12 subscribers
Go offline with the Player FM app!
Podcasts Worth a Listen
SPONSORED


1 You're not supposed to be here and other Dad wisdom 29:22
AI & the Hunt for Hidden Vulnerabilities with Tobias Diehl
Manage episode 474735021 series 3486243
In this episode of The BlueHat Podcast, host Nic Fillingham and Wendy Zenone are joined by security researcher Tobias Diehl, a top contributor to the Microsoft Security Research Center (MSRC) leaderboards and a Most Valuable Researcher. Tobias shares his journey from IT support to uncovering vulnerabilities in Microsoft products. He discusses his participation in the upcoming Zero Day Quest hacking challenge and breaks down a recent discovery involving Power Automate, where he identified a security flaw that could be exploited via malicious URLs. Tobias explains how developers can mitigate such risks and the importance of strong proof-of-concept submissions in security research.
In This Episode You Will Learn:
- Researching vulnerabilities in Power Automate, Power Automate Desktop, and Azure
- The importance of user prompts to prevent unintended application behavior
- Key vulnerabilities Tobias looks for when researching Microsoft products
Some Questions We Ask:
- Have you submitted any AI-related findings to Microsoft or other bug bounty programs?
- How does the lack of visibility into AI models impact the research process?
- Has your approach to security research changed when working with AI versus traditional systems?
Resources:
View Nic Fillingham on LinkedIn
Related Microsoft Podcasts:
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
The BlueHat Podcast is produced by Microsoft and distributed as part of N2K media network.
54 episodes
Manage episode 474735021 series 3486243
In this episode of The BlueHat Podcast, host Nic Fillingham and Wendy Zenone are joined by security researcher Tobias Diehl, a top contributor to the Microsoft Security Research Center (MSRC) leaderboards and a Most Valuable Researcher. Tobias shares his journey from IT support to uncovering vulnerabilities in Microsoft products. He discusses his participation in the upcoming Zero Day Quest hacking challenge and breaks down a recent discovery involving Power Automate, where he identified a security flaw that could be exploited via malicious URLs. Tobias explains how developers can mitigate such risks and the importance of strong proof-of-concept submissions in security research.
In This Episode You Will Learn:
- Researching vulnerabilities in Power Automate, Power Automate Desktop, and Azure
- The importance of user prompts to prevent unintended application behavior
- Key vulnerabilities Tobias looks for when researching Microsoft products
Some Questions We Ask:
- Have you submitted any AI-related findings to Microsoft or other bug bounty programs?
- How does the lack of visibility into AI models impact the research process?
- Has your approach to security research changed when working with AI versus traditional systems?
Resources:
View Nic Fillingham on LinkedIn
Related Microsoft Podcasts:
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
The BlueHat Podcast is produced by Microsoft and distributed as part of N2K media network.
54 episodes
All episodes
×
1 From Facebook-phished to MVR Top 5 with Dhiral Patel 41:45

1 AI & the Hunt for Hidden Vulnerabilities with Tobias Diehl 35:25

1 Bug Hunting from the Beach with Brad Schlintz 38:43

1 PoCs, Patching and Zero Day Quest Participation with Michael Gorelik 46:25

1 Secret Herbs, Spices and Hacking Copilot Studio 43:58

1 Automating Dynamic Application Security Testing at Scale 45:56

1 Refactoring the Windows Kernel with Joe Bialek 47:14

1 Defending Against NTLM Relay Attacks with Rohit Mothe and George Hughey 40:08

1 Navigating AI Safety and Security Challenges with Yonatan Zunger [Encore] 53:34

1 Johann Rehberger on Researching AI & LLM Attacks 49:20

1 BlueHat 2024 Day 2 Keynote: Amanda Silver, CVP Microsoft Developer Division 45:42

1 BlueHat 2024 Day 1 Keynote: Chris Wysopal AKA Weld Pond 47:50

1 From Software to Security: Arjun Gopalakrishna’s Journey at Microsoft 43:01
Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.