AI Security Podcast

How to Hack AI Applications: Real-World Bug Bounty Insights

17 snips
Apr 5, 2025
Join bug bounty hunter Joseph Thacker, who specializes in AI security, as he demystifies the evolving landscape of AI-powered applications. He shares real-world insights on unique vulnerabilities, like markdown image exfiltration and XSS in LLM responses. Discover why AI AppSec differs from traditional AppSec and how augmented human hackers currently outperform automated tools. Joseph also discusses the rise of hack bots and their limitations, offering a fascinating glimpse into the future of AI in cybersecurity.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Augmented Hackers vs. Hackbots

  • AI-driven pentesting agents (hackbots) are evolving but currently limited.
  • Augmented human hackers, assisted by AI, will outperform fully autonomous hackbots for now.
INSIGHT

AI AppSec vs. AI Model Security

  • AI AppSec focuses on securing applications that use AI models, not just the models themselves.
  • Common vulnerabilities like XSS and CSRF still exist but manifest differently in AI apps.
ANECDOTE

Bug Bounty Programs for AI

  • Joseph Thacker participates in bug bounty programs for AI systems, both for foundational models and applications.
  • Most of his work focuses on application security testing of AI features within existing systems.
Get the Snipd Podcast app to discover more snips from this episode
Get the app