In this episode of the Microsoft Threat Intelligence Podcast host Sherrod DeGrippo is joined by Technical Program Manager at Microsoft Lynn Miyashita and Principal Research Manager, Andrew Paverd. They discuss the evolution of bug bounty programs into the realm of artificial intelligence, specifically focusing on Microsoft's initiative launched in October 2023. Lynn explains that the AI Bug Bounty incentivizes external security researchers to discover and report vulnerabilities in Microsoft's AI systems, such as Copilot, across various platforms including web browsers and mobile applications. Andrew elaborates on the concept of a "bug bar," which sets the criteria for vulnerabilities eligible for the program. They emphasize the importance of identifying security issues that could arise uniquely from AI systems, such as prompt injection vulnerabilities. The discussion highlights Microsoft's structured approach to handling reported vulnerabilities through their Security Response Center, emphasizing quick mitigation and coordination with researchers to ensure timely fixes and public disclosure.\xa0\n\xa0\xa0\n\nIn this episode you\u2019ll learn:\xa0\xa0\xa0\xa0\xa0\xa0\n\xa0\xa0\n\nHow AI Bug Bounty programs are reshaping traditional security practices\xa0\n\nDangers of prompt injection attacks, and their capacity to exfiltrate sensitive data\xa0\n\nWhy you should engage in AI bug hunting and contribute to the evolving security landscape\xa0\n\n\xa0\n\nSome questions we ask:\xa0\xa0\xa0\xa0\xa0\n\xa0\xa0\n\nWhich products are currently included in the Bug Bounty program?\xa0\n\nShould traditional bug bounty hunters start doing AI bug bounty hunting?\xa0\n\nHow can someone get started with AI bug hunting and submitting to your program?\xa0\n\n\xa0\n\xa0\n\nResources:\xa0\xa0\nView Lynn Miyashita on LinkedIn\xa0\xa0\nView Andrew Paverd on LinkedIn\xa0\xa0\nView Sherrod DeGrippo on LinkedIn\xa0\xa0\n\xa0\nMicrosoft AI Bug Bounty Program\xa0\n\xa0\n\xa0\n\nRelated Microsoft Podcasts:\xa0\xa0\xa0\xa0\xa0\xa0\xa0\xa0\xa0\xa0\xa0\xa0\xa0\xa0\xa0\xa0\xa0\xa0\xa0\n\n\nAfternoon Cyber Tea with Ann Johnson\xa0\n\n\nThe BlueHat Podcast\xa0\n\n\nUncovering Hidden Risks\xa0\xa0\xa0\xa0\xa0\n\n\xa0\n\xa0\nDiscover and follow other Microsoft podcasts at microsoft.com/podcasts\xa0\xa0\n\xa0\nGet the latest threat intelligence insights and guidance at Microsoft Security Insider\xa0\n\xa0\n\xa0\nThe Microsoft Threat Intelligence Podcast is produced by Microsoft and distributed as part of N2K media network.