AI CyberSecurity Podcast cover image

AI CyberSecurity Podcast

How to Hack AI Applications: Real-World Bug Bounty Insights

Apr 5, 2025
Join bug bounty hunter Joseph Thacker, who specializes in AI security, as he demystifies the evolving landscape of AI-powered applications. He shares real-world insights on unique vulnerabilities, like markdown image exfiltration and XSS in LLM responses. Discover why AI AppSec differs from traditional AppSec and how augmented human hackers currently outperform automated tools. Joseph also discusses the rise of hack bots and their limitations, offering a fascinating glimpse into the future of AI in cybersecurity.
50:29

Episode guests

Podcast summary created with Snipd AI

Quick takeaways

  • AI security differs from traditional security by introducing unique vulnerabilities like prompt injection, necessitating specialized knowledge for effective protection.
  • The limitations of current AI-driven pentesting tools highlight the continued necessity for human experts to identify and address security gaps.

Deep dives

AI Pen Testing Limitations

While AI pen testing tools are expected to enhance the process of vulnerability detection, they currently fall short in identifying vulnerabilities at scale. Many experts believe that these tools struggle to find even a small percentage of existing vulnerabilities, making human pen testers vital for effective security assessments. The augmentation of human capabilities with AI technology may eventually lead to more efficient and comprehensive testing. For now, relying solely on AI for pen testing could leave significant security gaps.

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner