Security Unlocked

AI & the Hunt for Hidden Vulnerabilities with Tobias Diehl


Listen Later

In this episode of The BlueHat Podcast, host Nic Fillingham and Wendy Zenone are joined by security researcher Tobias Diehl, a top contributor to the Microsoft Security Research Center (MSRC) leaderboards and a Most Valuable Researcher. Tobias shares his journey from IT support to uncovering vulnerabilities in Microsoft products. He discusses his participation in the upcoming Zero Day Quest hacking challenge and breaks down a recent discovery involving Power Automate, where he identified a security flaw that could be exploited via malicious URLs. Tobias explains how developers can mitigate such risks and the importance of strong proof-of-concept submissions in security research. 



In This Episode You Will Learn


  • Researching vulnerabilities in Power Automate, Power Automate Desktop, and Azure
  • The importance of user prompts to prevent unintended application behavior
  • Key vulnerabilities Tobias looks for when researching Microsoft products


Some Questions We Ask:


  • Have you submitted any AI-related findings to Microsoft or other bug bounty programs?
  • How does the lack of visibility into AI models impact the research process?
  • Has your approach to security research changed when working with AI versus traditional systems?

  

Resources:     

View Tobias Diehl on LinkedIn  

View Wendy Zenone on LinkedIn  

View Nic Fillingham on LinkedIn 



Related Microsoft Podcasts:  

 

  • Microsoft Threat Intelligence Podcast  
  • Afternoon Cyber Tea with Ann Johnson  
  • Uncovering Hidden Risks  



Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

Hosted on Acast. See acast.com/privacy for more information.

...more
View all episodesView all episodes
Download on the App Store

Security UnlockedBy Microsoft

  • 4
  • 4
  • 4
  • 4
  • 4

4

56 ratings


More shows like Security Unlocked

View all
Security Now (Audio) by TWiT

Security Now (Audio)

1,971 Listeners

Risky Business by Patrick Gray

Risky Business

361 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

628 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

367 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,007 Listeners

Smashing Security by Graham Cluley & Carole Theriault

Smashing Security

311 Listeners

Click Here by Recorded Future News

Click Here

406 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,864 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

169 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

187 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

128 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

33 Listeners

The BlueHat Podcast by Microsoft

The BlueHat Podcast

12 Listeners