Microsoft Threat Intelligence Podcast

Hunting for AI Bug Bounty


Listen Later

In this episode of the Microsoft Threat Intelligence Podcast host Sherrod DeGrippo is joined by Technical Program Manager at Microsoft Lynn Miyashita and Principal Research Manager, Andrew Paverd. They discuss the evolution of bug bounty programs into the realm of artificial intelligence, specifically focusing on Microsoft's initiative launched in October 2023. Lynn explains that the AI Bug Bounty incentivizes external security researchers to discover and report vulnerabilities in Microsoft's AI systems, such as Copilot, across various platforms including web browsers and mobile applications. Andrew elaborates on the concept of a "bug bar," which sets the criteria for vulnerabilities eligible for the program. They emphasize the importance of identifying security issues that could arise uniquely from AI systems, such as prompt injection vulnerabilities. The discussion highlights Microsoft's structured approach to handling reported vulnerabilities through their Security Response Center, emphasizing quick mitigation and coordination with researchers to ensure timely fixes and public disclosure. 

  

In this episode you’ll learn:      

  

  • How AI Bug Bounty programs are reshaping traditional security practices 
  • Dangers of prompt injection attacks, and their capacity to exfiltrate sensitive data 
  • Why you should engage in AI bug hunting and contribute to the evolving security landscape 
  •  

    Some questions we ask:     

      

    • Which products are currently included in the Bug Bounty program? 
    • Should traditional bug bounty hunters start doing AI bug bounty hunting? 
    • How can someone get started with AI bug hunting and submitting to your program? 
    •  

       

      Resources:  

      View Lynn Miyashita on LinkedIn  

      View Andrew Paverd on LinkedIn  

      View Sherrod DeGrippo on LinkedIn  

       

      Microsoft AI Bug Bounty Program 

       

       

      Related Microsoft Podcasts:                   
      • Afternoon Cyber Tea with Ann Johnson 
      • The BlueHat Podcast 
      • Uncovering Hidden Risks     

         

         

        Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

         

        Get the latest threat intelligence insights and guidance at Microsoft Security Insider 

         

         

        The Microsoft Threat Intelligence Podcast is produced by Microsoft and distributed as part of N2K media network.  

        ...more
        View all episodesView all episodes
        Download on the App Store

        Microsoft Threat Intelligence PodcastBy Microsoft

        • 5
        • 5
        • 5
        • 5
        • 5

        5

        21 ratings


        More shows like Microsoft Threat Intelligence Podcast

        View all
        Hacked by Hacked

        Hacked

        184 Listeners

        Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

        Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

        369 Listeners

        Risky Business by Patrick Gray

        Risky Business

        374 Listeners

        SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

        SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

        637 Listeners

        CyberWire Daily by N2K Networks

        CyberWire Daily

        1,016 Listeners

        Smashing Security by Graham Cluley

        Smashing Security

        322 Listeners

        Click Here by Recorded Future News

        Click Here

        416 Listeners

        Darknet Diaries by Jack Rhysider

        Darknet Diaries

        8,000 Listeners

        Cybersecurity Today by Jim Love

        Cybersecurity Today

        175 Listeners

        Hacking Humans by N2K Networks

        Hacking Humans

        314 Listeners

        CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

        CISO Series Podcast

        188 Listeners

        Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

        Defense in Depth

        73 Listeners

        Cyber Security Headlines by CISO Series

        Cyber Security Headlines

        134 Listeners

        Risky Bulletin by risky.biz

        Risky Bulletin

        44 Listeners

        Hacker And The Fed by Chris Tarbell & Hector Monsegur

        Hacker And The Fed

        168 Listeners