Justin Gardner (Rhynorater) & Joseph Thacker (Rez0)
Episode 152: GeminiJack and Agentic Security with Sasi Levi
DEC 11, 202581 MIN
Episode 152: GeminiJack and Agentic Security with Sasi Levi
DEC 11, 202581 MIN
Description
<p>Episode 152: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Sasi Levi from Noma Security to talk about AI and Agentic Security. We also talk about ForcedLeak, a Google Vertex Bug, and debate if Prompt Injection is a real Vuln.</p><p>Follow us on twitter at: <a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/ctbbpodcast">https://x.com/ctbbpodcast</a></p><p>Got any ideas and suggestions? Feel free to send us any feedback here: <a target="_blank" rel="noopener noreferrer nofollow" href="mailto:[email protected]">[email protected]</a></p><p>Shoutout to<a target="_blank" rel="noopener noreferrer nofollow" href="https://twitter.com/realytcracker"> YTCracker</a> for the awesome intro music!</p><p>====== Links ======</p><p>Follow your hosts Rhynorater, rez0 and gr3pme on X: </p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/Rhynorater">https://x.com/Rhynorater</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/rez0__">https://x.com/rez0__</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/gr3pme">https://x.com/gr3pme</a></p><p>====== Ways to Support CTBBPodcast ======</p><p>Hop on the CTBB Discord at <a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/discord">https://ctbb.show/discord</a>!</p><p>We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.</p><p>CHeck out our New Christmas Swag at <a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/merch">https://ctbb.show/merch</a>!</p><p>Today's Sponsor: ThreatLocker. Check out ThreatLocker Elevation Control</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://ctbb.show/tl-ec">https://ctbb.show/tl-ec</a></p><p>And Noma Security! <a target="_blank" rel="noopener noreferrer nofollow" href="https://noma.security/">https://noma.security/</a></p><p>Today’s Guest: <a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/sasi2103">https://x.com/sasi2103</a></p><p>====== This Week in Bug Bounty ======</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://hackerone.com/vercel_platform_protection?type=team">Vercel Platform Protection</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/cramforce/status/1998072892391592195?s=20">Dedicated HackerOne program for Vercel WAF</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://yeswehack.com/programs?scopeType%5B%5D=open-source&page=1">YesWeHack Open Source Programs</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://www.yeswehack.com/learn-bug-bounty/android-recon-bug-bounty-guide">Android recon for Bug Bounty hunters</a></p><p>====== Resources ======</p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://x.com/sasi2103/status/608349038778437632">Sasi's Tweet from 2015</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://noma.security/blog/forcedleak-agent-risks-exposed-in-salesforce-agentforce/">ForcedLeak: AI Agent risks exposed in Salesforce AgentForce</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="https://danielmiessler.com/blog/is-prompt-injection-a-vulnerability">Is Prompt Injection a Vulnerability?</a></p><p>====== Timestamps ======</p><p>(00:00:00) Introduction</p><p>(00:09:16) Google Vertex AI Bug</p><p>(00:29:28) Sasi's Background and Bug Bounty Journey</p><p>(00:38:55) Resources for AI and Agentic Security Methodology</p><p>(00:50:34) ForcedLeak</p><p>(01:02:06) Is Prompt Injection a Vuln?</p>