 3D simulation where you face a realistic cybersecurity scenario and make decisions at key points.
Wrong choices trigger immediate corrective feedback explaining what went wrong and why. According to National Training Laboratories research, practice-by-doing achieves 75% knowledge retention compared to 5% for lectures.
Over 200 exercises across four active categories, with Application Security, API Security, and Cloud Security launching soon. Security Awareness covers phishing, ransomware, social engineering, vishing, smishing, business email compromise, deepfake whaling, and USB drop attacks.
AI & LLM Security covers prompt injection, AI-powered phishing, deepfake voice cloning, plus the OWASP Top 10 for LLM Applications and OWASP Top 10 for Agentic Applications. Privacy & Compliance exercises address GDPR, data subject access requests, breach notification, cross-border transfers, and the OWASP Top 10 Privacy Risks. New exercises are added monthly.
Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.
We use a minimal set of cookies for analytics so we can understand how the site is used. Nothing is shared with advertisers. Privacy Policy.
Choose which cookies to allow. You can change this anytime from the footer.