AI Security Podcast

How to Hack AI Applications: Real-World Bug Bounty Insights


Listen Later

In this episode, we sit down with Joseph Thacker, a bug bounty hunter and AI security researcher, to uncover the evolving threat landscape of AI-powered applications and agents. Joseph shares battle-tested insights from real-world AI bug bounty programs, breaks down why AI AppSec is different from traditional AppSec, and reveals common vulnerabilities most companies miss, like markdown image exfiltration, XSS from LLM responses, and CSRF in chatbots.

He also discusses the rise of AI-driven pentesting agents ("hack bots"), their current limitations, and how augmented human hackers will likely outperform them, at least for now. If you're wondering whether AI can really secure or attack itself, or how AI is quietly reshaping the bug bounty and AppSec landscape, this episode is a must-listen.


Questions asked:

(00:00) Introduction

(02:14) A bit about Joseph

(03:57) What is AI AppSec?

(05:11) Components of AI AppSec

(08:20) Bug Bounty for AI Systems

(10:48) Common AI security issues

(15:09) How will AI change pentesting?

(20:23) How is the attacker landscape changing?

(22:33) Where would autimation add the most value?

(27:03) Is code being deployed less securely?

(32:56) AI Red Teaming

(39:21) MCP Security

(42:13) Evolution of pentest with AI


Resources shared during the interview:

- How to Hack AI Agents and Applications

- Critical Thinking Bug Bounty Podcast

- The Rise of AI Hackbots

- Shift - Caido Plugin

- Shadow Repeater

- Nuclei

- Haize Labs

- White Circle AI

- Prompt Injection Primer for Engineers

...more
View all episodesView all episodes
Download on the App Store

AI Security PodcastBy Kaizenteq Team

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

8 ratings


More shows like AI Security Podcast

View all
Risky Business by Patrick Gray

Risky Business

374 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

655 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,023 Listeners

NVIDIA AI Podcast by NVIDIA

NVIDIA AI Podcast

333 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,041 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

181 Listeners

Hacking Humans by N2K Networks

Hacking Humans

315 Listeners

Practical AI by Practical AI LLC

Practical AI

211 Listeners

Cloud Security Podcast by Cloud Security Podcast Team

Cloud Security Podcast

57 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

138 Listeners

The AI Daily Brief: Artificial Intelligence News and Analysis by Nathaniel Whittemore

The AI Daily Brief: Artificial Intelligence News and Analysis

610 Listeners

AI + a16z by a16z

AI + a16z

35 Listeners

Training Data by Sequoia Capital

Training Data

39 Listeners

The AI Security Podcast by Harriet Farlow (HarrietHacks)

The AI Security Podcast

0 Listeners