New Content & Platform Update
Feature Update: AI Lab Builder
Release date: September 3rd, 2026
Smarter generation, file upload, an undo button, and a massively upgraded briefing editor.
We've shipped a big update to AI Lab Builder - sharpening the AI itself, giving it file upload and allowing authors to have far more control over how labs look and read.
This update improves our core artificial intelligence model to deliver higher-quality, more reliable lab content aligned with your intent, and introduces a built-in file upload feature. Authors can now upload files – such as security policies, frameworks, or binaries – so the AI can automatically build relevant content around real-world artifacts. We have also introduced a revert safety net to undo changes and easily step back to earlier versions.
In addition, we have overhauled the briefing editor with a rich formatting toolkit and pre-built templates. Authors and the AI can now structure briefings using horizontal rules, tables, cards, callout boxes, alert banners, and hover-definition acronym tags. These proven, learner-tested building blocks standardise sections like pre-requisites, detection indicators, and real-world examples across your catalogue.
Note: While the AI can generate end-to-end theory labs and edit all non-machine elements, it cannot currently create or edit practical machines.
Who are we doing it for
This release is for all content authors, instructional designers, and subject matter experts (SMEs) building custom learning content on the Immersive One platform. It also benefits junior learners and cybersecurity professionals taking these labs, as well as platform administrators looking to reduce user support tickets.
Licensing remains unchanged, and the enhanced briefing components are available to all customers immediately. To access the AI assistant features, administrators simply need to enable AI in their platform settings.
Why are we doing it now
We are releasing this now to transform lab authoring from time-consuming, freeform formatting into assembling consistent, high-quality content quickly. Custom content creation often presents formatting challenges, leading to plain walls of text or visual inconsistencies.
New collection release: Introduction to the AI Supply Chain
Release date: September 3rd, 2026
We have launched the first collection in our AI pipeline series: “Introduction to the AI Supply Chain”. This collection breaks down the four primary architectural layers of modern artificial intelligence (AI) implementations and highlights the hidden security vulnerabilities within each layer. You will explore the evolving threat landscape and gain practical knowledge of key security controls necessary to protect your machine learning (ML) environments. This foundational collection serves as the entry point for our broader AI defense curriculum and will be followed by the “Securing the Supply Chain” collection, featuring practical labs and supporting Crisis Simulation content.
Why are we doing it now
Software supply chain attacks targeting developer environments and continuous integration and continuous delivery (CI/CD) pipelines are an established threat, but the assets moving through these pipelines have changed drastically with the rise of AI. Traditional AppSec tools and standard software bill of materials (SBOM) frameworks are blind to poisonings in neural network weights, serialized code execution, and hijacked registry namespaces. Threat actors no longer need complex zero-day exploits; they can simply slip malicious code into trusted ML models or developer tools to bypass perimeter defenses. We are releasing this collection now to help you strip away the “black box” mystique of AI pipeline vulnerabilities and implement concrete, actionable security controls across your architecture.
Who are we doing it for
This feature is designed for application security (AppSec) engineers, security architects, software developers, and technical cybersecurity teams who build, deploy, or secure modern AI architectures and software development pipelines.
Link to the collection: here
Availability: Core license
New collection release: OWASP Agentic Skills Top 10 (2026)
Release date: September 3rd, 2026
We are releasing a brand-new theory collection covering the complete OWASP Agentic Skills Top 10. This foundational track breaks down all ten risk categories—from Critical threats like Malicious Skills (AST01) and Supply Chain Compromises (AST02) to operational risks like Update Drift (AST07) and Cross-Platform Reuse (AST10). While this is a knowledge-based collection rather than a hands-on lab, it provides the exact framework teams need to understand, classify, and mitigate vulnerabilities in AI agent ecosystems.
Why are we doing it now
As autonomous AI agents are integrated into enterprise workflows, they introduce a dual-layer attack surface. Unlike traditional software packages, agentic skills can be exploited through both standard code execution and the natural language instruction layer (like markdown prose). With active threat campaigns already successfully publishing malicious skills to public registries to steal credentials and inject backdoors, traditional application security scanners are largely blind to these new vectors.
This collection acts as the perfect prerequisite to our hands-on AI and LLM security content. It is an excellent technical module to drop straight into your AI governance, secure AI development, or threat modeling training paths, giving your teams the necessary vocabulary and theoretical foundation before they tackle our practical AI exploitation labs.
Who is this for
Governance, AppSec, and AI development teams need a structural understanding of this threat landscape before they begin deploying or approving agent frameworks.
Link to the collection: here
Availability: This collection is available to all customers on all tiers, and is available now!