
DEF CON 33 - Designing and Participating in AI Bug Bounty Programs - Dane Sherrets, Shlomie Liberow
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 51:53
The video discusses how hackers are compromising AI systems and how bug bounty programs can address these vulnerabilities 0:03-0:07. The speakers, both bug bounty hunters with experience in AI security, explain the distinction between AI security (protecting systems from external threats) and AI safety (protecting users from AI system flaws) 5:57-6:46.
Key Takeaways:
• Traditional web2 vulnerabilities still affect AI systems, as demonstrated by exposed GitHub tokens and AWS credentials in a crypto AI agent platform 13:57-14:46
• AI bias identification can be valuable, shown through a Department of Defense bug bounty that found biases affecting military personnel 20:35-22:05
• Prompt injection can manipulate AI agents, demonstrated by tricking an agent into posting a user's password on Instagram 34:00-37:38
The speakers emphasize that AI systems face many of the same security challenges as traditional systems, requiring comprehensive testing through bug bounty programs 19:52-20:12.
Sources:
- 0:03-0:07 Introduction to securing AI systems
- 5:57-6:46 AI security vs AI safety definitions
- 13:57-14:46 Exposed credentials vulnerability
- 20:35-22:05 Department of Defense bias identification
- 34:00-37:38 Prompt injection example with Instagram
- 19:52-20:12 Conclusion on security challenges
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
All right, thank you everyone for making time for today's talk, securing intelligence, how hackers are breaking modern AI systems and how bug bounty programs can keep up. We uh we worked really hard. We made a beautiful slide presentation for all of you and I'm the kind of person that likes to like practice before I do a talk and I want everyone to know I got my talk down to like 10 seconds of where I want it to be. But as you can see now, uh we actually have AV problems and we're not going to be able to use the slides. So, we're making a last minute pivot here and we're gonna make this more of a fireside chat, but still like walk through the actual content and uh I think it'll be great and probably a little more fun, interactive, and uh we'll maybe get some more questions. Uh so, the actu…