DEF CON 33 - Designing and Participating in AI Bug Bounty Programs - Dane Sherrets, Shlomie Liberow

DEF CON 33 - Designing and Participating in AI Bug Bounty Programs - Dane Sherrets, Shlomie Liberow

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 51:53

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video discusses how hackers are compromising AI systems and how bug bounty programs can address these vulnerabilities 0:03-0:07. The speakers, both bug bounty hunters with experience in AI security, explain the distinction between AI security (protecting systems from external threats) and AI safety (protecting users from AI system flaws) 5:57-6:46.

Key Takeaways:
• Traditional web2 vulnerabilities still affect AI systems, as demonstrated by exposed GitHub tokens and AWS credentials in a crypto AI agent platform 13:57-14:46
• AI bias identification can be valuable, shown through a Department of Defense bug bounty that found biases affecting military personnel 20:35-22:05
• Prompt injection can manipulate AI agents, demonstrated by tricking an agent into posting a user's password on Instagram 34:00-37:38

The speakers emphasize that AI systems face many of the same security challenges as traditional systems, requiring comprehensive testing through bug bounty programs 19:52-20:12.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right, thank you everyone for making time for today's talk, securing intelligence, how hackers are breaking modern AI systems and how bug bounty programs can keep up. We uh we worked really hard. We made a beautiful slide presentation for all of you and I'm the kind of person that likes to like practice before I do a talk and I want everyone to know I got my talk down to like 10 seconds of where I want it to be. But as you can see now, uh we actually have AV problems and we're not going to be able to use the slides. So, we're making a last minute pivot here and we're gonna make this more of a fireside chat, but still like walk through the actual content and uh I think it'll be great and probably a little more fun, interactive, and uh we'll maybe get some more questions. Uh so, the actu…