AI CyberSecurity Podcast

How to Hack AI Applications: Real-World Bug Bounty Insights


Listen Later

In this episode, we sit down with Joseph Thacker, a bug bounty hunter and AI security researcher, to uncover the evolving threat landscape of AI-powered applications and agents. Joseph shares battle-tested insights from real-world AI bug bounty programs, breaks down why AI AppSec is different from traditional AppSec, and reveals common vulnerabilities most companies miss, like markdown image exfiltration, XSS from LLM responses, and CSRF in chatbots.

He also discusses the rise of AI-driven pentesting agents ("hack bots"), their current limitations, and how augmented human hackers will likely outperform them, at least for now. If you're wondering whether AI can really secure or attack itself, or how AI is quietly reshaping the bug bounty and AppSec landscape, this episode is a must-listen.


Questions asked:

(00:00) Introduction

(02:14) A bit about Joseph

(03:57) What is AI AppSec?

(05:11) Components of AI AppSec

(08:20) Bug Bounty for AI Systems

(10:48) Common AI security issues

(15:09) How will AI change pentesting?

(20:23) How is the attacker landscape changing?

(22:33) Where would autimation add the most value?

(27:03) Is code being deployed less securely?

(32:56) AI Red Teaming

(39:21) MCP Security

(42:13) Evolution of pentest with AI


Resources shared during the interview:

- How to Hack AI Agents and Applications

- Critical Thinking Bug Bounty Podcast

- The Rise of AI Hackbots

- Shift - Caido Plugin

- Shadow Repeater

- Nuclei

- Haize Labs

- White Circle AI

- Prompt Injection Primer for Engineers

...more
View all episodesView all episodes
Download on the App Store

AI CyberSecurity PodcastBy Kaizenteq Team

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

4 ratings


More shows like AI CyberSecurity Podcast

View all
Risky Business by Patrick Gray

Risky Business

361 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

630 Listeners

The Cloudcast by Massive Studios

The Cloudcast

153 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

369 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,008 Listeners

Smashing Security by Graham Cluley & Carole Theriault

Smashing Security

313 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

162 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

188 Listeners

Practical AI by Practical AI LLC

Practical AI

189 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

76 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

118 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

33 Listeners

AI Applied: Covering AI News, Interviews and Tools - ChatGPT, Midjourney, Gemini, OpenAI, Anthropic by Jaeden Schafer and Conor Grennan

AI Applied: Covering AI News, Interviews and Tools - ChatGPT, Midjourney, Gemini, OpenAI, Anthropic

124 Listeners

Latent Space: The AI Engineer Podcast by swyx + Alessio

Latent Space: The AI Engineer Podcast

63 Listeners

The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis by Nathaniel Whittemore

The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis

422 Listeners