Research what attackers see.
Build what defenders need.
Security research should go beyond theory. TMG Security develops practical research environments, vulnerable applications and security labs designed to help security professionals explore modern attack surfaces in controlled environments.
CONCEPTUAL DIAGRAM · ILLUSTRATIVE, NOT LIVE DATA
Learn security by breaking realistic systems.
TMG Security Labs are designed as controlled environments for security testing, vulnerability research and practical learning. Each lab focuses on a different attack surface and is designed to help researchers understand how vulnerabilities appear, how they can be investigated and how secure implementations should behave.
TMG AI Security Lab
For Penetration Testers & Security Researchers
A practical environment focused on exploring security weaknesses across modern AI and LLM-powered systems. Described in the project as a locally-runnable, intentionally vulnerable AI / LLM / agentic security training environment, built as a hands-on companion to TMG Security's AI / LLM Penetration Testing & Bug Bounty course.
IMPLEMENTED COVERAGE
- OWASP LLM Top 10 (2025) — all ten
- OWASP Agentic AI ASI01–ASI10 — all ten
- Prompt injection
- System prompt leakage
- Sensitive information disclosure
- Data & model poisoning
- Vector & embedding weaknesses
- Improper output handling
- Unbounded consumption
- Misinformation
- Excessive agency
- Agent goal hijacking
- Tool misuse
- Identity & privilege abuse
- Memory & context poisoning
- Agentic supply chain
- Unexpected code execution
- Insecure inter-agent communication
- Cascading failures
- Human-agent trust exploitation
- Rogue agents
Also includes Bug Bounty Mode (an unguided target with no hints or category labels), a structured vulnerability reporting module, a local leaderboard and an instructor mode.
ACCESS THE LABTMG Vulnerable Web Application Lab
For Web Pentesters & Bug Bounty Researchers
A controlled vulnerable web application environment designed for practical web application security testing and vulnerability research, focused on realistic web application attack surfaces.
The vulnerability coverage for this environment has not been finalised, so none is listed here. It will be published once the lab is built.
REGISTER INTERESTTMG Vulnerable API Lab
For API Security Testers
A controlled environment designed to help security professionals explore API security weaknesses and understand how modern APIs can become part of an organization's attack surface.
The vulnerability coverage for this environment has not been finalised, so none is listed here. It will be published once the lab is built.
REGISTER INTERESTTMG Application Security Lab
For Security Engineers & Researchers
A practical application-security environment focused on understanding vulnerabilities across modern application workflows, integrations and security controls.
The vulnerability coverage for this environment has not been finalised, so none is listed here. It will be published once the lab is built.
REGISTER INTERESTONE LAB IS BUILT AND RUNNING · THE OTHER THREE ARE IN DEVELOPMENT AND THEIR SCOPE IS NOT YET PUBLISHED · STATUS ON EACH CARD IS ACCURATE
Explore the surfaces attackers look for.
Select a surface to see which lab environment covers it. Surfaces without a lab yet are shown as such rather than mapped to something that does not exist.
Every lab starts from research into how a surface is actually attacked, and ends in an environment where that behaviour can be reproduced safely.
IDENTITY, CLOUD and DATA are surfaces TMG Security works across in its services practices. They do not have a dedicated lab environment yet.
Realistic environments. Controlled research.
PRACTICAL
Learn through realistic environments rather than theory alone.
CONTROLLED
Explore vulnerabilities within intentionally designed environments.
RESEARCH-DRIVEN
Labs evolve around modern security problems and attack surfaces.
DEFENSIVE CONTEXT
Understand not only how vulnerabilities occur, but why secure design matters.
How a weakness becomes understanding.
The same five steps whether the surface is a web application, an API or an AI agent.
IDENTIFY
Research an attack surface.
REPRODUCE
Investigate the behavior in a controlled lab.
UNDERSTAND
Analyze why the weakness exists.
VALIDATE
Understand the security impact.
REMEDIATE
Study the secure design or defensive control.
What starting a lab session looks like.
An illustration of the sequence a research environment goes through as it comes up: initializing the environment, loading lab definitions, mapping the attack surface, analyzing application behavior, evaluating security controls, ready. The panel below is scripted for this page — it is not connected to a running system.
The formats research gets published in.
These are the formats TMG Security research will be published in. Nothing has been published yet, so nothing is listed — the cards below describe the format, not an article.
Research Report
Long-form research write-ups on attack surfaces TMG Security works across.
Security Advisory
Structured advisories covering issues found during research work.
Technical Blog
Shorter technical pieces on tooling, methodology and modern attack surfaces.
Vulnerability Research
Deeper vulnerability research from the labs and from client-facing work.
The archive is ready. The shelves are not full yet.
Filtering works. There is simply nothing published to filter — and we would rather show you that honestly than fill the page with placeholder articles.
There is no published research in ALL yet. TMG Security research is in progress; this archive will fill as reports, advisories and technical write-ups are released.
Want access to a TMG Security Lab?
Our labs are designed for controlled security research and practical learning. Tell us which environment you're interested in and the TMG Security team can help with access and next steps.
Research is where the next engagement starts.
Whether you want lab access, want to talk about a surface we have been researching, or need the same thinking applied to your own environment — start with the problem.
