<description>&lt;p&gt;Episode 152: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Sasi Levi from Noma Security to talk about AI and Agentic Security. We also talk about ForcedLeak, a Google Vertex Bug, and debate if Prompt Injection is a real Vuln.&lt;/p&gt;&lt;p&gt;Follow us on twitter at: &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/ctbbpodcast"&gt;https://x.com/ctbbpodcast&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Got any ideas and suggestions? Feel free to send us any feedback here: &lt;a target="_blank" rel="noopener noreferrer nofollow" href="mailto:info@criticalthinkingpodcast.io"&gt;info@criticalthinkingpodcast.io&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Shoutout to&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://twitter.com/realytcracker"&gt; YTCracker&lt;/a&gt; for the awesome intro music!&lt;/p&gt;&lt;p&gt;====== Links ======&lt;/p&gt;&lt;p&gt;Follow your hosts Rhynorater, rez0 and gr3pme on X: &lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/Rhynorater"&gt;https://x.com/Rhynorater&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/rez0__"&gt;https://x.com/rez0__&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/gr3pme"&gt;https://x.com/gr3pme&lt;/a&gt;&lt;/p&gt;&lt;p&gt;====== Ways to Support CTBBPodcast ======&lt;/p&gt;&lt;p&gt;Hop on the CTBB Discord at &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/discord"&gt;https://ctbb.show/discord&lt;/a&gt;!&lt;/p&gt;&lt;p&gt;We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.&lt;/p&gt;&lt;p&gt;CHeck out our New Christmas Swag at &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/merch"&gt;https://ctbb.show/merch&lt;/a&gt;!&lt;/p&gt;&lt;p&gt;Today's Sponsor: ThreatLocker. Check out ThreatLocker Elevation Control&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/tl-ec"&gt;https://ctbb.show/tl-ec&lt;/a&gt;&lt;/p&gt;&lt;p&gt;And Noma Security! &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://noma.security/"&gt;https://noma.security/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Today’s Guest: &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/sasi2103"&gt;https://x.com/sasi2103&lt;/a&gt;&lt;/p&gt;&lt;p&gt;====== This Week in Bug Bounty ======&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://hackerone.com/vercel_platform_protection?type=team"&gt;Vercel Platform Protection&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/cramforce/status/1998072892391592195?s=20"&gt;Dedicated HackerOne program for Vercel WAF&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://yeswehack.com/programs?scopeType%5B%5D=open-source&amp;amp;page=1"&gt;YesWeHack Open Source Programs&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://www.yeswehack.com/learn-bug-bounty/android-recon-bug-bounty-guide"&gt;Android recon for Bug Bounty hunters&lt;/a&gt;&lt;/p&gt;&lt;p&gt;====== Resources ======&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/sasi2103/status/608349038778437632"&gt;Sasi's Tweet from 2015&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://noma.security/blog/forcedleak-agent-risks-exposed-in-salesforce-agentforce/"&gt;ForcedLeak: AI Agent risks exposed in Salesforce AgentForce&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://danielmiessler.com/blog/is-prompt-injection-a-vulnerability"&gt;Is Prompt Injection a Vulnerability?&lt;/a&gt;&lt;/p&gt;&lt;p&gt;====== Timestamps ======&lt;/p&gt;&lt;p&gt;(00:00:00) Introduction&lt;/p&gt;&lt;p&gt;(00:09:16) Google Vertex AI Bug&lt;/p&gt;&lt;p&gt;(00:29:28) Sasi's Background and Bug Bounty Journey&lt;/p&gt;&lt;p&gt;(00:38:55) Resources for AI and Agentic Security Methodology&lt;/p&gt;&lt;p&gt;(00:50:34) ForcedLeak&lt;/p&gt;&lt;p&gt;(01:02:06) Is Prompt Injection a Vuln?&lt;/p&gt;</description>

Critical Thinking - Bug Bounty Podcast

Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)

Episode 152: GeminiJack and Agentic Security with Sasi Levi

DEC 11, 202581 MIN
Critical Thinking - Bug Bounty Podcast

Episode 152: GeminiJack and Agentic Security with Sasi Levi

DEC 11, 202581 MIN

Description

<p>Episode 152: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Sasi Levi from Noma Security to talk about AI and Agentic Security. We also talk about ForcedLeak, a Google Vertex Bug, and debate if Prompt Injection is a real Vuln.</p><p>Follow us on twitter at: <a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/ctbbpodcast">https://x.com/ctbbpodcast</a></p><p>Got any ideas and suggestions? Feel free to send us any feedback here: <a target="_blank" rel="noopener noreferrer nofollow" href="mailto:[email protected]">[email protected]</a></p><p>Shoutout to<a target="_blank" rel="noopener noreferrer nofollow" href="https://twitter.com/realytcracker"> YTCracker</a> for the awesome intro music!</p><p>====== Links ======</p><p>Follow your hosts Rhynorater, rez0 and gr3pme on X: </p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/Rhynorater">https://x.com/Rhynorater</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/rez0__">https://x.com/rez0__</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/gr3pme">https://x.com/gr3pme</a></p><p>====== Ways to Support CTBBPodcast ======</p><p>Hop on the CTBB Discord at <a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/discord">https://ctbb.show/discord</a>!</p><p>We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.</p><p>CHeck out our New Christmas Swag at <a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/merch">https://ctbb.show/merch</a>!</p><p>Today's Sponsor: ThreatLocker. Check out ThreatLocker Elevation Control</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/tl-ec">https://ctbb.show/tl-ec</a></p><p>And Noma Security! <a target="_blank" rel="noopener noreferrer nofollow" href="https://noma.security/">https://noma.security/</a></p><p>Today’s Guest: <a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/sasi2103">https://x.com/sasi2103</a></p><p>====== This Week in Bug Bounty ======</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://hackerone.com/vercel_platform_protection?type=team">Vercel Platform Protection</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/cramforce/status/1998072892391592195?s=20">Dedicated HackerOne program for Vercel WAF</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://yeswehack.com/programs?scopeType%5B%5D=open-source&amp;page=1">YesWeHack Open Source Programs</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.yeswehack.com/learn-bug-bounty/android-recon-bug-bounty-guide">Android recon for Bug Bounty hunters</a></p><p>====== Resources ======</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/sasi2103/status/608349038778437632">Sasi's Tweet from 2015</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://noma.security/blog/forcedleak-agent-risks-exposed-in-salesforce-agentforce/">ForcedLeak: AI Agent risks exposed in Salesforce AgentForce</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://danielmiessler.com/blog/is-prompt-injection-a-vulnerability">Is Prompt Injection a Vulnerability?</a></p><p>====== Timestamps ======</p><p>(00:00:00) Introduction</p><p>(00:09:16) Google Vertex AI Bug</p><p>(00:29:28) Sasi's Background and Bug Bounty Journey</p><p>(00:38:55) Resources for AI and Agentic Security Methodology</p><p>(00:50:34) ForcedLeak</p><p>(01:02:06) Is Prompt Injection a Vuln?</p>